Earlier quoted context omitted.
It's normal that a dev has *access* to all the code. But did he clone all the repos into his machine? I doubt it. So, the hacker extracted all the 3800 repos using the employee's machine as a gateway? I doubt it as well, I'm sure they would have detected this huge amount of data much earlier than transferring all of it? > The real question is why github has 3800 internal repos. I guess they mean customer's private re…
All the attackers need to do is steal an SSH key and they'd be able to clone everything, no?
So you'd need to authenticate for the VPN, which often has 2nd factor.
But I have no idea of how they are set up.