Live data from Hacker News

Home Depot GitHub token exposed for a year, granted access to internal systems

techcrunch.com

101–110 of 169 posts

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#101
post #90

Earlier quoted context omitted.

I've never had an employee know what a tool is, much less where to find it. All they're doing is doing this process on a slower, ruggedized phone. I literally watched someone Google "masonry bit" right in front of me.

It varies a lot by store. I’ve been to HDs where they’re all useless, and others where there’s a good number of knowledgeable DIYers working there. I think a lot of people just expect too much from a big box store employee making $17/hr… You go to HD because you have an easy job and you’re as cheap as their MBAs. If you need help, go to a supply house or an Ace Hardware or something.

Fully this. Every Ace or Do It Best I've been to in Washington has had at least one Rugged Grandpa ™ on staff who could have given me a PhD-level essay on whatever I asked them about; at Home Depot I'm lucky if the folks there have any idea what an impact-rated bit is or why I specifically need one and NO please stop trying to sell me this other crap if you're sold out of the impact bits, they are NOT the same!

(It gets worse the further from the power tools section you get, I find. I had to explain the difference between a three-prong and four-prong 240V plug once at HD and promptly told my friend to stop asking the staff for "help" finding things.)

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#102

Earlier quoted context omitted.

This is a network carrier setting, the issue is that T-Mobile (and maybe others) pushes a profile that does this as part of their network configuration.

Right, so you can't opt-out of it.

I went to Wi-Fi settings, "Edit" in top right, scroll to bottom "Managed" section, and was able to turn off "Auto-Join" for the "t-mobile" managed network just fine. I did this many months ago, I think because I was infuriated at the idea of auto-connecting to a Wi-Fi network I did not opt in to, but regardless, the checkbox has remained off through a few OS updates since (on 26.1 now with a T-Mo prepaid eSIM).

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#103
post #80

Earlier quoted context omitted.

I will not argue with the stock part. When the search _does_ finish, stock info is usually correct IME. What grinds my gears is the speed of this search, regardless of the phone reception. Even on the desktop it feels like they have a bunch of interns running a sneakernet. Or the website is laden with pointless javascript that slows everything down before the search is actually performed. I go to the same Home Depot…

> Other stores have figured this out. Not CostCo though! I open their page and immediately 'Can Costco.ca use your location?" I say yes and then it asks me what province I'm in. I tell it, and then it defaults me to a store 30 minutes' drive from here and not the one five minutes away. Every. Time.

Costco’s website is worse than useless. It doesn’t tell you anything useful beyond the hours.

I have to believe it’s intentional.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#104

Given the absolute state of their website on mobile it's hardly surprising. It's faster to find an employee and ask them where an item is at instead of waiting for the search to finish, see that it the "current store" now points to a random location somewhere in a different state, pick the correct store and re-do the search

Indeed, Home Depot's software is generally so bad. I remember around 2017/2018 time frame when they started showing up to big tech conferences (especially K8s and React.js conferences) really trying to modernize. I spent a few minutes talking to the people manning the booth (which were surprisingly high ranking in the company, at least by title), and came away thinking "I'm glad you're making an effort, but y'all rea…

It's sadly all too common. I worked at a Fortune50 retailer with a massive IT org. Was on a call one day with one of our most Senior Ent Arch who was excitedly telling me about how "these Java scripts" were the hot new thing and we were building "modern web 3.0 pages" with them. He did not understand the difference between Java and JavaScript or a blockchain branding exercise and SPAs.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#105

Earlier quoted context omitted.

If you’ve ever tried to find an employee in one of their stores, this won’t be very surprising.

Purely anecdotal, but I found Lowe's generally had much better customer service. But maybe it's just where I live

Very location dependent. Within the same metro area in one place we lived Lowes was better; in another less than 20 miles away, HD is.

But for actual help and humanity (if you can afford the price and the more limited selection), Ace is consistently better near where I am.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#106
post #34

I’m surprised that GitHub, OpenAI etc. doesn’t have automation to scan the usual surfaces for hashes of their access tokens. It seems like a cheap and simple thing to offer your customers a little extra safety. Anybody interested in starting a platform agnostic service to do this?

