Joined September 2022
67 Photos and videos
Patrick Gerard retweeted
There is a genuinely insane phishing campaign running on Google right now using ChatGPT. They are using ChatGPT Canvas itself to create content on ChatGPT and then use that for Ads, so the domain and URL are 100% legit. Most normal users will not notice this, even if they check whether they are on the right website.
26
71
1,251
126,947
Shoutout to the @PaddleHQ Twitter team!
1
30
Super unhappy with the current situation @PaddleHQ onboarding isn't even possible even tho I have 5 other accounts and my projects are live. Any other alternative with less than ~2 weeks until I can receive payments? #buildinpublic #paddle #stripe
1
279
anyone can recommend someone who has experience building personal brands? Or anyone I can chat with? #buildinpublic
33
Trusting is everything.
22
No more fine-tuning apperently, any alternatives #buildinpublic
1
29
also @sama if I fine-tuned a model years ago with GPT3, or 4. you're saying once the model is deprecated, I won't have access to the fine-tune anymore? That makes no sense to me.
12
Vercel what's happening?
2
3
200
Maybe a DDoS? Getting a lot of 429
1
17
Looks like it's down, for you too?
1
17
Let's go baby
21
Holy cow, I just came back from any amazing weekend, barely touching the laptop. All .env keys to be rotated, for all customers - is this correct?
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly. A Vercel employee got compromised via the breach of an AI platform customer called Context.ai that he was using. The details are being fully investigated. Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments. Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration. We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel. At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community. The recommendation for all Vercel customers is to follow the Security Bulletin closely (vercel.com/kb/bulletin/verce…). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature. In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback. We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance. It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
29
Deployed an LLM safeguard, it quietly broke everything. Some outputs were just the input. Internal tests didn’t catch it. If you don’t check similarity basic signals, your tests are useless.
1
25
Make sure you check input and output for text features like length and other unique factors
8
Network: Anyone who has moved his company in a tax-friendlier country? Please help!
21
Why is still no one using my Reddit analytics tool to grow his SaaS?
2
1
31
Boost your SEO by posting a link to your website in Reddits top posts which bring potentially thousends of clicks to your projects daily?
14
Someone knows a Social Media guy for UGC content? Wanna hire 10-20 hours weekly. Well paid. #buildinpublic
2
2
23
70–80% of users canceled via Paddle’s automated emails. Our fancy dashboard cancel flow? They never even saw it. Lesson: know where users actually cancel set it up Hopefully churn >25% this month 🚀
Lowest Churn ever this month!! #buildinpublic
1
25