Live data from Hacker News

Home Depot GitHub token exposed for a year, granted access to internal systems

techcrunch.com

121–130 of 169 posts

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#122

Earlier quoted context omitted.

Right, so you can't opt-out of it.

I went to Wi-Fi settings, "Edit" in top right, scroll to bottom "Managed" section, and was able to turn off "Auto-Join" for the "t-mobile" managed network just fine. I did this many months ago, I think because I was infuriated at the idea of auto-connecting to a Wi-Fi network I did not opt in to, but regardless, the checkbox has remained off through a few OS updates since (on 26.1 now with a T-Mo prepaid eSIM).

There's no "Managed" section showing up on my phone and the last time I set that network to not auto-join it still did. Lesson learned, I just turn off WiFi and Bluetooth before heading out to Home Depot.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#123
Last week I accidentally exposed my OpenAI, Anthropic, and Gemini keys. They somehow ended up in Claude Code logs(!) Within seconds I got an email from Anthropic and they have already disabled my keys. Neither OpenAI nor Google alerted me in anyway. I was able to login to OpenAI and delete all the keys quickly.

Took me a good 10-15 minutes to _just_ _find_ where Gemini/AI Studio/Vortex projects keys _might_ be! I had to "import project" before I could find where the key is. Google knew key was exposed but the key seemed to be still active with a "!" next to it!

With a lot of vibe coding happening, key hygiene becomes crucial on both issuer and user ends.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#124

What's the biggest damage someone could have done with that info?

- Download all the source code and look for vulnerabilities at their leisure.

- Depending on whether they use GH for deployments they can also introduce features to production that can help them

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#125

Given the absolute state of their website on mobile it's hardly surprising. It's faster to find an employee and ask them where an item is at instead of waiting for the search to finish, see that it the "current store" now points to a random location somewhere in a different state, pick the correct store and re-do the search

If you go to the home depot page for torque wrenches and click the filter for drive size, you get this list: 1/2 in 1/4 in 1 in 3/8 in 3/4 in Specialty Here is the same list in decimal to make the insanity plainly obvious: 0.5 0.25 1 0.375 0.75 What sadistic lunatic made that sort order?! It's not based on size and it's not alphabetic.

SELECT ... ORDER BY RAND()

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#126
post #123

Last week I accidentally exposed my OpenAI, Anthropic, and Gemini keys. They somehow ended up in Claude Code logs(!) Within seconds I got an email from Anthropic and they have already disabled my keys. Neither OpenAI nor Google alerted me in anyway. I was able to login to OpenAI and delete all the keys quickly. Took me a good 10-15 minutes to _just_ _find_ where Gemini/AI Studio/Vortex projects keys _might_ be! I had…

> With a lot of vibe coding happening

I shudder to think of the implications.

Consider all the security disasters we already get from brogramming, and multiply that, times 100.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#127

Earlier quoted context omitted.

They probably don't have any repeaters. All those metal shelves are going to interfere with the signal. I have the same experience.

Their in-store WiFi is a repeater more or less. It's one of those bullshit forced auto-join networks that you can't opt out of (at least on iOS). Because that's not a massive vector for phishing or anything.

I was livid when I discovered that my carrier had implemented that with no opt out. I worked around it by implementing shortcuts that disable my iPhone's WiFi when I leave my house until I've returned or reached one of the handful of other places I use it. It's ridiculous that something like that is necessary, though.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#129
post #119

Earlier quoted context omitted.

I don't know how well lumber holds up to the bottom of the ocean

Pretty good actually. With the salt, lack of oxygen and pressure it can last quite a long time.

Presumably you'd want human habitable atmosphere on the inside of the sphere, which would radically change the equation against the use of wood unfortunately.
Post reply on HN