<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: tetrakai</title><link>https://news.ycombinator.com/user?id=tetrakai</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 20 Apr 2026 21:50:58 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=tetrakai" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by tetrakai in "Vercel April 2026 security incident"]]></title><description><![CDATA[
<p>I can't comment about 1, but my read of 2 and 3 is that the chain was something like this:<p>1. One or more Vercel employees - likely engineers - grant OAuth access to context.ai. They presumably did this for office-suite style features, but the OAuth request included a GCP grant for some reason, maybe laziness on context.ai's part or planned future features? Either way, Google's OAuth flow has little differentiation between "office suite" scopes and "cloud platform" scopes, so this may not have been particularly obvious to those at Vercel<p>2. context.ai's AWS account was compromised (unspecified how), and the Google OAuth tokens they had for customer accounts, including those for at least one Vercel employee, were taken<p>3. Those OAuth token(s) were used to authenticate to the GCP APIs as those Vercel employees, then allowing access to Vercel's DBs, and therefore access to customer data and secrets</p>
]]></description><pubDate>Mon, 20 Apr 2026 11:53:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=47832987</link><dc:creator>tetrakai</dc:creator><comments>https://news.ycombinator.com/item?id=47832987</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47832987</guid></item><item><title><![CDATA[New comment by tetrakai in "A Look into NaviDial, Japan's Legacy Phone Service"]]></title><description><![CDATA[
<p>This is bizarre! When you call ANA from Australia they have multiple dedicated 1800 (free) numbers you can reach them at, including a call centre in the Philippines for simple issues that picked up straight away for me. I wonder why they're so much more customer hostile in their own geography?</p>
]]></description><pubDate>Thu, 16 Apr 2026 10:26:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=47791075</link><dc:creator>tetrakai</dc:creator><comments>https://news.ycombinator.com/item?id=47791075</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47791075</guid></item><item><title><![CDATA[Taxes: What happens when you move?]]></title><description><![CDATA[
<p>Article URL: <a href="https://karla.io/2020/07/16/source-taxation.html">https://karla.io/2020/07/16/source-taxation.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=23865461">https://news.ycombinator.com/item?id=23865461</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 17 Jul 2020 00:16:52 +0000</pubDate><link>https://karla.io/2020/07/16/source-taxation.html</link><dc:creator>tetrakai</dc:creator><comments>https://news.ycombinator.com/item?id=23865461</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=23865461</guid></item><item><title><![CDATA[Don't Panic: there's more TTL]]></title><description><![CDATA[
<p>Article URL: <a href="https://karla.io/2016/06/12/dont-panic.html">https://karla.io/2016/06/12/dont-panic.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=11891430">https://news.ycombinator.com/item?id=11891430</a></p>
<p>Points: 3</p>
<p># Comments: 1</p>
]]></description><pubDate>Mon, 13 Jun 2016 02:44:48 +0000</pubDate><link>https://karla.io/2016/06/12/dont-panic.html</link><dc:creator>tetrakai</dc:creator><comments>https://news.ycombinator.com/item?id=11891430</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11891430</guid></item><item><title><![CDATA[New comment by tetrakai in "SSH for Fun and Profit"]]></title><description><![CDATA[
<p>Thanks! I'll try to add one later this week, I've been meaning to :)</p>
]]></description><pubDate>Mon, 02 May 2016 04:54:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=11609268</link><dc:creator>tetrakai</dc:creator><comments>https://news.ycombinator.com/item?id=11609268</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11609268</guid></item><item><title><![CDATA[SSH for Fun and Profit]]></title><description><![CDATA[
<p>Article URL: <a href="https://karla.io/2016/04/30/ssh-for-fun-and-profit.html">https://karla.io/2016/04/30/ssh-for-fun-and-profit.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=11607762">https://news.ycombinator.com/item?id=11607762</a></p>
<p>Points: 324</p>
<p># Comments: 55</p>
]]></description><pubDate>Sun, 01 May 2016 20:38:24 +0000</pubDate><link>https://karla.io/2016/04/30/ssh-for-fun-and-profit.html</link><dc:creator>tetrakai</dc:creator><comments>https://news.ycombinator.com/item?id=11607762</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11607762</guid></item></channel></rss>