Live data from Hacker News

Home Depot GitHub token exposed for a year, granted access to internal systems

techcrunch.com

141–150 of 169 posts

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#141

Earlier quoted context omitted.

> With a lot of vibe coding happening I shudder to think of the implications. Consider all the security disasters we already get from brogramming, and multiply that, times 100.

Security simply doesn’t seem like it matters much based on the mild consequences.

Try working at a company of any remote public significance and see if your view changes.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#142
post #137
post #132

Earlier quoted context omitted.

How did they get leak them? Just someone getting into your personal Claude Code logs? I'm surprised that if it was just that Google would even be aware they're leaked.

Claude was looking up env-vars during the coding session which ended up in ~/.claude/projects/ log. I wanted to make the [construction] logs public with the code. Didn't think that was a leak vector.

[dead]

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#143

Earlier quoted context omitted.

Security simply doesn’t seem like it matters much based on the mild consequences.

Try working at a company of any remote public significance and see if your view changes.

Equifax? Capital One? 23andMe? My basis for this is that you can leak everyone’s bank data and barely have it show up in your stock price chart, especially long term.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#144
post #133

Earlier quoted context omitted.

Presumably you'd want human habitable atmosphere on the inside of the sphere, which would radically change the equation against the use of wood unfortunately.

I disagree. Traditional underwater human habitats are overengineered and expensive. By using plywood in conjunction with other off-the-shelf parts and materials, we can change this equation to deliver more value while dramatically reducing costs. If, due to unforeseen circumstances the habitat occupant can no longer sustain life, they're automatically entombed inside a makeshift plywood coffin—no costly recovery oper…

Could we involve robotics, LLMs and maybe some camera based vision models to this process? Surely with AI we could make building those very fast. Especially with humanoid robots...

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#145
post #73

Earlier quoted context omitted.

I'll bet money any new React/K8s/${WEBSCALE} stuff they're building is still just a wrapper over the same old inventory management they've been using for years...probably something like JDEdwards on AS/400.

You would lose that bet. Walmart has invested a LOT in modernizing stuff over the last 10 years. You cannot deliver groceries in less than an hour using the old inventory. It's not perfect, but what it's been done given the scale , it's nothing short of a miracle. Source: I have been working there for 10 years.

surely gp was referring to HD ;)

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#146

Earlier quoted context omitted.

Try working at a company of any remote public significance and see if your view changes.

Equifax? Capital One? 23andMe? My basis for this is that you can leak everyone’s bank data and barely have it show up in your stock price chart, especially long term.

I don't know if 23andMe has done so well, but many of their problems stem from a bad business model, as opposed to that awful breach.

I agree that we need to have "toothier" breach consequences.

The problem is that there's so much money sloshing around, that we have regulatory capture.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#147

Earlier quoted context omitted.

Try working at a company of any remote public significance and see if your view changes.

Equifax? Capital One? 23andMe? My basis for this is that you can leak everyone’s bank data and barely have it show up in your stock price chart, especially long term.

Stock price is an extremely narrow view of the total consequences of lax cybersecurity but that aside, the notion that security doesn’t matter because those companies got hacked is ridiculous. The reason there isn’t an Equifax every minute is because an enormous amount of effort and talent goes into ensuring that’s the case. If your attitude is we should vibe code our way past the need for security, you aren’t responsible enough to hold a single user’s data.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#148

Earlier quoted context omitted.

Equifax? Capital One? 23andMe? My basis for this is that you can leak everyone’s bank data and barely have it show up in your stock price chart, especially long term.

Stock price is an extremely narrow view of the total consequences of lax cybersecurity but that aside, the notion that security doesn’t matter because those companies got hacked is ridiculous. The reason there isn’t an Equifax every minute is because an enormous amount of effort and talent goes into ensuring that’s the case. If your attitude is we should vibe code our way past the need for security, you aren’t respon…

I feel as if security is a much bigger concern than it ever was.

The main issue seems to be, that our artifacts are now so insanely complex, that there’s too many holes, and modern hackers are quite different from the old skiddies.

In some ways, it’s possible that AI could be a huge boon for security, but I’m worried, because its training data is brogrammer crap.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#149

Earlier quoted context omitted.

I had to check what the gold standard McMaster-Carr does: their torque wrench drive size widget is sorted 1/4", 3/8", 1/2", 3/4", 1", 1 1/2". Glorious. https://www.mcmaster.com/products/torque-wrenches/

McMaster-Carr's website is actually pretty impressive given how unassuming it is. It does a ton of pre-loading on hover and caching to make it feel like you're just navigating a static site. I didn't even realize that the page had a loading state until I enabled throttling from my network tab and immediately clicked on a link as soon as I hovered over it.

See https://news.ycombinator.com/item?id=32976978

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#150
post #90

Earlier quoted context omitted.

It varies a lot by store. I’ve been to HDs where they’re all useless, and others where there’s a good number of knowledgeable DIYers working there. I think a lot of people just expect too much from a big box store employee making $17/hr… You go to HD because you have an easy job and you’re as cheap as their MBAs. If you need help, go to a supply house or an Ace Hardware or something.

Fully this. Every Ace or Do It Best I've been to in Washington has had at least one Rugged Grandpa ™ on staff who could have given me a PhD-level essay on whatever I asked them about; at Home Depot I'm lucky if the folks there have any idea what an impact-rated bit is or why I specifically need one and NO please stop trying to sell me this other crap if you're sold out of the impact bits, they are NOT the same! (It g…

I am buying an impact driver for someone for christmas. Any recommendations on a fastner/drill bit set?
Post reply on HN