Hacker Newsnew | past | comments | ask | show | jobs | submit | MattIPv4's commentslogin

Related: https://news.ycombinator.com/item?id=47824426

https://x.com/theo/status/2045862972342313374

> I have reason to believe this is credible.

https://x.com/theo/status/2045870216555499636

> Env vars marked as sensitive are safe. Ones NOT marked as sensitive should be rolled out of precaution

https://x.com/theo/status/2045871215705747965

> Everything I know about this hack suggests it could happen to any host

https://x.com/DiffeKey/status/2045813085408051670

> Vercel has reportedly been breached by ShinyHunters.


Who is this “theo” person and why are multiple people quoting him? He seems to have little to say that’s substantive at this point.

He’s a tech influencer, probably getting quoted here because he has the biggest reach of people covering this so far.

He’s a streamer who talks about tech. Previously had a sponsorship relationship with Vercel so is theoretically more well connected than average on the topic. He’s also very divisive because he does a lot of ragebait, grievance reporting, and contrarian takes but famously has blind spots for a few companies and technologies that he’s favored in past videos or been sponsored by. I have friends who watch a lot of his videos but I’ve never been able to get into it.

Theo Browne is a reasonably well known YouTuber & YC founder.

https://t3.gg/


He is a paid Vercel shill (literally, he does sponsored content for them on his YouTube channel)


Not in a few years.

YT tech vlogger

> Ones NOT marked as sensitive should be rolled out of precaution

if it's not marked as sensitive (because it is not sensitive) there is no reason to roll them. if you must roll a insensitive env var it should've been sensitive in the first place, no?


There's a difference between sensitive, private and public. If public (i.e. NEXT_PUBLIC_) then yeah likely not a reason to roll. Private keys that aren't explicitly sensitive probably are still sensitive. It doesn't seem to be the default to have things "sensitive" and I can't tell if that's a new classification or has always been there.

I can imagine the reason why an env variable would be sensitive, but need to be re-read at some point. But overwhelmingly it makes sense for the default to be set, and never access again (i.e. Fly env values, GCP secret manager etc)




Hitting 500s when trying to push branches and create PRs.


Related: A better streams API is possible for JavaScript: https://news.ycombinator.com/item?id=47180569


Are y'all aware your agent's name clashes with an established and rather popular streaming bot/tool, https://fossabot.com ?


That would explain why I tried to get vulnerability notifications and instead all my code was streamed to Twitch.


Spitballing some alt names

Fossadep

Fossacheck

Fossasafe


Fossamatta

Fossahappenin

Fossagoinon


Again... Unicorns when trying to view files or PRs, errors trying to leave comments or review things if they do load.


Looks like they've got a status page up now for PRs, separate from the earlier notifications one: https://www.githubstatus.com/incidents/smf24rvl67v9

Edit: Now acknowledging issues across GitHub as a whole, not just PRs.


Status page currently says the only issue is notification delays, but I have been getting a lot of Unicorn pages while trying to access PRs.

Edit: Looks like they've got a status page up now for PRs, separate from the earlier notifications one: https://www.githubstatus.com/incidents/smf24rvl67v9

Edit: Now acknowledging issues across GitHub as a whole, not just PRs.


They added the following entry:

Investigating - We are investigating reports of impacted performance for some GitHub services. Feb 09, 2026 - 15:54 UTC

But I saw it appear just a few minutes ago, it wasn't there at 16:10 UTC.


And just now:

Investigating - We are investigating reports of degraded performance for Pull Requests Feb 09, 2026 - 16:19 UTC


Yeah I've been seeing a lot of 500 errors myself, latency seems to have spiked too: https://github.onlineornot.com/


I cannot approve PRs because the JSON API is returning HTML error pages. Something is really hosed over there.


Yep, trying to access commit details is just returning the unicorn page for me


git operations are down too.


https://github.com/google-gemini/gemini-cli/issues/16723 is even worse, GitHub shows `5195 remaining items` in the collapsed timeline.


Wow. If you look at all the issues this seems pretty common

https://github.com/google-gemini/gemini-cli/issues?q=is%3Ais...


Wow that's whole a lot of yapping


Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: