Most large companies won’t allow direct access to Docker hub or PyPI, and now they’ll have to restrict access to VSCode extensions. How did the extension get poisoned?
GitHub is investigating unauthorized access to their internal repositories
141–150 of 359 posts
Re: GitHub is investigating unauthorized access to their internal repositories
#142Earlier quoted context omitted.
> I guess they mean customer's private repos? I don't think so. It is even worse if a random developer has access to customers' private repos.
Good point. Then why in the world would a company have 3,500 repos? Do they create a repo for each employee?
It doesn’t mean they are all masterpieces of elaborate production code.
Re: GitHub is investigating unauthorized access to their internal repositories
#143Earlier quoted context omitted.
I prefer Forgejo, which is a Gitea fork. Forgejo is what runs Codeberg if I understand correctly.
I currently use Gitea. I am interested in your opinion on why you prefer Forgejo to Gitea
[1]: https://blog.codeberg.org/codeberg-launches-forgejo.html
Re: GitHub is investigating unauthorized access to their internal repositories
#144Why did one developer have access, even if read-only, to more than 3,800 internal repos?
Devs not having read access to all code seems like a massive org smell. What’s worse, in many cases not having access doesn’t just prevent you from seeing it it also prevents you from knowing it exists. Now you don’t know what to ask for, who to ask, or what to not implement again. There is no security risk that you could use to convince me that ”devs should only have access to code they need to modify”.
It’s a simple rule from a simpler time, to limit the risk of total compromise.
Re: GitHub is investigating unauthorized access to their internal repositories
#145Which extension was it?
Re: GitHub is investigating unauthorized access to their internal repositories
#146Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/
watch it turn out to be that their twitter account is what was hacked, and github.com is actually fine
Re: GitHub is investigating unauthorized access to their internal repositories
#147Re: GitHub is investigating unauthorized access to their internal repositories
#148Are they required to announce that they're being hacked in real time?
Microsoft owned so many a CYA to explain why the liability insurance goes up to investors?
"The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far."
Re: GitHub is investigating unauthorized access to their internal repositories
#149I'm not sure if this is related or not. But a few days ago, I saw commits from the "future tense" in some repositories. When you read "committed tomorrow" after a commit, it's not funny at all. I posted a screenshot in the announcement on GitHub.
Re: GitHub is investigating unauthorized access to their internal repositories
#150The security issue aside, seeing more companies push announcements like these on X as the only official source is a trend I'm not sure I like. I can understand the rationale, this feels lighter and not something that belongs on status.github.com or the blog. Maybe what's actually missing is an official channel for ephemeral stuff on a domain they own, somewhere between a status page and a tweet? Just sharing an obser…
Are you from 2015? Companies have been announcing stuff on Twitter for a decade, and the rest of social media has been regurgitating Twitter posts for almost as long. Newspapers routinely quote Twitter. All that happened before they even renamed it to X. I’m not saying it’s a good idea. I am saying it somehow became the single source of truth for the Internet with all that entails.
You're saying Twitter is famous for being famous, and looking down at someone who expresses dismay at this for being behind the times.