For things pushed to github, github has quite sophisticated secret scanning. They have a huge list of providers where they will automatically verify if a potential key is real and revoke it automatically [2], and a smaller list of generic patters they try to match if you enable the matching of "non-provider patterns".

This seems to be a case of someone accidentally publishing their github token somewhere else. I'm not sure how github would cheaply and easily prevent that. Though there are third party tools that scan your web presence for secrets, including trying wordlists of common files or directories

1: https://docs.github.com/en/code-security/secret-scanning/int...

2: https://docs.github.com/en/code-security/secret-scanning/int...

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#107
post #93
post #48

Earlier quoted context omitted.

That was true for a long time, but before that, Home Depot's customer service was terrific too. I think that's a cost that gets cut by a focus on shareholder value. Local hardware stores are still going to be better, with the caveat it may take a decade before they smile when you walk in.

> with the caveat it may take a decade before they smile when you walk in. That’s damn good customer service right there, if you ask me. The fake-chipper act makes me want to dive into a wood chipper…

I used to frequent a wonderful Ace Hardware with some regularity.

The old lady that always seemed to be behind the register eventually started greeting me by name when I walked in. (I don't recall ever giving her my name; maybe she remembered seeing on a credit card or something.)

After the pleasantries (which didn't seem fake at all), one of the greybeards present would appoint themselves as my personal shopper. I'd go down my list of demands that was only vaguely sorted by department: "One M8x1.25x80mm all-thread stainless Philips screw, a 16x20 furnace filter, a box of #8x3/4 sheet metal screws, and uh... what do you have for can openers?"

And then we'd make a lap or two of the store to get these things, and I'd pay and GTFO.

It was great.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#108

Earlier quoted context omitted.

Yeah I think it'll be location dependent. FWIW I've got both by me and they're equally terrible as far as the availability and knowledge of their employees. Lowes edges out Home Depot a tiny bit for me simply because I've never been accosted by a sanctioned in-store roaming sales person for solar or siding at Lowes (yet!).

I get hit up for gutter guards every trip at my Lowe’s. I have a stationary woman hawking Generac and HVAC installs at my Home Depot. I’d agree though, it’s department dependent. The electrical at my HD is an unorganized mess, but their plumbing section is world-class. Lowe’s is oddly flip-flopped. To Lowe’s great credit, their staff has those little tablets with inventory locations on them including all the top-shel…

HD has it, but it lies, and is horribly inaccurate.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#109

Earlier quoted context omitted.

I feel like the home depot website is fine. It's a lot better than most other shops, I've had a good experience finding the aisle and location of items, and it's generally accurate with the amount in stock at each location. If you didn't enable precise location or have bad cell signal then that is hardly the fault of the website.

its generally in HD stores you never have cell signal or wifi

Never noticed this. The SAF store has guest wifi and my mint/t-mobile 5G service inside is full strength.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#110
post #34

I’m surprised that GitHub, OpenAI etc. doesn’t have automation to scan the usual surfaces for hashes of their access tokens. It seems like a cheap and simple thing to offer your customers a little extra safety. Anybody interested in starting a platform agnostic service to do this?

For things pushed to github, github has quite sophisticated secret scanning. They have a huge list of providers where they will automatically verify if a potential key is real and revoke it automatically [2], and a smaller list of generic patters they try to match if you enable the matching of "non-provider patterns". This seems to be a case of someone accidentally publishing their github token somewhere else. I'm no…

GitHub wants to sell a service. Keys are convenient. Better alternatives in authorization and authentication exist, and GitHub is very aware of them. They even offer and facilitate them. For example, see OIDC. But many users either want keys because they're used to them or GitHub is sure they do, so they continue to offer them to avoid friction. The alternatives require more parameters, thought, and coordination between services.

GitHub has deprecated classic tokens, but the new tokens are not backwards compatible. The deprecated tokens have also continued to be available for some time. Real security professionals will tell you flatly "tokens are bad", and they're right. They're leakable attack vectors. The tokens are the problem and discontinuation is the solution. Scanning is simply symptom treating, and given what I know about Microsoft culture, I doubt that's going to change soon or quickly.

Post reply on HN