Live data from Hacker News

GitHub is investigating unauthorized access to their internal repositories

twitter.com

291–300 of 359 posts

Re: GitHub is investigating unauthorized access to their internal repositories

#291

Earlier quoted context omitted.

As a developer or security researcher, you're able to download and run GitHub Enterprise Server. I'm not sure having access to the full source code makes a meaningful difference for most of GitHub's surface area, given it's largely Ruby.

LLMs can't really parse compiled code to find exploits, maybe code in scripting languages (python, js, etc) even if minified. So I don't quite agree with you, having access to the source can definitely help find exploits even in pre-LLM days.

Pretty much everyone disagrees with you, especially when you add in decompiler tools to the LLM.

Re: GitHub is investigating unauthorized access to their internal repositories

#292
post #49

Sympathy to engineers and everyone at github, it's good that they're being open even if findings are limited. I'm sure they will figure out the root cause and will publish results to be a learning experience for everyone else

Microsoft’s GitHub was compromised when a Microsoft developer using Microsoft VSCode installed a rogue extension from Microsoft’s VSCode extension library, which is moderated and hosted by Microsoft.

via: news.ycombinator.com/item?id=48204312

Re: GitHub is investigating unauthorized access to their internal repositories

#294
post #252

If they do leak it all, these are the first one's im digging into out of curiosity 3329:-rw-r--r-- 1 root root 62971493 May 18 22:52 spam-investigations.tar.gz 3330:-rw-r--r-- 1 root root 7915019 May 18 22:55 spamops.tar.gz 680:-rw-r--r-- 1 root root 306146 May 18 23:14 copilot-abuse-dashboard.tar.gz 681:-rw-r--r-- 1 root root 219637 May 18 23:03 copilot-abuse.tar.gz 2245:-rw-r--r-- 1 root root 55838 May 18 23:14 le-…

Where is this list from?

It's the filetree the threat actors, TeamPCP, released of what they exfil'd.

see the full one @ hxxps://limewire[.]com/d/4HPnj#dbRR3wQb4u

Re: GitHub is investigating unauthorized access to their internal repositories

#295
post #252

If they do leak it all, these are the first one's im digging into out of curiosity 3329:-rw-r--r-- 1 root root 62971493 May 18 22:52 spam-investigations.tar.gz 3330:-rw-r--r-- 1 root root 7915019 May 18 22:55 spamops.tar.gz 680:-rw-r--r-- 1 root root 306146 May 18 23:14 copilot-abuse-dashboard.tar.gz 681:-rw-r--r-- 1 root root 219637 May 18 23:03 copilot-abuse.tar.gz 2245:-rw-r--r-- 1 root root 55838 May 18 23:14 le-…

The existence of a explicitly named "front-door" implies there is also a ....

Re: GitHub is investigating unauthorized access to their internal repositories

#296
post #49

Sympathy to engineers and everyone at github, it's good that they're being open even if findings are limited. I'm sure they will figure out the root cause and will publish results to be a learning experience for everyone else

Microsoft’s GitHub was compromised when a Microsoft developer using Microsoft VSCode installed a rogue extension from Microsoft’s VSCode extension library, which is moderated and hosted by Microsoft. via: news.ycombinator.com/item?id=48204312

Built with packages hosted on Microslop's NPM

Re: GitHub is investigating unauthorized access to their internal repositories

#297

Earlier quoted context omitted.

I probably wouldn't believe that "shredding". Also there will be legal consequences I think?

counter intuitively criminal ransomware gangs operate on trust. They have to ensure that we believe they really will shred it, otherwise no victim will ever pay a ransom ever again. Therefore one way to weaken these criminals would be to weaken this trust factor. In a way therefore comments like "can we actually believe they will really shred it" goes towards this aim. I have to wonder what criminal hacking gangs tha…

And if the company doesn’t pay it they would therefore have to go through with their threat to publish it.

More than likely they will just claim that the company paid the ransom and never release the code (or at least not immediately).

Re: GitHub is investigating unauthorized access to their internal repositories

#299

Earlier quoted context omitted.

I think the other side is much more important. With company mandates to use AI as much as possible, there has been a deluge of low-quality PRs. Everybody is feeling tired from reviewing those, and quite possibly numerous security issues have been introduced since.

This really feels like what's happening where i work. Management wants everything done yesterday. Juniors and seniors alike are giving me pure slop PRs to review. I point out an issue and the next draft from Claude has two more. It's extremely exhausting, and it's not like I'm reviewing every PR or catching every issue.

I was trying to go against the tide for the longest time by providing detailed reviews, understanding every line of code, leave meaningful comments, improve architecture, etc.. Then management started pushing AI more and more and explicitly called out PR reviews as a bottleneck, timelines shortened, and more and more slop got pushed.

I gave up and I'm now a happy "AI enthusiast" at my company, handing out AI slop reviews for AI slop PRs. Deep down, I don't care anymore, if that's what they want, that's what they'll get, and it's no longer my problem if stuff leaks through that brings down prod or worse. Oh, and I'm also in line for a promotion this coming quarter thanks to my new found "velocity".

Re: GitHub is investigating unauthorized access to their internal repositories

#300
post #228

Earlier quoted context omitted.

Much more reasonable to oppose 2026 X as the default platform than it was to oppose 2015 Twitter as the default platform. I mean reasonable both times but you obviously understand why one might have changed their mind in recent years

Asking on behalf of Github’s PR team: what is the suggested alternative to X to post our updates to reach the largest amount of people, companies, as well as promote our brand? I haven’t seen any suggestion in this thread. status.github.com fails many of these criteria.

Bluesky is much better for this type of thing. It functions like X did 10 years ago: anyone can read the posts and subsequent thread, even if they don't have a Bluesky account.

The main non-political issue with X is that those without an account (or who are unable to login) may not be able to access it, which isn't ideal for a backup communications channel. Best of both worlds is to set up mirroring where you post to bluesky and automatically post a copy to X.

Post reply on HN