21 pointsby ssiddharth6 hours ago5 comments
  • esher6 hours ago
    Got that too. My first reaction: Go to HN to understand what's going on. Where are the comments?
  • sathomasga2 hours ago
    Closing the barn door well after the horses are long gone.
  • sph5 hours ago
    > webhook secrets for webhooks you are responsible for were inadvertently included in an HTTP header on webhook deliveries

    LOL how does this even happen?

    • freakynit5 hours ago
      Same reaction of mine as well. I mean, how do you even fck up this way? ... I dont know why, but, this is giving me vibe-coded vibes.

      Developer might have prompted to include some signature (definitely they didn't use this word, or else AI would not have messed this way) to verify the webhooks as being coming from legitimate source, and AI probably went ahead with the secret key itself :)

  • suralind5 hours ago
    How come it took them so much time to send this notification? I'm so fed up with their bs.
  • preetigagarwal11 minutes ago
    [dead]