Live data from Hacker News

GitHub is investigating unauthorized access to their internal repositories

twitter.com

201–210 of 359 posts

Re: GitHub is investigating unauthorized access to their internal repositories

#201
Seems like disgruntled tech bros who lost their jobs to AI are now wrecking havoc on tech platforms.

This is going to create so much work and job security for software developers.

Large companies are going to have to adopt all kinds of policies and bureaucratic processes to protect themselves from supply chain attacks. It's going to increase the amount of engineering work, create new blockers, increase the on-boarding time for new tech talent. I suspect that software devs are going to get their jobs back with a thick, cushiony layer of bureaucracy on top.

Software developers are a bit like lawyers. As an aggregate, they have the capacity to create problems which translate directly into billable hours for themselves.

Re: GitHub is investigating unauthorized access to their internal repositories

#202
post #116

Why did one developer have access, even if read-only, to more than 3,800 internal repos?

Read-only access to all non-sensitive code is how things should be. Huge engineering culture and productivity booster. It’s also very useful to keep each other honest (I’ve found so many “interesting” things hidden away in organizations with tight read access restrictions).

It’s called “inner source”, I’m also a fan of such a culture.

Re: GitHub is investigating unauthorized access to their internal repositories

#204
post #153
post #71

GitHub: " Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far." Oof https://xcancel.com/github/status/2056949169701720157

directionally, how bad is this ?

let's take this offline and circle back on it

Re: GitHub is investigating unauthorized access to their internal repositories

#205
post #153
post #71

GitHub: " Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far." Oof https://xcancel.com/github/status/2056949169701720157

directionally, how bad is this ?

directionally very bad

Re: GitHub is investigating unauthorized access to their internal repositories

#207

That's the reason I stopped installing random extensions and even themes in VS Code, they are too dangerous.

Pro tip: In vscode, you can specify which plugin publishers are allowed.

You can set this to only allow plugins from Microsoft, which is a company most people trust and also owns Github.

Oh wait...

Re: GitHub is investigating unauthorized access to their internal repositories

#208
post #103

Do they know what the attackers were after? Maybe they were just trying to help fix the availability problems.

This comment reminds me of a joke where the punchline is that a person is so poor that burglars break in to their house and leave money. Similarly, I could see ransomware groups hacking in and feeling bad for GH so they improve a few things to help them get to at leave nine fives of uptime.

There was a worm that patched vulnerabilities in mikrotik couple of years ago.

Re: GitHub is investigating unauthorized access to their internal repositories

#209

That's the reason I stopped installing random extensions and even themes in VS Code, they are too dangerous.

I just moved to Zed (zed.dev). Has everything I need

Zed installs all kind of random crap without asking you and once done it's total memory usage is on par with vscode is not higher.

Plus, it runs like shit on Linux.

Re: GitHub is investigating unauthorized access to their internal repositories

#210
post #168

Earlier quoted context omitted.

This comment reminds me of a joke where the punchline is that a person is so poor that burglars break in to their house and leave money. Similarly, I could see ransomware groups hacking in and feeling bad for GH so they improve a few things to help them get to at leave nine fives of uptime.

Just in case you are not aware, a joke loses its fun factor if you explain it.

Unfortunately on HN people who don't get the joke tend to down vote it, so there's an incentive for pre emptive explanation.
Post reply on HN