GitHub and Rails: You have let us all down.
171–180 of 205 posts
Re: GitHub and Rails: You have let us all down.
#172Jesus, HN goes from zero to lynch mob faster than reddit these days. Guy drops a zero day on a major service provider, guy gets his account suspended (temporarily, it turns out). In what possible world is disabling an account that has recently exploited your live product in a very visible way not ok? Remember, you don't have a chance to call a meeting with the C level guys and your community manager - you're one or t…
Correct me if I'm wrong but this wasn't a "zero day". This issue was brought up four days ago https://github.com/rails/rails/issues/5228
"Weapons of Mass Assignment" by Patrick McKenzie, ACM Queue, March 2011
http://queue.acm.org/detail.cfm?id=1964843
Worse, ten years ago PHP changed the default behavior after suffering from very similar problem:
http://www.sitepoint.com/write-secure-scripts-php-4-2/
Rails actually needed Egor to initiate change. At first they ignored him:
https://github.com/rails/rails/issues/5228
Now the change can be seen:
Re: GitHub and Rails: You have let us all down.
#173Earlier quoted context omitted.
Coincidentally, the incident with Zed was also fueled by the ruby guys being dicks. He just happens to be a higher-profile personality.
It is rails guys, not ruby guys. I am still wondering why people can't distinguish two different communities. You don't mistake python and django or php and kohana or java and strut, right?
Re: GitHub and Rails: You have let us all down.
#174The response to this makes me feel that HackerNews is now populated by a bunch of pretenders. This "bug" has been in Rails since Day 1, and any remotely experienced Rails developer is aware of this functionality. You can argue for a different default, but it's not a bug. Github did have a bug and noone knowledgeable about Rails appears to have made even a cursory inspection of the security of their controllers - whic…
Re: GitHub and Rails: You have let us all down.
#175Jesus, HN goes from zero to lynch mob faster than reddit these days. Guy drops a zero day on a major service provider, guy gets his account suspended (temporarily, it turns out). In what possible world is disabling an account that has recently exploited your live product in a very visible way not ok? Remember, you don't have a chance to call a meeting with the C level guys and your community manager - you're one or t…
"What I want you to see in that thread I mentioned is the way the core team perceives this. You are not discovering anything unknown, we already know this stuff and we like attr protection to work the way it is."
(https://github.com/rails/rails/issues/5228#issuecomment-4292...)
After reading for how long he tried to bring attention to this and only got a top guy to say that kind of stuff. The guy who hacked is not right in any way but I don't even have words to describe the person who wrote the above line.
Re: GitHub and Rails: You have let us all down.
#176"If you are one of those strange coders that don't use GitHub". Never used and never will. What's strange with that?
"If you are one of those strange coders that don't use GitHub and think you are in the clear because you use SVN/Mercurial" I can't believe he actually put SVN and Mercurial on the same side, or that he implies that not using GitHub must mean that you don't use Git at all. This sentence is wrong on so many levels. Sigh.. I'm strange , for my actual work I use Mercurial hosted on BitBucket.
Re: GitHub and Rails: You have let us all down.
#177Earlier quoted context omitted.
Clearly the only secure and rational solution for all of us is to print out our source code every hour and store it in a shoebox under our beds.
Try to be serious. What are you gonna do, type your source back in by hand? Punch cards, paper tape, cassette recorder, pick one.
Nowadays you can hand a CD, plus a printed manual. Printing the code is now optional. But you still have to register every version :)
Re: GitHub and Rails: You have let us all down.
#178Earlier quoted context omitted.
Reporting security flaws is fine. Doing it by demonstration on a live product without asking first is not as fine.
"Houses aren't very secure, here's a video of me picking the lock on my own front door." "I demonstrated how insecure your house is by picking the front door lock and leaving a note on your bed." Sometimes it can be difficult to have the empathy and perspective to see how frightening and unconscionable the 2nd action can be, but it very much is.
Empathy was casusing me pain everytime I saw you 'lock' your door with that elastic band. Attention seeking or malicious behaviour would have been to break into all the insecure doors on the street.
I broke into yours, so you would take security seriously, because I care about you and your wellbeing."
Re: GitHub and Rails: You have let us all down.
#179Earlier quoted context omitted.
In what way do they have to prevent him from ever accessing the site from any account ever again? Who said they did? The best they can do is suspend his account per policy while they are investigating. Why? What's the point of suspending his account?
Why? What's the point of suspending his account? There are two issues with any exploit: (1) prevent future exploits and (2) making sure that whoever discovered the exploit hasn't retained any unauthorized access. Fixing the bug addresses (1) and suspending his account gives them time to address (2).
Suspending his account wouldn't have affected him if he was being black hat about this. A suspension in this case serves pretty much no purpose other than to make Github feel better about themselves.
Re: GitHub and Rails: You have let us all down.
#180Earlier quoted context omitted.
Yeah, I think we'll migrate all our private stuff to http://gitlabhq.com/ The way GitHub reacted (blocking @homakov) is just wrong and destroyed all my confidence in them. Even more so when it was pointed out that @zedshaw crashed GitHub and didn't get blocked. http://sheddingbikes.com/posts/1306816425.html Edit: Given that they have now stated that suspending @homakov was only temporary I no longer bear any ill will…
I actually wanted them to ban me for that, because then they'd have even more to explain about them allowing rape/abuse comics about me on their site: https://github.com/nickmartini/dongml Which has: https://a248.e.akamai.net/assets.github.com/img/b0de87a4cf0c... If I was a woman there'd be an international shit storm over that image, but I'm a dude, and one that TPW hates, so of course they won't do shit. Then again…
And github forgetting the block user functionality makes me think they don't want to listen to user needs. Sure, it may not be a very popular request, but I bet for a minority it's the most important.