Posting this at 5pm on a Friday sounds about right, yeah?
Heroku: We’ve Heard Your Feedback
11–20 of 151 posts
Re: Heroku: We’ve Heard Your Feedback
#12>The Heroku team and their colleagues have worked around the clock, including nights and weekends Can someone more familiar with an event like this tell me what they are working so hard on? I imagine securing the vulnerable service and resetting various credentials doesn't take that much work.
Re: Heroku: We’ve Heard Your Feedback
#13Posting this at 5pm on a Friday sounds about right, yeah?
That isn’t a very charitable take. It’s been 24x7 for them, the acknowledgement is most welcome, in my opinion. I’m not sure waiting until Monday 9AM Pacific just to avoid these type of comments would be the right choice. The internet is 24x7 after all.
Re: Heroku: We’ve Heard Your Feedback
#14Posting this at 5pm on a Friday sounds about right, yeah?
That isn’t a very charitable take. It’s been 24x7 for them, the acknowledgement is most welcome, in my opinion. I’m not sure waiting until Monday 9AM Pacific just to avoid these type of comments would be the right choice. The internet is 24x7 after all.
Re: Heroku: We’ve Heard Your Feedback
#15By the way, how many senior devs and cofounders are left at Heroku Bob? Why doesn't it show up at dreamforce anymore?
Re: Heroku: We’ve Heard Your Feedback
#16>The Heroku team and their colleagues have worked around the clock, including nights and weekends Can someone more familiar with an event like this tell me what they are working so hard on? I imagine securing the vulnerable service and resetting various credentials doesn't take that much work.
Re: Heroku: We’ve Heard Your Feedback
#17Re: Heroku: We’ve Heard Your Feedback
#18Well, those, and:
1. Speed. It took days for heroku customers to be told about this.
2. Customers sign up at "heroku.com", the platform is called "Heroku", the CLI is "heroku", everything's heroku, so don't send emails from a parent company (Salesforce), send them from "Heroku".
3. Unambiguous info on what customers need to do. I had to guess based on HN comments whether config vars were accessed. Config vars are 100x more sensitive than code. Comms should be unambiguous and complete, and if incomplete for any reason, explain that (e.g. we don't know yet).
4. I still don't know whether having 1 Github Deploy on my Heroku account allowed unauthorized access to all heroku applications on my heroku account (i.e. those using other deploy methods, like `git push heroku main`). Were all my apps' repositories able to be accessed, or just the one(s) deployed via Github Deploys?
5. I still don't know whether unauthorized access was gained to all other GitHub respositories on my GitHub account, i.e. the repos that aren't heroku apps.
These said, I still really appreciate that security incidents happen and aren't easy to deal with, and there's no obligation for anyone at a profitable company to actually care about semi-captive customers, so thanks to Heroku for the efforts; it's genuinely appreciated.
Re: Heroku: We’ve Heard Your Feedback
#19And then drops a link to contact them, via LinkedIn…
LinkedIn is the polar opposite of GitHub. It’s the worst example of social media, from its news feed, to spam invites. And it’s broken every rule in the “be a good netizen” play book, from constant spam, to slurping your email contacts and surveillance to the extreme.
I struggle to imagine a developer saying “I’d like to contact xxx, and I’d love to do it via LinkedIn”
Why not drop your email? Or a GitHub profile with a public email, and readme containing other contact methods, would have been more dev centric.
Re: Heroku: We’ve Heard Your Feedback
#20> I started as Heroku GM a few weeks ago with intense enthusiasm to be a part of such a storied team. Wow talk about terrible timing.