3 ms·
The real story isn't Vercel. It's that a Context.ai employee got infostealer'd in February and four months later that single compromise propagated through an 'A
by BrianneLee011 6mo ago
The real story isn't Vercel. It's that a Context.ai employee got infostealer'd in February and four months later that single compromise propagated through an 'Allow All' Google Workspace OAuth grant into Vercel's env vars. This is less a Vercel incident and more the chronic OAuth-supply-chain problem finally surfacing somewhere visible.
- pier25 6mo agoHow do you go from a Google Workspace to production env vars without Vercel doing something wrong?
- ctmnt 6mo agoNot just into Vercel's env vars, but into Vercel's customer's env vars.
- ctmnt 6mo agoWhere did you see that a Context employee had credentials stolen in February? I haven't run into that particular data point.
- brazukadev 6mo agoThe real story is Vercel letting users with access to their infrastructure install random apps not vetted by any security system.