Live data from Hacker News

GitHub is investigating unauthorized access to their internal repositories

twitter.com

71–80 of 359 posts

Re: GitHub is investigating unauthorized access to their internal repositories

#71
GitHub: " Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far."

Oof

https://xcancel.com/github/status/2056949169701720157

Re: GitHub is investigating unauthorized access to their internal repositories

#72

Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/

It's certainly not the right platform. It'd be one thing if they had any official communication on the matter anywhere else. Maybe they're ashamed and are trying to limit the visibility while only technically issuing an announcement. They announced this exclusively on X.com, which ranks barely above Pinterest in terms of usage. That's below Reddit, Snapchat, WeChat, and Instagram, and requires a user account to view…

[dead]

Re: GitHub is investigating unauthorized access to their internal repositories

#73

Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/

It's certainly not the right platform. It'd be one thing if they had any official communication on the matter anywhere else. Maybe they're ashamed and are trying to limit the visibility while only technically issuing an announcement. They announced this exclusively on X.com, which ranks barely above Pinterest in terms of usage. That's below Reddit, Snapchat, WeChat, and Instagram, and requires a user account to view…

> Maybe they're ashamed and are trying to limit the visibility while only technically issuing an announcement.

I think that's panic mode from some decision maker (i.e. head of marketing or head of security).

Re: GitHub is investigating unauthorized access to their internal repositories

#74

Earlier quoted context omitted.

So? Is this where your corporate paying clients should find out about an issue of this severity? Not to mention Twitter is not an open platform anymore! (A) I'm an employee in an organization paying for Github. (B) I don't have a Twitter account. I already have a Github account because of (A). Why should (B) stop/delay me from getting official comms about this?

I can't imagine they'd spam every account with an email address, though an email to organization owners would make more sense.

Mailing every (potentially) affected entity is common and good practice for major incidents.

Re: GitHub is investigating unauthorized access to their internal repositories

#77

Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/

It's certainly not the right platform. It'd be one thing if they had any official communication on the matter anywhere else. Maybe they're ashamed and are trying to limit the visibility while only technically issuing an announcement. They announced this exclusively on X.com, which ranks barely above Pinterest in terms of usage. That's below Reddit, Snapchat, WeChat, and Instagram, and requires a user account to view…

[flagged]

Re: GitHub is investigating unauthorized access to their internal repositories

#79

Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/

They should send messages directly to their customers as a first step in addition to posting an official article on their site. That’s the minimum. If they haven’t done that then it is hard to defend.

Beyond that, Twitter is the de facto default dissemination vehicle, due to its reach. Even if people are not on Twitter, they are likely to see things from people that are on Twitter.

Re: GitHub is investigating unauthorized access to their internal repositories

#80
post #26

Earlier quoted context omitted.

It reminds me of the famous "mistakes were made" Nixon quote. "We are investigating unauthorized access" sounds much better than "we've been hacked"

This reminds me of George Carlin standup routine about PTSD. If you want to make any bad news sound less bad, just wrap the concept around complicated jargon to sterilize it.

Carlin would have loved watching the big tech companies fall victim to the very LLMs they created.
Post reply on HN