Live data from Hacker News

Vercel April 2026 security incident

bleepingcomputer.com

161–170 of 540 posts

Re: Vercel April 2026 security incident

#161

What is the rationale for using vercel ? I'm getting a lot of value out of cloudflare with the $5/month plan lately but my bare metal box with triple digit ram has seen zero downtime since 2015.

I haven't used Cloudflare and am the first to shit on Vercel. But I have to say, some aspects of their hosting are nice. In many ways it really is just a terminal command and up it goes with good tooling around it. For example, the PR previews take zero setup and just work. Managing your projects is easy, it's all nicely designed, it integrates well with Next and some other frontend-heavy systems and so on.

Re: Vercel April 2026 security incident

#162
post #105

What is the rationale for using vercel ? I'm getting a lot of value out of cloudflare with the $5/month plan lately but my bare metal box with triple digit ram has seen zero downtime since 2015.

They put a massive amount of VC cash into convincing people that Next.js was "the modern way" to create a website. Then they got lucky with the timing of LLMs becoming popular while they were the hot thing, leading LLMs to default to it when creating new websites. To picture that amount of VC cash - they're at Series F , and a huge chunk of that went towards marketing. Both have been changing as people realize it's r…

[dead]

Re: Vercel April 2026 security incident

#163

What is the rationale for using vercel ? I'm getting a lot of value out of cloudflare with the $5/month plan lately but my bare metal box with triple digit ram has seen zero downtime since 2015.

Out of curiosity what are you using cloudflare for that it costs $5 and who do you use for the baremetal box?

Re: Vercel April 2026 security incident

#164

Earlier quoted context omitted.

It's interesting how many of the low-effort vibecoded projects I see posted on reddit are on vercel. It's basically the default.

10 years ago it was Heroku and Three.js.

New one coming in 5 years. Cycle repeats itself.

Re: Vercel April 2026 security incident

#165

Earlier quoted context omitted.

That's the irony of Mythos. It doesn't need to exist. LLM vibe slop has already eroded the security of your average site.

Self fulfilling prophecy: You don't need to secure anything because it doesn't make a difference, as Mythos is not just a delicious Greek beer, but also a super-intelligent system that will penetrate any of your cyber-defenses anyway.

In some ways Mythos (like many AI things) can be used as the ultimate accountability sink.

These libraries/frameworks are not insecure because of bad design and dependency bloat. No! It's because a mythical LLM is so powerful that it's impossible to defend against! There was nothing that could be done.

Re: Vercel April 2026 security incident

#166

Earlier quoted context omitted.

Who is this “theo” person and why are multiple people quoting him? He seems to have little to say that’s substantive at this point.

He is a paid Vercel shill (literally, he does sponsored content for them on his YouTube channel)

He literally doesn't. https://x.com/theo/status/1832228209573949947

Re: Vercel April 2026 security incident

#167

Earlier quoted context omitted.

I think most people would agree. However it is less clear on how to do this, people mostly take the easiest path.

I guess engineers can differentiate their vibecoded projects by selecting an eccentric stack.

Choosing an eccentric stack makes the llms do better even. Like Effect.ts or Elixir

Re: Vercel April 2026 security incident

#168
post #105

What is the rationale for using vercel ? I'm getting a lot of value out of cloudflare with the $5/month plan lately but my bare metal box with triple digit ram has seen zero downtime since 2015.

They put a massive amount of VC cash into convincing people that Next.js was "the modern way" to create a website. Then they got lucky with the timing of LLMs becoming popular while they were the hot thing, leading LLMs to default to it when creating new websites. To picture that amount of VC cash - they're at Series F , and a huge chunk of that went towards marketing. Both have been changing as people realize it's r…

> To picture that amount of VC cash - they're at Series F, and a huge chunk of that went towards marketing.

I guess they should have put some of that marketing money into hiring someone to manage the security of their systems. It's pretty telling that they had to hire an "incident response provider" just to figure out what happened and clean up after the hack. If you treat security like something you don't have to worry about until after you've been hacked you're probably going to get hacked.

Re: Vercel April 2026 security incident

#169
post #15

Earlier quoted context omitted.

from his "sources". > Here’s what I’ve managed to get from my sources: >3. The method of compromise was likely used to hit multiple companies other than Vercel. https://x.com/theo/status/2045870216555499636 To be fair journalists often do this too, eg. "[company] was breached, people within the company claim"

Isn’t he a Vercel evangelist though?

He quite publicly is not anymore.

Re: Vercel April 2026 security incident

#170
post #136
post #103

Earlier quoted context omitted.

Very nice developer experience. A lot of batteries included, like CDN, incremental page regeneration, image pipeline or observability. Not having to maintain a server. I’m still planning to move elsewhere though, the vendor lock-in is not worth it and I’d like to keep our infra in the EU.

All of this is available in Cloudflare $5 plan?

Cloudflare’s developer experience doesn’t come close, it is terrible. Cloudflare are working on it, and hopefully they’ll be a real competitor to Vercel on ease of use someday, but right now, it is painful when compared to Vercel. Cloudflare is infrastructure first, Vercel is developer experience first.
Post reply on HN