Comment on Tea app leak worsens with second database exposing user chats

<- View Parent
FauxLiving@lemmy.world ⁨3⁩ ⁨days⁩ ago

This wasn’t vibe coding, it’s incompetant devops.

You have to go out of your way to make these buckets public like this. Several giant “Everyone will have access to this” warnings, re-authentication, a permanent warning symbol on the dashboard AND regular e-mails reminding you that you have a public bucket. I don’t even think you can do this via the API, it requires a human to manually make this setting.

I’m guessing that they couldn’t figure out how to configure the Access Control Lists and just made it public so that it would work. That’s fine in a test environment, without any user data but it’s pure incompetence to have a production system setup this way.

source
Sort:hotnewtop