Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The lesson here is that there are things worse than downtime. Yeah the site being down is bad but hey, what's worse? Leaking PII all over the place.


I tried to highlight this in the post, but the key is a personal user one tied to an email, and the worst that I expect would happen would be that some training scripts break.

If this was a production key or something that seemed like it would cause financial harm/downtime, I would have never deleted it.


Honestly, with this level of competence I wouldn't be surprised if the same admin user credentials were used in application/lambda processor/whatever there is. Not at all saying you shouldn't have done it though!


Sadly, if you measure "worse" in selfish financial terms, the site being down is probably worse for you.


Even worse: PHI.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: