Live data from Hacker News

Home Depot GitHub token exposed for a year, granted access to internal systems

techcrunch.com

71–80 of 169 posts

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#71

Earlier quoted context omitted.

If you go to the home depot page for torque wrenches and click the filter for drive size, you get this list: 1/2 in 1/4 in 1 in 3/8 in 3/4 in Specialty Here is the same list in decimal to make the insanity plainly obvious: 0.5 0.25 1 0.375 0.75 What sadistic lunatic made that sort order?! It's not based on size and it's not alphabetic.

Now look up impact wrenches. 1/2 in 1 in 1/4 in 3/8 in 3/4 in 7/16 in

> 7/16 in

I had a major WTF moment there, until I realized that's probably for a hex driver (and thus something totally different than what I think of when someone says "impact wrench").

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#72
post #32

Earlier quoted context omitted.

Too busy going all-in on Flock cameras. This was the nail in the coffin for me. [0] https://deflock.me/map#map=17/33.639428/-111.976540

Not entirely unsurprising due to the theft issues they face

Yeah, I'm not sure why so many people seem pro-theft for a lack of a better term. I don't believe they are but there's so much resistance to locking up high value items especially if they're valuable ones.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#73

Given the absolute state of their website on mobile it's hardly surprising. It's faster to find an employee and ask them where an item is at instead of waiting for the search to finish, see that it the "current store" now points to a random location somewhere in a different state, pick the correct store and re-do the search

Indeed, Home Depot's software is generally so bad. I remember around 2017/2018 time frame when they started showing up to big tech conferences (especially K8s and React.js conferences) really trying to modernize. I spent a few minutes talking to the people manning the booth (which were surprisingly high ranking in the company, at least by title), and came away thinking "I'm glad you're making an effort, but y'all rea…

I'll bet money any new React/K8s/${WEBSCALE} stuff they're building is still just a wrapper over the same old inventory management they've been using for years...probably something like JDEdwards on AS/400.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#74
>When reached by TechCrunch on December 5, Home Depot spokesperson George Lane acknowledged receipt of our email but did not respond to follow-up emails asking for comment. The exposed token is no longer online, and the researcher said the token’s access was revoked soon after our outreach.

>

>We also asked Lane if Home Depot has the technical means, such as logs, to determine if anyone else used the token during the months it was left online to access any of Home Depot’s internal systems. We did not hear back.

As soon as they realized that the researcher had contacted "the media", they probably escalated internally to their legal team before anyone else, who told them to shut up.

The response, if one ever comes, will be a communication dense in lawyer-speak that admits no fault whatsoever.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#75
post #72
post #32

Earlier quoted context omitted.

Not entirely unsurprising due to the theft issues they face

Yeah, I'm not sure why so many people seem pro-theft for a lack of a better term. I don't believe they are but there's so much resistance to locking up high value items especially if they're valuable ones.

People are anti-surveillance, not pro-theft.

Although, plenty of people are pro-theft from the corporations sucking our towns and local economies dry and paying so little that their employees have to rely on foodstamps.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#76
post #72
post #32

Earlier quoted context omitted.

Not entirely unsurprising due to the theft issues they face

Yeah, I'm not sure why so many people seem pro-theft for a lack of a better term. I don't believe they are but there's so much resistance to locking up high value items especially if they're valuable ones.

Maybe you're not familiar with Flock Safety, but my comment is not about locking up high value items. It's more about my location information being shipped to weird police circles by big box stores.

[0] deflock.me

[1] https://www.youtube.com/watch?v=uB0gr7Fh6lY

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#77

Given the absolute state of their website on mobile it's hardly surprising. It's faster to find an employee and ask them where an item is at instead of waiting for the search to finish, see that it the "current store" now points to a random location somewhere in a different state, pick the correct store and re-do the search

I think the same people/platform made the Best Buy mobile website, they look very similar. Just absolutely atrocious design. It's slow, the UI elements bounce all over the place, it forgets your selections, and godspeed if for whatever reason you need to refresh the page because something chose not to render. That's outside of the store on a good connection. Doing this IN the store is a whole new level of hair pulling frustration.

Also I once asked an employee for help locating an item and they told me to pull up the app. I was like "you pull up the app", and we sat there for 5 minutes waiting for things to load until he decided he'll just help me locate the item lol

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#78

Given the absolute state of their website on mobile it's hardly surprising. It's faster to find an employee and ask them where an item is at instead of waiting for the search to finish, see that it the "current store" now points to a random location somewhere in a different state, pick the correct store and re-do the search

I think the same people/platform made the Best Buy mobile website, they look very similar. Just absolutely atrocious design. It's slow, the UI elements bounce all over the place, it forgets your selections, and godspeed if for whatever reason you need to refresh the page because something chose not to render. That's outside of the store on a good connection. Doing this IN the store is a whole new level of hair pullin…

I'm just happy that Best Buy recently added the ability to filter out items they cannot actually sell me. The amount of searches I would do where I had to scroll through page after page of 'not available online' 'not available in store' items in order to find a search result they actually had was ridiculous.

Now Home Depot for some reason just doesn't load on mobile (white screen) unless I disable content filtering in the browser. Classy.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#79
post #34

I’m surprised that GitHub, OpenAI etc. doesn’t have automation to scan the usual surfaces for hashes of their access tokens. It seems like a cheap and simple thing to offer your customers a little extra safety. Anybody interested in starting a platform agnostic service to do this?

GitHub already has a program to scan for keys, since publishing Discord tokens by mistake used to get the token immediately revoked and a DM from the system account saying why

I thought there were many first and third party services looking for this kind of thing (AWS, Github, GWS, crypto, etc tokens). Seems weird that a F500 company repo was not receiving the regular, let alone extra deep scanning which could have trivially found these.

There was a recent post from someone who made the realization that most of these scanning services only investigate the main branch. Extra gold in them hills if you also consider development branches.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#80

Earlier quoted context omitted.

I feel like the home depot website is fine. It's a lot better than most other shops, I've had a good experience finding the aisle and location of items, and it's generally accurate with the amount in stock at each location. If you didn't enable precise location or have bad cell signal then that is hardly the fault of the website.

I will not argue with the stock part. When the search _does_ finish, stock info is usually correct IME. What grinds my gears is the speed of this search, regardless of the phone reception. Even on the desktop it feels like they have a bunch of interns running a sneakernet. Or the website is laden with pointless javascript that slows everything down before the search is actually performed. I go to the same Home Depot…

> Other stores have figured this out.

Not CostCo though! I open their page and immediately 'Can Costco.ca use your location?" I say yes and then it asks me what province I'm in. I tell it, and then it defaults me to a store 30 minutes' drive from here and not the one five minutes away. Every. Time.

Post reply on HN