Live data from Hacker News

GitHub is investigating unauthorized access to their internal repositories

twitter.com

321–330 of 359 posts

Re: GitHub is investigating unauthorized access to their internal repositories

#321

Earlier quoted context omitted.

And your reason for believing this is…

1. We've seen LLMs detect existing supply chain attacks when pointed at malicious install scripts. This is direct, empirical support for my position. 2. We have a long history of using heuristic technologies to detect attacks. We can infer that other heuristic technologies can be combined in a successful manner. 3. Shortcomings of LLMs are directly addressed by removing attacker controlled information from the input,…

Calling an anecdotal observation “empirical” is a new one.

I stopped reading after that.

Re: GitHub is investigating unauthorized access to their internal repositories

#322

Earlier quoted context omitted.

1. We've seen LLMs detect existing supply chain attacks when pointed at malicious install scripts. This is direct, empirical support for my position. 2. We have a long history of using heuristic technologies to detect attacks. We can infer that other heuristic technologies can be combined in a successful manner. 3. Shortcomings of LLMs are directly addressed by removing attacker controlled information from the input,…

Calling an anecdotal observation “empirical” is a new one. I stopped reading after that.

> Calling an anecdotal observation “empirical” is a new one.

I guess maybe you've learned a new word today? Hope so.

Re: GitHub is investigating unauthorized access to their internal repositories

#323

Earlier quoted context omitted.

I just spent a few minutes trying to think of a better place, I can't think of one, there is no professional social network, and linkedin doesn't qualify.

You don't need a professional network. This is a company informing customers about a security issue. It should be on their website. Anyone can subscribe to the RSS feed if they are a customer. Remember RSS? There is no need to add a social network element.

While I do agree, I feel like they control the entire discussion if they run their own rss.

Re: GitHub is investigating unauthorized access to their internal repositories

#324
post #252

If they do leak it all, these are the first one's im digging into out of curiosity 3329:-rw-r--r-- 1 root root 62971493 May 18 22:52 spam-investigations.tar.gz 3330:-rw-r--r-- 1 root root 7915019 May 18 22:55 spamops.tar.gz 680:-rw-r--r-- 1 root root 306146 May 18 23:14 copilot-abuse-dashboard.tar.gz 681:-rw-r--r-- 1 root root 219637 May 18 23:03 copilot-abuse.tar.gz 2245:-rw-r--r-- 1 root root 55838 May 18 23:14 le-…

Where is this list from?

Everytime it is BreachForums: https://breached.st/threads/internal-github-source-code.8739...

Re: GitHub is investigating unauthorized access to their internal repositories

#325

Earlier quoted context omitted.

And your reason for believing this is…

1. We've seen LLMs detect existing supply chain attacks when pointed at malicious install scripts. This is direct, empirical support for my position. 2. We have a long history of using heuristic technologies to detect attacks. We can infer that other heuristic technologies can be combined in a successful manner. 3. Shortcomings of LLMs are directly addressed by removing attacker controlled information from the input,…

I don’t deny that LLMs can detect some attacks. I just don’t think they can be made to do so reliably.

Re: GitHub is investigating unauthorized access to their internal repositories

#326
post #316

Earlier quoted context omitted.

It's to point out how comparatively small X is. It's in the same ballpark as Pinterest and Quora. Github decided not to use email (which every Github customer has), their sites, or their otherwise active BlueSky.

It's not small in the tech community though. Users are not distributed evenly among platforms. Others may have more users but not as many tech users.

Maybe, but I don't use it and nobody I know uses it. It's a very politically divisive platform, and users without an account can't post on there.

There are plenty of reasons not to use X, but that's not what's in contention. X.com was the _only_ platform they shared this information on.

It bears repeating: Github decided not to use email, which every GitHub customer has, and Github chose not to use their sites, and GitHub chose not to use their otherwise active BlueSky.

Re: GitHub is investigating unauthorized access to their internal repositories

#327
post #18

The security issue aside, seeing more companies push announcements like these on X as the only official source is a trend I'm not sure I like. I can understand the rationale, this feels lighter and not something that belongs on status.github.com or the blog. Maybe what's actually missing is an official channel for ephemeral stuff on a domain they own, somewhere between a status page and a tweet? Just sharing an obser…

[deleted]

Re: GitHub is investigating unauthorized access to their internal repositories

#328
post #141

Most large companies won’t allow direct access to Docker hub or PyPI, and now they’ll have to restrict access to VSCode extensions. How did the extension get poisoned?

We run an explicit whitelist, enforced through Microsoft Entra (or was it Intune).

That’s also a nice idea.
Post reply on HN