Sabitlenmiş Tweet
ronit
1.5K posts

ronit retweetledi

@riddhixjain yeah, good time to touch grass and come back when claude is up againn
English
ronit retweetledi

Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly.
A Vercel employee got compromised via the breach of an AI platform customer called Context.ai that he was using. The details are being fully investigated.
Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments.
Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration.
We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel.
At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community.
The recommendation for all Vercel customers is to follow the Security Bulletin closely (vercel.com/kb/bulletin/ve…). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature.
In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback.
We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance.
It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
English

@RubenVeidt @infinterenders hell nah, it can be non other than javascript
English

@FarzaTV Clicky made hands-on learning feel way more intuitive for me.
But I wanted something that felt more real.
So I forked it and added personas.
Each one has its own way of thinking, teaching, and even voice.
It feels more like learning from actual people.
Demo 👇
Which persona should i ship next ?
#AI #BuildInPublic
Farza 🇵🇰🇺🇸@FarzaTV
I built this thing called Clicky. It's an AI teacher that lives as a buddy next to your cursor. It can see your screen, talk to you, and even point at stuff, kinda like having a real teacher next to you. I've been using it the past few days to learn Davinci Resolve, 10/10.
English

I'm gonna keep hacking on Clicky!
It's not a 10/10 idea, but, I think it's an okay starting point to continue iterating into an actual company. Instead of hunting for the perfect idea, I rather ship and turn whatever I'm building into the perfect idea!
The existing codebase remains open source. Tinker with it, make it yours, start a company out of it, do whatever you want I don't mind. But, for all the new stuff I'm hacking on, gonna keep it private.
What's funny is I had been sitting on the Clicky demo for a few weeks. I thought it was a pretty meh idea and posted it with no real expectation. I really didn't wanna work on it. What changed my mind was talking to all the users this week, I feel like there's so much more here than what meets the eye.
Let's see what happens.
Regardless, glad I shipped it! And glad so many people are building their own Clicky's now as well it's very inspiring.
Gonna continue sharing learnings.
Wish me luck!!
English

@avrldotdev @JacobSobolev yeah, you are doing great by helping beginners. keep up the good work aviral
English

@ronitrajfr @JacobSobolev I don't have it, but I like to not write too much coz people don't read & skip.
English

Step-1: Learn Go
Step-2: Learn goroutines, channel & ascheduler
Step-3: Master pointers, interfaces & malloc
Step-4: Build an HTTP server with std lib
Step-5: Read the Go runtime & standard library source. Embrace humility
Step-6: Build a production-grade backend (REST/gRPC, DB, caching, msging)
Step-7: Make it resilient under load
Step-8: Learn profiling and optimization (pprof, trace, benchmarks)
Step-9: deploy with Docker & K8s
Step-10: Ship it
English

@avrldotdev @JacobSobolev yeah, i didnt mean to point you out or smth, i was just curious that how you have character limit even after premium.
appreciate it 🤗
English

@ronitrajfr @JacobSobolev people don't read that much, I try to keep it as tight as possible. But it doesn't work 90% of the time without degrading the quality so yeah. I try to keep the info up top without having to click read more
English

@avrldotdev @JacobSobolev you have character limit even after having premium?
English

@JacobSobolev I just used the abbreviation for memory allocation just for character limit.
English

Wrote something on what do we mean while building a scalable distributed system
mrinals-vault.xyz/Engineering/Di…
English












