Live data from Hacker News

GitHub is investigating unauthorized access to their internal repositories

twitter.com

211–220 of 359 posts

Re: GitHub is investigating unauthorized access to their internal repositories

#211
post #169

Earlier quoted context omitted.

I just moved to Zed (zed.dev). Has everything I need

does it have some kind of sandboxing for its extensions?

They are compiled to WASM, so they have limited IO capabilities, but still they have IO.

Re: GitHub is investigating unauthorized access to their internal repositories

#212
post #103

Do they know what the attackers were after? Maybe they were just trying to help fix the availability problems.

The availibilty problems are caused by incapable managers overloading Azure boxes, code fixes will not help much. Maybe they get into HR and help get them fired. And help rehire the ones who could fix it. But that needs a nation state actor, not just your best hacker group.

Re: GitHub is investigating unauthorized access to their internal repositories

#214

That's the reason I stopped installing random extensions and even themes in VS Code, they are too dangerous.

editor themes seem like a good candidate for something that someones trusted local LLM could generate for them

Re: GitHub is investigating unauthorized access to their internal repositories

#215

Earlier quoted context omitted.

It's been pretty common in the past for tech companies to announce outages and quick updates about them on twitter for decades. I'm sure their status page etc will be updated soon, but it's historically been the fastest way to get things out to the wider audience whilst bypassing the "official mail out" review by marketing etc.

I think that was a lot more justifiable when Twitter reliably let logged out users read tweets. X seem to tweak it all the time, or maybe it’s just broken a lot, but sometimes I can’t even load a tweet in a browser that isn’t logged in.

They broke it not too long before Musk bought it when they wanted to boost user numbers.

It'll frequently display tweets from literal years ago as being the latest.

It's why proxies/mirrors are often linked rather than Twitter itself.

They don't seem to care to fix it, which implies that it's intentional. Seems completely stupid but what do I know?

Re: GitHub is investigating unauthorized access to their internal repositories

#217
post #168

Earlier quoted context omitted.

Just in case you are not aware, a joke loses its fun factor if you explain it.

On hn, a joke increases its fun factor by being over-explained in excruciating detail with several digressions into related jokes and the history and philosophy of joking, and someone ends up showing a site they made with all the possible variations of that joke and something about the scrolljacking css annoys one of the commenters enough that they break in and fix it.

A variation of that joke is used in Zen Buddhism as a teaching story. A famous monk, who lived in voluntary poverty in a mountain hut, wakes up in the middle of the night because a robber had broken in - except the robber couldn't find anything of value. So the monk listened to the rummaging sound for a while, and feeling bad for the robber's family, offers his blanket. The robber is so surprised by the kindness of the monk that he gives up his stealing ways and decides to become a good guy.

Re: GitHub is investigating unauthorized access to their internal repositories

#219
post #101

Sure, I'm frustrated by the github outages too, but hacking into github to fix their code seems like a bit of an overreaction.

It feels like it would be the natural direction of an AI agent tasked with improving uptime of their solution without bounds on how it achieved it.

Re: GitHub is investigating unauthorized access to their internal repositories

#220

Why did one developer have access, even if read-only, to more than 3,800 internal repos?

I think it is pretty common that devs have read only access to all source code. The real question is why github has 3800 internal repos.

3800 repos without any orgs/groups must be fun..

*assuming github dogfoods github

Post reply on HN