5 ms·
Yep, they outright lied about env vars. Incredible. It pains me to see even occasional defenders of Heroku. They're not the company they were 10 years ago. The
by hthrowaway5 4y ago
Yep, they outright lied about env vars. Incredible.
It pains me to see even occasional defenders of Heroku. They're not the company they were 10 years ago. They've been gutted and left for dead years ago but the product was so good nobody noticed until now.
They're not to be trusted as your platform. They simply don't have anywhere close to the manpower required to run such a platform. This was a when not if situation.
If you're still on it, make your plans to move away now. Time is ticking until a major outage or another security incident like this one. See my comment history and related threads for more. Specifically this summary: https://news.ycombinator.com/item?id=31374048 https://news.ycombinator.com/item?id=31374048
- bradleybuda 4y agoI would not say that they lied about the env vars. The stated line is still "env vars in apps were not compromised, but env vars in CI pipelines and review apps were". For some applications there may have been shared data in these vars - in our case (N=1) our CI pipeline and review apps had a dramatically smaller and less critical set of variables. It still sucks that they are parceling out the information, but the claim that they outright lied is not true.
- hthrowaway5 4y agoThe lie was: > We also wanted to address a question regarding impact to environment variables. While we confirmed that the threat actor had access to encrypted Heroku customer secrets stored in config var, the secrets are encrypted at rest and the threat actor did not access the encryption key necessary to decrypt config var secrets. https://status.heroku.com/incidents/2413 https://status.heroku.com/incidents/2413 Nowhere in that did it clarify it was speaking of app but not pipeline env vars. They had plenty of time to author that post too. Make sure you rotate those app env vars anyways as this somehow appears to be getting worse by the week.
- deleted 4y ago[deleted]
- colesantiago 4y agoI would like to move but there are really no good alternatives that are even close to Heroku.
- hthrowaway5 4y agoWell hopefully once it's gone the competition will be able to get more market share to build quality product. Heroku has been starving the entire ecosystem for years. I don't have experience with any other PaaS's so I can't recommend one, but what you say is what I commonly hear.
- ezekg 4y agoHeroku hasn’t been starving the ecosystem. They simply haven’t had real competition on their caliber of (zero-)devops.
- glenngillen 4y agoThis makes no sense. Heroku have had no competition because nobody has built a better product. They’ve not been starving anyone or anything. Given the biggest and most common complaint most lay against Heroku is that it’s too expensive, if anything the lack of innovation for years has created a huge window for a competitor. And yet here we are. Still.
- hthrowaway5 4y agotl;dr: Heroku is taking customers away that if competitors had it: they would be able to receive more capital It's not unlike Google Search. Google Search has atrophied over the years but because it's still the best in the market, it's used by almost everyone. Competition is hard to build because it has to be better than Google Search in order to bother using it. Heroku competitors have struggled in part because Heroku is a fully featured platform. It's relatively easy to build a platform that ticks a couple of boxes really well but building something that matches Heroku in feature parity is a daunting task. In order for competition to get there they need customers and funding, and funding is way easier to get the more customers come in through the door. Once Heroku dies (perhaps already since this incident) we'll start to see real competition in this space because their competition will be getting used. The PaaS space needs that oxygen Heroku is taking up.