Back

Havish Gupta

Figuring Out • 7m

The issue is that most people just get the ai gen code, replace the API keys and deploy it. That's what causes these issues. Also api key being exposed is small thing, no one (including me 🤐) cares about security while vibe coding. “env var in production” 😂😂😭

Reply

More like this

Recommendations from Medial

Image Description
Image Description

Account Deleted

Hey I am on Medial • 7m

Somebody just scanned 2000 Vibecoded websites... and here's what he found : - 49.5% had security issues - Found 1120 JWT tokens exposed - 70 Google API keys floating around And yes, env vars in production 🤦‍♂️ Security ain't a vibe if you're lea

See More
4 Replies
1
19

Ibrahim S AdamuFura

Full-stack Software ... • 4d

Day 15 of risking everything to build something bigger than myself. Today I set up my databases. I’m using Backblaze for storing pet images and anything media-related, and MongoDB for users and app data. Got all the API keys connected and tested suc

See More
Reply
6
Image Description

Nandeesh N

For the greater good... • 4m

HOW TO VIBE CODE EFFECTIVELY Step 2: Acknowledge the Risks and the Core Principle Before you begin, it's crucial to understand the potential pitfalls. As seen in the presentation, vibe coding without proper oversight can lead to issues like maxed-o

See More
1 Reply
5

Somen Das

Senior developer | b... • 6m

I messed up things. I am building an opensource package to connect multiple S3 compatible services like cloudflare r2, digitalocean etc. so when testing I used original API keys and I totally forgot to remove things and just did npm publish. and the

See More
Reply
3
Image Description

Ashish Kushwaha

CSE '25 || Java, JSw... • 3m

Deploying My First App on Railway Today marks a special milestone in my learning journey — I successfully deployed my first app, a Discord Bot, on Railway! Until now, I had been building and testing my projects locally. But deployment is where the

See More
2 Replies
2
11

Subhajit Chatterjee

From India For World • 4m

Forget switching to a new AI browser. Anneshon.ai is a powerful Chrome extension that brings intelligent automation directly to your current browser. Instantly summarize web pages, translate text, and let our AI draft and schedule emails for you. It

See More
Reply
2

Sheikh Ayan

Founder of VistaSec:... • 4m

📖 What is White Box Penetration Testing? White Box Penetration Testing (also called Clear Box, Glass Box, or Transparent Box Testing) is a security testing approach where the tester is given full knowledge of the target system before the assessment

See More
Reply
1

Gigaversity

Gigaversity.in • 7m

One missing .env file nearly took our production down. During one of our projects, a routine deployment went live with everything seemingly in order. But moments later, critical services started failing, and our team quickly realized that something

See More
Reply
14
Image Description
Image Description

Chetan Bhosale

 • 

Petpooja • 3m

Hey Everyone, I am launching dovia ai, vibe-coding app currently in prototype phase! ✨ We're using the Gemini free version for now, so it’s not as powerful as some of the big names yet, but we’re building some amazing features! 💡 🔗 Try it out here

See More
12 Replies
14
27
1

Tanzeem Shaikh

On a Journey to Mast... • 2m

It took me three hours (yes, hours 😭) to make a list of all the new AIs out there. Seriously, I live and breathe in this stuff—and with new tools dropping every other day, I started saving them just to test later. Well, today was that day. I actuall

See More
Reply
1
1

Download the medial app to read full posts, comements and news.