Github uses ruby on rails, which is a pretty mature framework, perhaps covering most of the common security pitfalls. Additionally, I assume github has excellent programmers because of the nature of their job. Could someone explain in simple english, how did they overlook known & well documented bugs that got them hacked (e.g. Bug 3 about cross domain injection). I'm wondering if someone of Github's caliber can be ha…
I'm wondering if someone of Github's caliber can be hacked so easily, what about the rest of the masses developing web apps.
What do you think makes Github that much better than all the rest?
Not everyone's time is equal. If you're finding security holes like Egor then an hour of your time is absolutely worth $400/hr.
I totally believe that he's worth that amount of money. I'm sorry if you thought I was questioning that. I'm questioning the juxtaposition of his hourly rate with a request for donations.
Understood. But I imagine that his work isn't quite as "steady" as one might expect. He invests time by trying to find security exploits in hopes that the affected company compensates him. He doesn't set his price or even determine if he gets paid for his time.
I think that might be the rationale...or it might just be that he's found himself in a position where he can collect bounties AND donations :).
Github uses ruby on rails, which is a pretty mature framework, perhaps covering most of the common security pitfalls. Additionally, I assume github has excellent programmers because of the nature of their job. Could someone explain in simple english, how did they overlook known & well documented bugs that got them hacked (e.g. Bug 3 about cross domain injection). I'm wondering if someone of Github's caliber can be ha…
I'm wondering if someone of Github's caliber can be hacked so easily, what about the rest of the masses developing web apps. What do you think makes Github that much better than all the rest?
It's a dream job for developers, in some ways a lot more so than the big boys like Google and Facebook. They have a hiring pipeline any tech company would kill for. They probably don't have the deep security talent that say Google or Microsoft have, but they should have enough.
People shouldn't trust the cloud for important source storage. Always self-host anything you want to keep private.
I'm pretty sure many more codebases have been lost through failures to secure internal networks by corporate IT departments than through vulnerabilities in cloud hosting providers.
If you're talking about for company projects, the enterprise version of Github is self-hosted (e.g. on a VPN): https://enterprise.github.com/
People shouldn't trust the cloud for important source storage. Always self-host anything you want to keep private.
'People' shouldn't 'trust' anything.
Verify.
Important storage can be done 'in the cloud', but you need to audit and verify the cloud vendor is providing the proper controls. Just like you need to do 'privately'.
@homakov finds 5 different bugs with github and manages to align them so that a bigger vulnerability is exposed in under 5 hours ? That's amazing! I used to think I'm a fast delivery-focused developer but I'm probably just a fraction of how fast some people are.
He's not counting all the time he's spent carefully reading the oauth spec and playing with different options ;).
Is there a way to guarantee you will spend donations on alcohol and not waste them on things like rent or food?
yes. donate to someone who makes $400/hour.
Charging $400/hour does not mean he does not need extra money. His nature of business is a short term projects, it's not like a regular web developer who has to work 40 hours a week for many month to finish a project, he only does audits which don't last long because of that you see this "high" (I personally don't think it's high) hourly rate.
Why is GitHub so hostile to this kid, just give him a job already! He obviously has deep understanding of how things work. I would feel better knowing he work for them.