Earlier quoted context omitted.
> and how they should never have had such a vulnerable bug in the first place is even worse. Bugs happen. Even stupid oh-my-god-i-can't-believe-i-did-that bugs happen. And they happen to the best of us. However , when someone reports a vulnerability about my code to me or I discover a problem myself, the very first thing I do is break out the grep. I grep the shit out of my code. Because I am a human being. I am a cr…
"The guy reported the issue on Friday, they fixed that specific instance of the issue ... and it remained a problem in other places." If I have correctly understood the issue, Igor at first informed Rails, and this was the right thing to do. He was ignored by Rails and then he wanted to proof his view point by applying it to GitHub. How could GitHub inform other places? By contacting Rails, but they already downplaye…
GitHub and Rails: You have let us all down.
191–200 of 205 posts
Re: GitHub and Rails: You have let us all down.
#192Earlier quoted context omitted.
> If we have to worry about each of these on our pwn, what's the point? You should always have to worry about these things, regardless of who's hosting things. It just so happens that Github, to date, has been checking the boxes in these areas and has established a reputation for doing so. But, if GitHub losing your repo/having it trashed beyond repair will kill your project (or severely hamper it), the cost of setti…
That's not how git works. I have the entire repo locally. If I didn't, I wouldn't be able to commit anything. So if Github goes poof, I'd be pissed, but I wouldn't lose a single line of code. I would obviously lose things like issues/wiki. Actually, it would be pretty cool if Github turned issues/wiki into some sort of git repo of markdown files and allow me to pull them and commit to them. Something for them to thin…
Re: GitHub and Rails: You have let us all down.
#193Give me an F'in break. I understand security is not something to take lightly, but no system is infallible. There was an oversight, plain and simple. It is debatable whether the Github/Rails Core Team was too lax, but I for one am tired of hearing developers whine and make a witch trial out of groups of developers that have moved the development community forward several huge steps just to make themselves sound smart…
"we already know this stuff and we like attr protection to work the way it is." https://github.com/rails/rails/issues/5228#issuecomment-4292...
Re: GitHub and Rails: You have let us all down.
#194Earlier quoted context omitted.
"But thats exactly why I left you that note. Because it frightens me just how insecure your house is. I care about you and don't want to see you hurt. I did it as a last resort, I tried to inform you but you clearly didn't take me seriously. Empathy was casusing me pain everytime I saw you 'lock' your door with that elastic band. Attention seeking or malicious behaviour would have been to break into all the insecure…
How is that so very different from, say, kidnapping someone's children and holding them hostage until they fix whatever you want fixed? The problem here is that when you violate someone's trust you change the landscape. People get scared, they question your motives, they go into a fight or flight response. Yes, this sometimes results in the problem being fixed faster because they are very much more motivated now, but…
Re: GitHub and Rails: You have let us all down.
#195Earlier quoted context omitted.
From 3 days ago: "What I want you to see in that thread I mentioned is the way the core team perceives this. You are not discovering anything unknown, we already know this stuff and we like attr protection to work the way it is." ( https://github.com/rails/rails/issues/5228#issuecomment-4292... ) After reading for how long he tried to bring attention to this and only got a top guy to say that kind of stuff. The guy w…
This, to me, is the craziest part. I'm not condemning anyone, but it seems that when someone points out that your framework ships Insecure By Default code with absolutely no warning in the generated code, you'd take that seriously. Instead, the thread is full of "We've discussed this before, we like it the way it is" and "Rails is not responsible here."
I am not a rails developer, but I am pretty sure this would have woken up a lot of people for a lot of similar issues, there will be a mad flurry of devs rechecking a whole bunch of code. Had he reported this disacreetly what are the chances of this much publicity have been generated?!?
Re: GitHub and Rails: You have let us all down.
#196Earlier quoted context omitted.
