Earlier quoted context omitted.
I think it is pretty common that devs have read only access to all source code. The real question is why github has 3800 internal repos.
It's normal that a dev has *access* to all the code. But did he clone all the repos into his machine? I doubt it. So, the hacker extracted all the 3800 repos using the employee's machine as a gateway? I doubt it as well, I'm sure they would have detected this huge amount of data much earlier than transferring all of it? > The real question is why github has 3800 internal repos. I guess they mean customer's private re…
GitHub is investigating unauthorized access to their internal repositories
111–120 of 359 posts
Re: GitHub is investigating unauthorized access to their internal repositories
#112Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/
Re: GitHub is investigating unauthorized access to their internal repositories
#113Earlier quoted context omitted.
It's certainly not the right platform. It'd be one thing if they had any official communication on the matter anywhere else. Maybe they're ashamed and are trying to limit the visibility while only technically issuing an announcement. They announced this exclusively on X.com, which ranks barely above Pinterest in terms of usage. That's below Reddit, Snapchat, WeChat, and Instagram, and requires a user account to view…
[flagged]
Re: GitHub is investigating unauthorized access to their internal repositories
#114Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/
Re: GitHub is investigating unauthorized access to their internal repositories
#115Re: GitHub is investigating unauthorized access to their internal repositories
#116Why did one developer have access, even if read-only, to more than 3,800 internal repos?
Re: GitHub is investigating unauthorized access to their internal repositories
#117Re: GitHub is investigating unauthorized access to their internal repositories
#118Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/
It's been pretty common in the past for tech companies to announce outages and quick updates about them on twitter for decades. I'm sure their status page etc will be updated soon, but it's historically been the fastest way to get things out to the wider audience whilst bypassing the "official mail out" review by marketing etc.
Re: GitHub is investigating unauthorized access to their internal repositories
#119This is bad. If they came out announcing this, without a long winded explanation and further details, it's because they're staring at a bottomless pit and they haven't put the lid on it yet. For a Fortune 100, to go out of your way to spook investors is the least desirable approach.
I don't remember the exact wording about what qualifies as "incident" or "major incident" but the TL;DR is that the regulated entities are required to notify their regulators of impactful supplier incidents within 24h with initial information and within 72h with more complete details.
Which in turn means that Github will have signed contracts that bind them to accommodating timelines.
Re: GitHub is investigating unauthorized access to their internal repositories
#120Why did one developer have access, even if read-only, to more than 3,800 internal repos?