What does GitHub's security team even do?
orchidfiles.com
What does GitHub's security team even do?
1–10 of 36 posts
Re: What does GitHub's security team even do?
#2Re: What does GitHub's security team even do?
#3This (IMO) points to a perverse reality: things need to get worse before they can get better. In other words, Microsoft probably needs to feel more pain (in the form of negative revenue pressure) before they take their own platform responsibilities (vis a vis not distributing malware) seriously.
We say this play out recently with improvements to GitHub Actions security, I expect we'll see the same here.
(Edit: to be absolutely clear, I have first-hand experience that GitHub's security folks work extremely hard, and are often doing the kinds of invisible, thankless "deck-swabbing" work that nobody even thinks about. They're just under-resourced.)
Re: What does GitHub's security team even do?
#4Re: What does GitHub's security team even do?
#5Re: What does GitHub's security team even do?
#6The instability and security issues that come of relying on the software supply chain has been pointed out for around 30 years. Seriously, go look. Multiple articles have pointed out the problems we’re seeing.
I used to ask the same question on behalf of clients but after multiple non-answers and silence my response now is just put something between you and GitHub that you can control.
Re: What does GitHub's security team even do?
#7Re: What does GitHub's security team even do?
#8They're just limping along. In reality, I think Microsoft wants to kill the GitHub brand, they're just doing it slowly, feeding poison.
Re: What does GitHub's security team even do?
#9GitHub today isn't GitHub from the early-mid 2010's. Today it is a Microsoft side-gig, something they bought simply because nobody wanted theirs. But, GitHub makes good money, and turns out they're a great source of training material. They're just limping along. In reality, I think Microsoft wants to kill the GitHub brand, they're just doing it slowly, feeding poison.
Re: What does GitHub's security team even do?
#10Does GH get money for taking these actions? Do they have any monetary incentive other than 'their reputation', which clearly isn't changing usage, to improve? Maybe the best question here is why is it that after a lot of black eyes on data usage, reliability and monitoring aren't people switching. What keeps you using GH after stories like this?
I have a suggestion. PyPi and similar package managers should start publishing security warnings about the hosts of projects. That in turn can eventually lead to bans of packages from generally insecure places. Maybe if we start seeing 'WARNING: projects from github.com may contain malware!' after doing pip install XXX MS will start listening.