Live data from Hacker News

Vercel April 2026 security incident

bleepingcomputer.com

81–90 of 540 posts

Re: Vercel April 2026 security incident

#81

Earlier quoted context omitted.

Ah, Theo with his vast insights and connections into everything. That man gets around, and his content is worth it's cost. Theo's content boils down to the same boring formula. 1. Whatever buzzword headline is trending at the time 2. Immediate sponsored ad that is supposed to make you sympathize with Theo cause he "vets" his sponsors. 3. The man makes you listen to a "that totally happened" story that he somehow alwa…

I just wanted to chime in and say I think he is knowledgeable; he's not a con. I know you didn't say that, but people might have the impression he doesn't know what he's talking about. He does know, and I've learned quite a lot from him in the past. However, since the LLM Cambria explosion, he has become very clickbaity, and his content has become shallow. I don't watch his videos anymore.

Not that I ever had confidence in his technical knowledge, but it went to zero when he confidently asserted that there was no possible way a single server could handle the massive traffic some NextJS app he had made was serving. He then posted the bill - which was about $5K IIRC - and I was able to determine from the billed runtime and memory that a modestly-spec’d RPi could in fact handle it.

Re: Vercel April 2026 security incident

#82

I've been part of a response team on a security incident and I really feel for them. However, this initial communication is terrible. Something happened, we won't say what, but it was severe enough to notify law enforcement. What floors me is the only actionable advice is to "review environment variables". What should a customer even do with that advice? Make sure the variable are still there? How would you know if a…

> The only reason to dramatically overpay for the hosting resources they provide is because you expect them to expertly manage security and stability.

This and because it's so convenient to click some buttons and have your application running. I've stopped being lazy, though. Moved everything from Render to linode. I was paying render $50+/month. Now I'm paying $3-5.

I would never use one of those hosting providers again.

Re: Vercel April 2026 security incident

#83

Earlier quoted context omitted.

Ah, Theo with his vast insights and connections into everything. That man gets around, and his content is worth it's cost. Theo's content boils down to the same boring formula. 1. Whatever buzzword headline is trending at the time 2. Immediate sponsored ad that is supposed to make you sympathize with Theo cause he "vets" his sponsors. 3. The man makes you listen to a "that totally happened" story that he somehow alwa…

I just wanted to chime in and say I think he is knowledgeable; he's not a con. I know you didn't say that, but people might have the impression he doesn't know what he's talking about. He does know, and I've learned quite a lot from him in the past. However, since the LLM Cambria explosion, he has become very clickbaity, and his content has become shallow. I don't watch his videos anymore.

> he's not a con.

When you're putting the bar that low, sure.

He's about as knowledgeable as the junior you hired last week, except that he speaks from a position of authority and gets retweeted by the entire JS slop sphere. He's LinkedIn slop for Gen Z.

Re: Vercel April 2026 security incident

#85
post #4

Related: https://news.ycombinator.com/item?id=47824426 https://x.com/theo/status/2045862972342313374 > I have reason to believe this is credible. https://x.com/theo/status/2045870216555499636 > Env vars marked as sensitive are safe. Ones NOT marked as sensitive should be rolled out of precaution https://x.com/theo/status/2045871215705747965 > Everything I know about this hack suggests it could happen to any host http…

Who is this “theo” person and why are multiple people quoting him? He seems to have little to say that’s substantive at this point.

He is a paid Vercel shill (literally, he does sponsored content for them on his YouTube channel)

Re: Vercel April 2026 security incident

#88
post #33

Earlier quoted context omitted.

I don't know if I'd trust some random programmer-streamer-influencer on anything other than the topic of streamer-influencing.

The link at the top of the page it to vercel acknowledging it...

Vercel acknowledges a security incident, which nobody is claiming doesn't exist. What they don't acknowledge are this person's vague implications about impact elsewhere.

Re: Vercel April 2026 security incident

#89
post #36

Much as I want to rip on vercel, its clear that ai is going to lead to mass security breaches. The attack surface is so large, and ai agents are working around the clock. This is a new normal. Open source software is going to change, companies wont be running random repos off github anymore

Your entire recent posting history is "software engineering is over, AI has won." What's your agenda here?

The guy has like 10 thousand comments boosting AI and 600 karma, whatever his agenda is people aren’t buying it.

Re: Vercel April 2026 security incident

#90

What is the rationale for using vercel ? I'm getting a lot of value out of cloudflare with the $5/month plan lately but my bare metal box with triple digit ram has seen zero downtime since 2015.

0.82% of homes are burglarized every year.

Meaning since 2015, you’ve got an 8.2% chance of having someone walk out with that box. Hopefully there’s nothing precious on it.

Post reply on HN