Live data from Hacker News

GitHub and Rails: You have let us all down.

chrisacky.posterous.com

171–180 of 205 posts

Re: GitHub and Rails: You have let us all down.

#172

Jesus, HN goes from zero to lynch mob faster than reddit these days. Guy drops a zero day on a major service provider, guy gets his account suspended (temporarily, it turns out). In what possible world is disabling an account that has recently exploited your live product in a very visible way not ok? Remember, you don't have a chance to call a meeting with the C level guys and your community manager - you're one or t…

Correct me if I'm wrong but this wasn't a "zero day". This issue was brought up four days ago https://github.com/rails/rails/issues/5228

Yes, it's the very known issue made public long ago on a lot of serious places, for example:

"Weapons of Mass Assignment" by Patrick McKenzie, ACM Queue, March 2011

http://queue.acm.org/detail.cfm?id=1964843

Worse, ten years ago PHP changed the default behavior after suffering from very similar problem:

http://www.sitepoint.com/write-secure-scripts-php-4-2/

Rails actually needed Egor to initiate change. At first they ignored him:

https://github.com/rails/rails/issues/5228

Now the change can be seen:

http://news.ycombinator.com/item?id=3664459

Re: GitHub and Rails: You have let us all down.

#173

Earlier quoted context omitted.

Coincidentally, the incident with Zed was also fueled by the ruby guys being dicks. He just happens to be a higher-profile personality.

It is rails guys, not ruby guys. I am still wondering why people can't distinguish two different communities. You don't mistake python and django or php and kohana or java and strut, right?

I think this Depends on the country or language somewhat too - many ruby guys in Japan are another breed entirely (using it as a playground for esoteric languages, quines..)

Re: GitHub and Rails: You have let us all down.

#174
post #164

The response to this makes me feel that HackerNews is now populated by a bunch of pretenders. This "bug" has been in Rails since Day 1, and any remotely experienced Rails developer is aware of this functionality. You can argue for a different default, but it's not a bug. Github did have a bug and noone knowledgeable about Rails appears to have made even a cursory inspection of the security of their controllers - whic…

Normally I respond negatively to this type of post, but you've captured my feelings perfectly. The facts here are nothing that should be blown so far out of proportion. I can't help but detect a hint of schadenfreude at the idea that Rails core or Github are not infallible.

Re: GitHub and Rails: You have let us all down.

#175

Jesus, HN goes from zero to lynch mob faster than reddit these days. Guy drops a zero day on a major service provider, guy gets his account suspended (temporarily, it turns out). In what possible world is disabling an account that has recently exploited your live product in a very visible way not ok? Remember, you don't have a chance to call a meeting with the C level guys and your community manager - you're one or t…

From 3 days ago:

"What I want you to see in that thread I mentioned is the way the core team perceives this. You are not discovering anything unknown, we already know this stuff and we like attr protection to work the way it is."

(https://github.com/rails/rails/issues/5228#issuecomment-4292...)

After reading for how long he tried to bring attention to this and only got a top guy to say that kind of stuff. The guy who hacked is not right in any way but I don't even have words to describe the person who wrote the above line.

Re: GitHub and Rails: You have let us all down.

#176
post #46
post #25

"If you are one of those strange coders that don't use GitHub". Never used and never will. What's strange with that?

"If you are one of those strange coders that don't use GitHub and think you are in the clear because you use SVN/Mercurial" I can't believe he actually put SVN and Mercurial on the same side, or that he implies that not using GitHub must mean that you don't use Git at all. This sentence is wrong on so many levels. Sigh.. I'm strange , for my actual work I use Mercurial hosted on BitBucket.

I stopped reading when I saw that the author can't distinguish GitHub and Git usage…

Re: GitHub and Rails: You have let us all down.

#177

Earlier quoted context omitted.

Clearly the only secure and rational solution for all of us is to print out our source code every hour and store it in a shoebox under our beds.

Try to be serious. What are you gonna do, type your source back in by hand? Punch cards, paper tape, cassette recorder, pick one.

You're snarky, but that's exactly the way we used to protect source code intellectual property here in Uruguay until recently.

Nowadays you can hand a CD, plus a printed manual. Printing the code is now optional. But you still have to register every version :)

http://www.cuti.org.uy/registro-de-software.html

Re: GitHub and Rails: You have let us all down.

#178

Earlier quoted context omitted.

Reporting security flaws is fine. Doing it by demonstration on a live product without asking first is not as fine.

"Houses aren't very secure, here's a video of me picking the lock on my own front door." "I demonstrated how insecure your house is by picking the front door lock and leaving a note on your bed." Sometimes it can be difficult to have the empathy and perspective to see how frightening and unconscionable the 2nd action can be, but it very much is.

"But thats exactly why I left you that note. Because it frightens me just how insecure your house is. I care about you and don't want to see you hurt. I did it as a last resort, I tried to inform you but you clearly didn't take me seriously.

Empathy was casusing me pain everytime I saw you 'lock' your door with that elastic band. Attention seeking or malicious behaviour would have been to break into all the insecure doors on the street.

I broke into yours, so you would take security seriously, because I care about you and your wellbeing."

Re: GitHub and Rails: You have let us all down.

#179

Earlier quoted context omitted.

In what way do they have to prevent him from ever accessing the site from any account ever again? Who said they did? The best they can do is suspend his account per policy while they are investigating. Why? What's the point of suspending his account?

Why? What's the point of suspending his account? There are two issues with any exploit: (1) prevent future exploits and (2) making sure that whoever discovered the exploit hasn't retained any unauthorized access. Fixing the bug addresses (1) and suspending his account gives them time to address (2).

But the thing here is that if he genuinely wanted to retain unauthorized access, he had at the very least several days to create a ton of alternative accounts to make use of this exploit with.

Suspending his account wouldn't have affected him if he was being black hat about this. A suspension in this case serves pretty much no purpose other than to make Github feel better about themselves.

Re: GitHub and Rails: You have let us all down.

#180

Earlier quoted context omitted.

Yeah, I think we'll migrate all our private stuff to http://gitlabhq.com/ The way GitHub reacted (blocking @homakov) is just wrong and destroyed all my confidence in them. Even more so when it was pointed out that @zedshaw crashed GitHub and didn't get blocked. http://sheddingbikes.com/posts/1306816425.html Edit: Given that they have now stated that suspending @homakov was only temporary I no longer bear any ill will…

I actually wanted them to ban me for that, because then they'd have even more to explain about them allowing rape/abuse comics about me on their site: https://github.com/nickmartini/dongml Which has: https://a248.e.akamai.net/assets.github.com/img/b0de87a4cf0c... If I was a woman there'd be an international shit storm over that image, but I'm a dude, and one that TPW hates, so of course they won't do shit. Then again…

Oh wow, that nickmartini story is really something. Trolling through github ? Just sad.

And github forgetting the block user functionality makes me think they don't want to listen to user needs. Sure, it may not be a very popular request, but I bet for a minority it's the most important.

Post reply on HN