<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: preperat</title><link>https://news.ycombinator.com/user?id=preperat</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 27 Apr 2026 16:14:18 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=preperat" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by preperat in "An AI agent deleted our production database. The agent's confession is below"]]></title><description><![CDATA[
<p>The Railway detail is the part that sticks. Backups stored inside the same volume they're backing up isn't really a backup, it's a snapshot with extra steps. Delete the volume, delete the evidence.
That said, credential scoping should have been the first line here. A token that can destroy production infrastructure shouldn't exist in a dev environment config, full stop.</p>
]]></description><pubDate>Mon, 27 Apr 2026 03:32:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=47917445</link><dc:creator>preperat</dc:creator><comments>https://news.ycombinator.com/item?id=47917445</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47917445</guid></item></channel></rss>