Microsoft's GitHub account allegedly hacked, 500GB stolen
11–20 of 126 posts
Re: Microsoft's GitHub account allegedly hacked, 500GB stolen
#12> In a directory listing and samples of other private repositories sent to BleepingComputer, the stolen data appears to be mostly code samples, test projects, an eBook, and other generic items. Other than private keys or sensitive info being left behind, doesn't appear to be severe. Looks nothing burger given the data until more is released. > Microsoft employee Sam Smith replied to Under the Breach's tweet stating t…
I guess they have internal Git servers, since they develop VFS for Git[1] to handle large amount of files in git, but IIRC github isn't support it yet
Re: Microsoft's GitHub account allegedly hacked, 500GB stolen
#13Re: Microsoft's GitHub account allegedly hacked, 500GB stolen
#14Re: Microsoft's GitHub account allegedly hacked, 500GB stolen
#15So a closed source software company buys an open source tool company, and inadvertently make closed source open source! Or, in other words, if you want to keep something private, don't put it in the "cloud"!
The lesson I carry is that the more secret it something is, the closer to my brain it is. Top-secret = only in my head, little bit secret = encrypted on my harddrive, little less secret = encrypted in the cloud, not secret at all = just dumped in a Google Drive account
Re: Microsoft's GitHub account allegedly hacked, 500GB stolen
#16> This evening, a hacker going by the name Shiny Hunters contacted BleepingComputer to tell us they had hacked into the Microsoft GitHub account, gaining full access to the software giant's 'Private' repositories. Well, someone asked the other day whether or not private repositories on GitHub were safe: [0] I think you now have a concrete answer regardless if this is true or not. I have already made the case to priva…
I don't think this is necessarily true. Microsoft's org, like any large org, has a large number of users with access. Its security is dependent on each one of those many accounts being secure.
A smaller org, or an individual, can secure their repositories much more easily as there's fewer entrypoints.
They haven't mentioned whether this hack was achieved by compromising individual account credentials, or by compromising the Github platform itself. If it's the latter, you may be right, but I suspect it's more likely the former.
Re: Microsoft's GitHub account allegedly hacked, 500GB stolen
#17Re: Microsoft's GitHub account allegedly hacked, 500GB stolen
#18> In a directory listing and samples of other private repositories sent to BleepingComputer, the stolen data appears to be mostly code samples, test projects, an eBook, and other generic items. Other than private keys or sensitive info being left behind, doesn't appear to be severe. Looks nothing burger given the data until more is released. > Microsoft employee Sam Smith replied to Under the Breach's tweet stating t…
Re: Microsoft's GitHub account allegedly hacked, 500GB stolen
#19> In a directory listing and samples of other private repositories sent to BleepingComputer, the stolen data appears to be mostly code samples, test projects, an eBook, and other generic items. Other than private keys or sensitive info being left behind, doesn't appear to be severe. Looks nothing burger given the data until more is released. > Microsoft employee Sam Smith replied to Under the Breach's tweet stating t…
Re: Microsoft's GitHub account allegedly hacked, 500GB stolen
#20Awfully boring things to breach. Not very exciting except for the fact that some employee probably installed nudez.exe.