Ruby / Golang / DevOps. Senior Backend Engineer @gitlab, Prev @rd_station (opinions my own)

Joined October 2008
152 Photos and videos
É oficial, endireitaram o Peru. Agora o Peru volta a crescer
1
13
Gabriel Mazzetto retweeted
Cuidado com o que deseja
5
86
1,089
6,555
Bolha tec hj tendo gostinho da democracia brasileira. Boa parte tava aplaudindo por que o porrete não tava caindo na própria cabeça, hj tão vendo o efeito colateral do estado grande. A prioridade é o pão e circo (futebol) todo o resto do país que se exploda.
15
O Brasil inteiro de olho no Peru. Peru na boca do povo, ninguém mais faz nada hj só pensando no futuro do Peru, em qual candidato vai sair por cima.
51
Pessoal usa "seu zé das verduras" como gateway de pagamento e fica surpreso que o negócio é zuado.
32
youtu.be/DmU9uovmT2A?is=txYS… This is the meeting every single company went throgh this year before announcing AI will 10 billion X everything
72
Music Assitant is the secret from Home Assitant very few people know. It is really everything streaming music should have been by default. Want group speakers with random brands? Sure. Want to list everything from Spotify, YT music and Soundcloud? RIGHT AWAY! Want music to keep playing no matter what? You are the boss!
54
Gabriel Mazzetto retweeted
The HR department exists for one reason: to perpetuate the HR department.
645
3,278
25,492
2,828,083
Every 12-24 month, leadership somewhere rediscover a variation of LoC per person as a metric $current_bullshit (AI). This industry is fundamentally doomed
35
Gabriel Mazzetto retweeted
10
66
822
25,988
It used to be that opting for a SaaS was buying into insurance. We should all realize every single one is a liability. #saas #soc2
1
140
We used AI to *checks notes* "improve speed and be more productive" and instead got hacked by AI being actually an unreliable piece of s*** with more roles then a swiss cheese.
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly. A Vercel employee got compromised via the breach of an AI platform customer called Context.ai that he was using. The details are being fully investigated. Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments. Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration. We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel. At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community. The recommendation for all Vercel customers is to follow the Security Bulletin closely (vercel.com/kb/bulletin/verce…). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature. In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback. We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance. It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
220
De Extreme Go Horse pra Agentic Go Horse
O frenesi com AI tá fazendo todo mundo passar um verniz nesse velho conhecido aqui ó:
2
124
Única opção, única via. Raio privatizador sem sobrar nada.
54
Apple has a unique opportunity to grab a large chunk of Microsoft Business users with the combo of cheap decent macbook Neo Bundled MDM. Everything is already running on the web, so there is barely any moat on Windows anymore.
1
98
Gabriel Mazzetto retweeted
2
197
2,036
13,899
Every single compliance report is performative theather mafia charging for "protection". If you don't pay you can't sell. Everyone, large or small is just pretending.
Your SOC2 compliance is fake, your deploy platform leaks private user data, and your HTTP library has malware in it. Happy Monday.
1
58
Npm considered evil (again)
considering the risk of supply chain attacks from npm packages, maybe we should not have default trusted dependencies?
43
Onii-chan Musk has decided that we need more japanese content. Can't disagree here... the alternative has been really depressing
41
We can only have AGI when we put more lidar on everything... or so I heard
55