They should have burned the midnight oil and made sure the same problem wasn't prevalent in other parts of the code. I understand that's the feeling here, but it's unrealistic. I've reported dozens of bugs to shops that ranged in size from 1 to borg. You simply never see a whole set of bugs fixed and pushed live over a weekend. Not even close. Exactly what company have you seen set this standard for professional? The…
I agree to a point. However, if such a problem was reported to LedgerSMB here is how we handle it: 1) Scope out the problem. What's affected? Are other related open source projects affected? How bad is it? This itself can take a bit of time. We do not rush this because we don't want a full disclosure when it happens to bring other problems into the fore. 2) Within a few days we let the reporter know what we have foun…
I definitely wanted to do a more careful audit and investigation, but my hands were tied.
Re: GitHub and Rails: You have let us all down.
#197Earlier quoted context omitted.
"But thats exactly why I left you that note. Because it frightens me just how insecure your house is. I care about you and don't want to see you hurt. I did it as a last resort, I tried to inform you but you clearly didn't take me seriously. Empathy was casusing me pain everytime I saw you 'lock' your door with that elastic band. Attention seeking or malicious behaviour would have been to break into all the insecure…
This isn't breaking into someone's house and leaving a note. This is breaking into a huge commercial factory with thousands of clients, where you could cause colossal damage, and only leaving a note.
Exactly, you and every other hacker with out there. At least you had the good conscience to leave a note.
Re: GitHub and Rails: You have let us all down.
#198I have lost all trust in GitHub, and not because of the vulnerability, but because of their response. With their suspension of hamakov's account and deceptive blog post about the extent of the hole, GitHub has guaranteed that they won't be the first to know about the next vulnerability (and there's always another). I've downgraded my paid account to a free account, and won't keep any non-public data on GitHub in the…
We suspended it after fixing the bug to make sure he didn't retain access to something he shouldn't. We rarely do this, but he wasn't upfront with everything he was doing on the site like people that disclose vulnerabilities responsibly.
EDIT: On second thoughts, I think I am being overly critical on all parties. Instead, I think I hands up "we messed up, but we are learning" approach would be better, and we see how both sides act if/when this happens again, lessons learnt and all that!
Re: GitHub and Rails: You have let us all down.
#199The response to this makes me feel that HackerNews is now populated by a bunch of pretenders. This "bug" has been in Rails since Day 1, and any remotely experienced Rails developer is aware of this functionality. You can argue for a different default, but it's not a bug. Github did have a bug and noone knowledgeable about Rails appears to have made even a cursory inspection of the security of their controllers - whic…
> Github did have a bug and noone knowledgeable about Rails appears to have made even a cursory inspection of the security of their controllers > Github had a pretty terrible bug > but the certainly don't deserve this sort of mon hatred For all the free fun you can have on github, they are in the business of selling private repositories. What could possibly have been worse than someone finding a bunch of bugs in a ma…
For all that GitHub has given to the developer community, an innocent mistake even of this proportion of incompetence is still should not evoke such hatred. And those upset about someone's account being suspended who was actively misusing security holes - well, maybe you should use a provider who looks positively upon reporting security holes by vandalizing customer data. And they suspended his account for only a few hours! Unreasonable? Hate inspiring? Outrageous? I think not.
And by the way, the fact the "issue" of the default had been reported 4 days earlier in a github issue tracker for Rails (which is certainly not followed, let alone on weekends, by github employees) does not in any way impact whether GitHub should have been aware of this vulnerability, and to suggest so is intellectually dishonest.
Re: GitHub and Rails: You have let us all down.
#200Jesus, HN goes from zero to lynch mob faster than reddit these days. Guy drops a zero day on a major service provider, guy gets his account suspended (temporarily, it turns out). In what possible world is disabling an account that has recently exploited your live product in a very visible way not ok? Remember, you don't have a chance to call a meeting with the C level guys and your community manager - you're one or t…
This was anything but a zero-day, and that's the whole reason people are mad. Homakov very clearly made an effort to get this patched before exploiting it before taking action himself. They're not mad that it wasn't fixed immediately on Sunday; they're mad that, on Sunday, there was still a problem in the first place. Big difference.