Live data from Hacker News

GitHub is investigating unauthorized access to their internal repositories

twitter.com

141–150 of 359 posts

Re: GitHub is investigating unauthorized access to their internal repositories

#141

Most large companies won’t allow direct access to Docker hub or PyPI, and now they’ll have to restrict access to VSCode extensions. How did the extension get poisoned?

We run an explicit whitelist, enforced through Microsoft Entra (or was it Intune).

Re: GitHub is investigating unauthorized access to their internal repositories

#142
post #95

Earlier quoted context omitted.

> I guess they mean customer's private repos? I don't think so. It is even worse if a random developer has access to customers' private repos.

Good point. Then why in the world would a company have 3,500 repos? Do they create a repo for each employee?

I am sure many of their employees create repos. Is that strange?

It doesn’t mean they are all masterpieces of elaborate production code.

Re: GitHub is investigating unauthorized access to their internal repositories

#143
post #90

Earlier quoted context omitted.

I prefer Forgejo, which is a Gitea fork. Forgejo is what runs Codeberg if I understand correctly.

I currently use Gitea. I am interested in your opinion on why you prefer Forgejo to Gitea

I'm not OP but probably the licensing drama. Gitea is now open core if I remember correctly. Some details are available here[1]. I also used to run Gitea, but I don't any more. The open-source churn is getting tedious and difficult to keep up with.

[1]: https://blog.codeberg.org/codeberg-launches-forgejo.html

Re: GitHub is investigating unauthorized access to their internal repositories

#144

Why did one developer have access, even if read-only, to more than 3,800 internal repos?

Devs not having read access to all code seems like a massive org smell. What’s worse, in many cases not having access doesn’t just prevent you from seeing it it also prevents you from knowing it exists. Now you don’t know what to ask for, who to ask, or what to not implement again. There is no security risk that you could use to convince me that ”devs should only have access to code they need to modify”.

in my org, devs don’t have access to customer data directly, and sysadmins don’t have access to modify code.

It’s a simple rule from a simpler time, to limit the risk of total compromise.

Re: GitHub is investigating unauthorized access to their internal repositories

#146

Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/

watch it turn out to be that their twitter account is what was hacked, and github.com is actually fine

Yes, and github having zero-nines reliability record is because of a hacked twitter account too! (sigh...)

Re: GitHub is investigating unauthorized access to their internal repositories

#147
I'm not sure if this is related or not. But a few days ago, I saw commits from the "future tense" in some repositories. When you read "committed tomorrow" after a commit, it's not funny at all. I posted a screenshot in the announcement on GitHub.

Re: GitHub is investigating unauthorized access to their internal repositories

#148

Are they required to announce that they're being hacked in real time?

Microsoft owned so many a CYA to explain why the liability insurance goes up to investors?

Ah, this makes most sense to me, the details of the compromise must have already been published,

"The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far."

https://xcancel.com/i/status/2056949168208552080

Re: GitHub is investigating unauthorized access to their internal repositories

#149

I'm not sure if this is related or not. But a few days ago, I saw commits from the "future tense" in some repositories. When you read "committed tomorrow" after a commit, it's not funny at all. I posted a screenshot in the announcement on GitHub.

But you can change the commit date from cli when committing? Github just shows the commit metadata, right?

Re: GitHub is investigating unauthorized access to their internal repositories

#150
post #130
post #18

The security issue aside, seeing more companies push announcements like these on X as the only official source is a trend I'm not sure I like. I can understand the rationale, this feels lighter and not something that belongs on status.github.com or the blog. Maybe what's actually missing is an official channel for ephemeral stuff on a domain they own, somewhere between a status page and a tweet? Just sharing an obser…

Are you from 2015? Companies have been announcing stuff on Twitter for a decade, and the rest of social media has been regurgitating Twitter posts for almost as long. Newspapers routinely quote Twitter. All that happened before they even renamed it to X. I’m not saying it’s a good idea. I am saying it somehow became the single source of truth for the Internet with all that entails.

You are kind of saying it's a good idea or at least a totally acceptable one.

You're saying Twitter is famous for being famous, and looking down at someone who expresses dismay at this for being behind the times.

Post reply on HN