Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Ruepler
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
Ruepler
3y ago
Exactly. You'd need to implement standard authentication mechanisms, preventing these vectors of attack from existing in the first place. They are "in the process" and "looking" to do that. As of now if I am not mis
2.
▲
by
Ruepler
3y ago
You can for sure. I am using it with Cloudflare pages for example. It's a matter of a click.
3.
▲
by
Ruepler
3y ago
It's most likely not. Not sure if this was intentional but they pretty much confirmed it in a reddit thread: > ... and are also in the process of completely deprecating the admin tokens for a more secure internal authentication proc
4.
▲
by
Ruepler
3y ago
>"we've decided to leave out the technical details of the breach in the blog post" >"Our dedication to transparency, security, and the trust you place in us remains unwavering." You are contradicting yourself
5.
▲
by
Ruepler
3y ago
They are claming that they resolved the vulnerability that caused the token leak but don't mention it. Doesn't exactly seem transparent to me or like handling it well. I was contracting for them last year and tried, among other th
6.
▲
by
Ruepler
3y ago
Yea it does. It most likely is related to MDX documents beeing susceptible to XSS attacks. Having worked at mintlify last year I can tell you that this is not surprising at all and I've been warning them extensively of sth like this ha