Live data from Hacker News

Heroku: We’ve Heard Your Feedback

blog.heroku.com

51–60 of 151 posts

Re: Heroku: We’ve Heard Your Feedback

#51
post #36

Earlier quoted context omitted.

Email address is good but also an issue tracker or better yet IRC or something public would be good.

Agreed, for the specific issue. But it seems like he’s asking ppl to contact him more generally. It does pose the question, what is the most developer friendly contact method?? GET /contacts POST /message Interested to hear ideas.

Email address and / or GitHub. No one's saying he needs to show off what a great programmer he is through his contact methods, just don't use a site that's infamously bad for dark patterns and recruiter spam.

Re: Heroku: We’ve Heard Your Feedback

#52

If you're on Heroku how do you deploy now? It says it's still weeks away before you can deploy - did I read this right?

Same way we’ve done for years, via our CD (circle CI), which uses the Heroku CLI

We’ve been lucky that this entire event has, theoretically, not touched us as we never connected GitHub. That may change as more information comes to light.

We’re still strongly considering moving to AWS, and are in the process of getting quotes from vendors.

Re: Heroku: We’ve Heard Your Feedback

#53
post #12

>The Heroku team and their colleagues have worked around the clock, including nights and weekends Can someone more familiar with an event like this tell me what they are working so hard on? I imagine securing the vulnerable service and resetting various credentials doesn't take that much work.

You have to make sure the attackers aren’t still in your network, you have to get them out if they are, you have to fully scope out what they messed with, and restore anything that’s plausibly connected. Even in the best case with all the right monitoring systems in place there is a lot of manual work involved from owners of the various different effected services and just managing the overall response adequately. I…

Additionally there are legal concerns, for both regulatory compliance and for prepping for inevitable litigation. Those concerns aren’t necessarily a blocker for service restoration, but it really depends on the systems involved. If service could be restored by rebooting a system, for example, but that system also has data related to customers’ (and their customers’) PII and it might have been accessed by the attacker, then you need to make sure it’s all properly preserved forensically first, so that you can comply with regulations regarding breach notifications. The forensic analysis could then happen, but it’s definitely a “measure twice, cut once” situation with lots of lawyers involved (they won’t understand the systems, but they’ll make you explain everything so they can make decisions about risk; and they are in charge).

Also, generally, it’s a “fog of war” scenario, where you can have so many unknowns to work through in a compressed time period, and sometimes there’s an active attacker and they get a vote, too.

Re: Heroku: We’ve Heard Your Feedback

#54

“I have a lifelong enthusiasm for developers and the experience they have building software together” And then drops a link to contact them, via LinkedIn… LinkedIn is the polar opposite of GitHub. It’s the worst example of social media, from its news feed, to spam invites. And it’s broken every rule in the “be a good netizen” play book, from constant spam, to slurping your email contacts and surveillance to the extre…

It hadn't really clicked until your comment that both Github and LinkedIn are owned by the same company.

Re: Heroku: We’ve Heard Your Feedback

#55
post #18

> We’ve heard your feedback on our communications during this incident. You want more transparency, more in-depth information, and fewer “we are working on it” posts. Well, those, and : 1. Speed. It took days for heroku customers to be told about this. 2. Customers sign up at "heroku.com", the platform is called "Heroku", the CLI is "heroku", everything's heroku, so don't send emails from a parent company (Salesforce…

> 2. Customers sign up at "heroku.com", the platform is called "Heroku", the CLI is "heroku", everything's heroku, so don't send emails from a parent company (Salesforce), send them from "Heroku". They're working on something called "Project Periwinkle" that is intended to remove all Heroku branding and make everything Salesforce branded. Periwinkle being a colour between blue (salesforce) and purple (heroku). No mor…

The amount of Salesforce fluff in the post is quite palpable. There is a clear lack of control with the leaders in Heroku judging off this post because of the salesforce transition.

This project Periwinkle sounds awful. Basically thats the end of using Heroku for us. If it remains like this its something to judge from.

Re: Heroku: We’ve Heard Your Feedback

#56

As a former herokai, communication was always the #1 point of discussion internally. This idea that they "can" do better is a half truth. They DID do better. I leave it as an exercise to the reader to determine what the limiting resource was here. By the way, how many senior devs and cofounders are left at Heroku Bob? Why doesn't it show up at dreamforce anymore?

(Former) Salesforce employee here, long enough to have been there a couple of years before the Heroku acquisition. I can't let this stand without a comment. Heroku never seemed to want to integrate, but instead be the "cool kids", those who just do not have to worry about the enterprisy stuff such as automated backups, DR, high availability, enabling Java, etc. Everything they did was great, everything "Salesforce" s…

Trying to integrate with SFDC was a mistake. The product never fit inside of the company. Of course their investment made Heroku successful over the first few years (and eventually highly profitable as I understand) but they should've just spun it off and let it succeed without trying to figure out how to "enterprise" it.

What we knew how to do at Heroku was build a great platform for developers to launch apps. We never claimed to know how to make that model work for enterprise. In fact we were awful at trying.

Re: Heroku: We’ve Heard Your Feedback

#57

“I have a lifelong enthusiasm for developers and the experience they have building software together” And then drops a link to contact them, via LinkedIn… LinkedIn is the polar opposite of GitHub. It’s the worst example of social media, from its news feed, to spam invites. And it’s broken every rule in the “be a good netizen” play book, from constant spam, to slurping your email contacts and surveillance to the extre…

I assume it’s so that they can mine your LinkenIn connection data and make it available to their sales teams to upsell you and people you know. I’d imagine they would end up storing all that data in some kind of web-based CRM, possibly sold as a SAAS product.

Re: Heroku: We’ve Heard Your Feedback

#58

Earlier quoted context omitted.

> 2. Customers sign up at "heroku.com", the platform is called "Heroku", the CLI is "heroku", everything's heroku, so don't send emails from a parent company (Salesforce), send them from "Heroku". They're working on something called "Project Periwinkle" that is intended to remove all Heroku branding and make everything Salesforce branded. Periwinkle being a colour between blue (salesforce) and purple (heroku). No mor…

The amount of Salesforce fluff in the post is quite palpable. There is a clear lack of control with the leaders in Heroku judging off this post because of the salesforce transition. This project Periwinkle sounds awful. Basically thats the end of using Heroku for us. If it remains like this its something to judge from.

[deleted]

Re: Heroku: We’ve Heard Your Feedback

#59
post #18

> We’ve heard your feedback on our communications during this incident. You want more transparency, more in-depth information, and fewer “we are working on it” posts. Well, those, and : 1. Speed. It took days for heroku customers to be told about this. 2. Customers sign up at "heroku.com", the platform is called "Heroku", the CLI is "heroku", everything's heroku, so don't send emails from a parent company (Salesforce…

This all somehow seems unsurprising. If anyone has tried to use Heroku in easily the last year, the number of times you get failed builds over really trivial things is noticeable.

Re: Heroku: We’ve Heard Your Feedback

#60
post #37

If you're on Heroku how do you deploy now? It says it's still weeks away before you can deploy - did I read this right?

Still weeks away from enabling the GitHub integration again, you can still manually deploy via the heroku CLI. Our team realised heroku was going to take weeks and we’ve replicated our “review app” development workflow with GitHub actions that clone apps on PR, push code and rebuild them on push and destroy them on PR close. It’s not as seamless as the heroku GitHub integration but it’s good enough for now.

Woah… this would be an amazing thing to open source
Post reply on HN