Vercel employee used customer information to pursue a personal trademark matter
twitter.com
twitter.com
1. Vercel shipping Indie hackers projects ( their customers) as "app templates" as a host, for marketing purpose
https://twitter.com/nico_jeannen/status/1712749652133683632?...
2. The mentioned infringement of a Vercel employee, mentioned here ( he seems to be fired)
https://twitter.com/nico_jeannen/status/1713139186474406206?...
3. Very broad ToS -> Vercel may delete your app for no reason at all
https://twitter.com/bk_7312/status/1713197808264839479?t=h1T...
This combined with their marketing strategy of copying popular indie products and turning them into NextJS templates creates paranoia in the minds of builders who trust Vercel with their codebases, analytics, and often even their data (via Vercel's storage products).
It seems that an enterprising Vercel employee has a goldmine of data to help inform their next "side project".
Suing for copying your product is tricky. In general I wouldn't rely on courts to protect your product IP. Execution is the only real moat. Any good product will have many copycats and competitors.
At every decent sized company I've worked for, topics like production data privileges, data classification (public, sensitive, confidential, etc.), data masking, and data anonymization for testing have been top priorities. And these policies are sometimes a true pain in the ass for developers, but they exist for a good reason.
I guess you shouldn't miss the timing to go from "move fast and break things" to "ok we're now a serious business".
Having run a couple of businesses and feeling the pain I still don't see how to better the situation. It's good that businesses are put under pressure, because if they are not, bad actors would run wild. It is bad that running any business, at least to me, feels like navigating a minefield, and good actors are negatively impacted by that disproportionally.
Personally, I have come to accept that, no matter how hard you can reasonably try, with any business and at any given moment, there is a number of things that if somebody looked very closely, that would probably raise some red flags, because the cost of safeguarding against all of them is infinite.
Is there some tech incubator clause buried in their TOS and this is all okay?
Also Vercel/NextJS is like if DHH was charging people to use Rails. We are in the “enshittification” part of react development.
is this satire?
(By the way, don't forget that [] or it does a completely different thing that you never want.)
I'm sorry, the entire community rallied around hooks PRECISELY because the life cycle methods were not clear and were very problematic.
It seems extremely strange to see such opinions.
When you see a hook you know exactly when it's going to execute and why and because of what. You don't have to layer the methods with tons of checks making sure the life cycle method has been run in the right context, it literally just works.
Anyway, both are fine and usable haha. Just think there are arguments to be made on both sides.
It's complicated. If you want the vercel like experience of deploying to a serverless environment it's not as trivial. There is a reason that open-next exists.
Between MUI and Next and RTK-query, IMO, React is finally approaching something usable and complete.
Not a React fanboy. I loved Angular v1, in fact. Just hate how minimalist and useless vanilla React was.
Edit: And maybe this is a problem of scale too. At Meta's size or similar, React is just one component and one team that works alongside dozens of others to deliver a working product. But when they open source it, smaller companies and individuals also try to use it but without Meta's scale and resources. And they inevitably find it lacking because they don't have whole teams working on the rest of the problem (like basic routing, which Meta handles in their derivative of PHP, I think?) , so they have to hope someone else (like react router) solved that problem in a drop-in way. That's why Next is so magical for small and medium businesses; they do a lot of that curation and infra building for you, for a reasonable fee.
And being a Vercel customer has been wonderful. Their systems are so much nicer to work with than legacy web stacks/VMs/containers, or trying to hook something up in PHP or Java. The dev ex is awesome, being able to `create-next-app` and deploy to Vercel in like 3 minutes.
currently, deploying on vercel is so easy and the project structure works on any other compute instance that migrating away will be easy too, and breaking versions of Next or NextAuth can just not be used
Vercel is a business with a very good value proposition. And Next is open source with a huge community. It's not perfect, and Vercel isn't perfect, but among its peers (the web industry) it stands out to me as one of the two companies I'd trust to steward the future of the web (the other being Cloudflare). Way way way more so than Meta or Google, because at the end of the day at least these companies are selling good web hosting, not shitty advertising, and aren't run by total dicks either.
Do I wish they were nonprofits with shared governance? Yeah, maybe. But short of that, their track record has actually been incredible.
The web is still immature enough (surprising, I know) that new companies and technologies rise and fall all the time. Today's vendor lock-in is tomorrow's opportunity for another young upstart, the same way Next was to React, the way React was to Angular, the way Angular was to the frameworks before it. I'm not too worried.
It doesn't make sense to be afraid of Next when it's really just repackaged cloud hosting in a very shiny wrapper. They resell AWS and GCP and Cloudflare infra at a markup but make it much much easier to use. It's a win win for everyone as far as I can tell.
We are talking about an employee who has access to the customers personal information as part of their job doing something unethical.
I would be extremely surprised if Vercel didn't have industry systems and practices in place for security.
This is an edge case which can only be avoided by building Google-esque systems and practices. I don't think you guys really understand what your asking for here.
This will cripple them in so many ways, it makes so much more sense delay it as long as possible. Not because they can save a bit of money, but because they UX will fall of a cliff, feature velocity will ground to a halt and the product will drift further away from stuff we really want.
I am sure a half motivated employee at your favorite cab service could see which addresses you frequently commuted to in first few years of that service's existence