Live data from Hacker News

Heroku: We’ve Heard Your Feedback

blog.heroku.com

71–80 of 151 posts

Re: Heroku: We’ve Heard Your Feedback

#71
post #67

> Additionally, we have no evidence that the attacker has accessed any customer accounts or decrypted customers’ environment variables. Now the attackers had access to encrypted environment variables?

More context, from the latest email notification:

> We also wanted to address a question regarding impact to environment variables. While we confirmed that the threat actor had access to encrypted Heroku customer secrets stored in config var, the secrets are encrypted at rest and the threat actor did not access the encryption key necessary to decrypt config var secrets.

Re: Heroku: We’ve Heard Your Feedback

#74

“I have a lifelong enthusiasm for developers and the experience they have building software together” And then drops a link to contact them, via LinkedIn… LinkedIn is the polar opposite of GitHub. It’s the worst example of social media, from its news feed, to spam invites. And it’s broken every rule in the “be a good netizen” play book, from constant spam, to slurping your email contacts and surveillance to the extre…

It hadn't really clicked until your comment that both Github and LinkedIn are owned by the same company.

True, but both of them have stuck to their original objectives even now. GitHub at doing things Devs like and LinkedIn at doing things HR likes.

WaPo and AWS are both owned by the same person. That doesn't mean both (have to) charter in the same territory.

Re: Heroku: We’ve Heard Your Feedback

#76
post #22

Heroku is a one of kind platform, many tried to replicate, none have come close, the ability to setup a whole app with a few clicks on dynos and add-ons is great. The price was always salty $50/month for 1gb RAM shared CPU, and in the few past years no newly released features comes to mind. As a customer I have no idea what this security issue impact, the communication has been poor as this post does not clarify much…

Sorry but Render at their lunch entirely. Try it. https://render.com/docs/deploy-rails Want simple? Use a build.sh Want a bit complexity? Use a Dockerfile. Their docs are really copy paste for 99.9% applications. Whoever in that company made the decision to invest in docs was right on the money. It made switching to them a much easier choice. https://render.com

I'm moving a small amount of stuff ($250/mo spend) off Heroku this weekend. It's either Render or Fly, and I guess I'm going to start with Render.

Here's where I'm starting: https://render.com/docs/migrate-from-heroku

Re: Heroku: We’ve Heard Your Feedback

#77

Sorry, but this is a joke of a response. When they started sending out password reset emails, they should have explained why. Not only when people started complaining, and the media picked up on the lack of transparency.

It's ok: Bob says "Trust as our #1 value".

Re: Heroku: We’ve Heard Your Feedback

#78
post #61

Earlier quoted context omitted.

> 2. Customers sign up at "heroku.com", the platform is called "Heroku", the CLI is "heroku", everything's heroku, so don't send emails from a parent company (Salesforce), send them from "Heroku". They're working on something called "Project Periwinkle" that is intended to remove all Heroku branding and make everything Salesforce branded. Periwinkle being a colour between blue (salesforce) and purple (heroku). No mor…

Any suggestions on a rival PaaS that has a similar engineering philosophy to the old Heroku?

fly.io is an excellent alternative. I am slowly migrating all of my clients over.

Re: Heroku: We’ve Heard Your Feedback

#79

Sorry, but this is a joke of a response. When they started sending out password reset emails, they should have explained why. Not only when people started complaining, and the media picked up on the lack of transparency.

can somebody fill me in what happened? is this related to the oAuth vulnerability through github a while back?

Re: Heroku: We’ve Heard Your Feedback

#80

“I have a lifelong enthusiasm for developers and the experience they have building software together” And then drops a link to contact them, via LinkedIn… LinkedIn is the polar opposite of GitHub. It’s the worst example of social media, from its news feed, to spam invites. And it’s broken every rule in the “be a good netizen” play book, from constant spam, to slurping your email contacts and surveillance to the extre…

I agree with you about LinkedIn. I also would have agreed with you about how silly that is, until I started working with giant banks and other huge finance industry people. Many of the devs there legit do use LinkedIn. A number of people actually blog and post updates and stuff on LinkedIn. It was really surprising. Startup culture and big corporate tech, despite using many of the same technologies, are miles apart c…

Devs use LinkedIn for blog posts? Are they using it as way to get other devs to read it, or as a way to get potential employers to notice them?

Tbh, I don't a single dev who uses LinkedIn unless they looking for a new role I.e they're certainly not using LinkedIn as a dev-oriented news feed

Post reply on HN