Live data from Hacker News

What does GitHub's security team even do?

orchidfiles.com

31–36 of 36 posts

Re: What does GitHub's security team even do?

#31

GitHub today isn't GitHub from the early-mid 2010's. Today it is a Microsoft side-gig, something they bought simply because nobody wanted theirs. But, GitHub makes good money, and turns out they're a great source of training material. They're just limping along. In reality, I think Microsoft wants to kill the GitHub brand, they're just doing it slowly, feeding poison.

> Today it is a Microsoft side-gig, something they bought simply because nobody wanted theirs.

Theirs? Perforce, TeamServer aren't really competing with GitHub.

Re: What does GitHub's security team even do?

#32

GitHub's response time on malicious repositories is often lackluster. However, from conversations with folks at GitHub, my suspicion is that this is because they're being starved for resources, not incompetency or maliciousness. This (IMO) points to a perverse reality: things need to get worse before they can get better. In other words, Microsoft probably needs to feel more pain (in the form of negative revenue press…

Reminds me of when Windows security problems hit critical mass in the early-2000s and Microsoft went all-in on addressing it (this started in the XP days IIRC).

The post-release XP service packs, to be precise. XP's release was a perfect storm of events: Suddenly, millions of home users receiced an OS that had dozens of networked RPC services running in the background, and received DSL modems around the same time that exposed their computer directly to the internet. A slightly suboptimal combination at a time when software firewalls were a separate product you had to buy for a hundred dollars a year, if you even knew they were a thing.

Re: What does GitHub's security team even do?

#33
post #6

So far this year 40% of my contracts have been a recovery from a Shai Hulud like attack. That’s in the area of 750k profit and more spent by the companies. The instability and security issues that come of relying on the software supply chain has been pointed out for around 30 years. Seriously, go look. Multiple articles have pointed out the problems we’re seeing. I used to ask the same question on behalf of clients b…

[flagged]

Re: What does GitHub's security team even do?

#34

GitHub today isn't GitHub from the early-mid 2010's. Today it is a Microsoft side-gig, something they bought simply because nobody wanted theirs. But, GitHub makes good money, and turns out they're a great source of training material. They're just limping along. In reality, I think Microsoft wants to kill the GitHub brand, they're just doing it slowly, feeding poison.

> Today it is a Microsoft side-gig, something they bought simply because nobody wanted theirs. Theirs? Perforce, TeamServer aren't really competing with GitHub.

I think GP was implying Azure DevOps.

Re: What does GitHub's security team even do?

#35

Earlier quoted context omitted.

> Today it is a Microsoft side-gig, something they bought simply because nobody wanted theirs. Theirs? Perforce, TeamServer aren't really competing with GitHub.

I think GP was implying Azure DevOps.

Thanks, wow, not sure how that slipped by me.
Post reply on HN