Defaults decide: example secrets, new timeouts and a privacy model that needs two companies
Four items from the past few days look unrelated: a batch of security advisories, a web-server patch, a package-manager patch and a privacy product. Read together, they are about defaults, the values a system uses when nobody makes a deliberate choice.
The default that was a secret. In Trigger.dev's advisories, the critical problems were not clever exploits. A coordinator endpoint authenticated with a fixed string, coordinator-secret, written in the public source, and the Docker example file shipped fixed keys for signing login links. The override variables were undocumented, so the safe path required reading the code. Self-hosters who followed the docs ran the defaults.
The default that broke streaming. Caddy 2.11.6 added sensible-sounding idle read and write timeouts by default. They cut server-sent-event streams at exactly 60 seconds and could crash the HTTP/2 proxy path; 2.11.7 fixes both. The release that followed also adopted the Incremental header from RFC 10036, a standard way for an application to tell a proxy not to buffer, instead of relying on each proxy's default.
The default that cost 50 megabytes. pnpm 12.9.1 took a WebAssembly build out of its main package, bringing it back from about 55 MB to about 4 MB. Every user had been downloading an artefact only WebContainer users needed, because it was included by default.
The default the protocol forbids. Cloudflare's new OHTTP Gateway exists because Oblivious HTTP's privacy holds only if the relay and the gateway are run by different, non-colluding parties. The convenient default, buying both from the same provider, removes the guarantee entirely, and nothing in the traffic would show it.
What they share. None of these failures needed an attacker to be clever. Each came from a value that someone accepted rather than chose: a secret copied from an example, a timeout inherited from an upgrade, a dependency bundled for a minority, an architecture where one company holds both keys. The fixes are equally unglamorous: remove the default, document the override, make the choice explicit.

What it means
Most configuration reviews check what a team set. The more useful review lists what it did not set, and asks where each of those values came from. For self-hosted platforms that means diffing deployed secrets against the project's public examples; for proxies, reading the release notes of every minor version for new defaults; for privacy architectures, writing down which company operates each hop.