Live data from Hacker News

How I hacked Github again

homakov.blogspot.com

191–200 of 202 posts

Re: How I hacked Github again

#191
post #162
post #85

Earlier quoted context omitted.

> Infosec is hard. In computer security, you have to get it right every single time. The bad guys only need to get it right once.

This is a little myopic but understandable in the context of a discussion on HN. Infosec is hard, but it is just one example of a bigger truth: Defense is hard. This comes up time and time again in any defensive discipline: Over two decades the CIA had learned again and again that it could not hope to defend against terrorists by relying solely on its ability to detect specific attacks in advance. No matter how many…

This is why I think some more work into client (or active) honeypots may be beneficial. If we can get an easy to install, auto updating honeypot that fights back, we may have a better offensive capability.

This may just end, like nuclear warfare, in MAD... But it would be great fun to watch!

http://en.wikipedia.org/wiki/Client_honeypot

http://books.google.com.au/books?id=YQmWtsqlvfMC&dq=active+h...

http://en.wikipedia.org/wiki/Mutual_assured_destruction

Re: How I hacked Github again

#193
post #12

Earlier quoted context omitted.

I'm pretty sure Egor's first language isn't English, so OK might mean 'meh it's alright' through to 'hey this is great'. I know a few non-native speakers who do similar things.

OK means it's OK but could be better :P

I agree... How much could you have sold that exploit for on the black market?

http://krebsonsecurity.com/tag/0day/

Re: How I hacked Github again

#194
post #96
post #82

Earlier quoted context omitted.

Start-up idea: let Hacker News users pay to berate you for x minutes. There's a clearly huge market.

plus.inyourfacetwit.com, where you have 140 chars to berate anyone, and a whaling-wall for when you really need to get it off your chest. Ad supported. Abusive ads berating potential users are encouraged.

20 hours later, domain still not registered...

Get on that before someone filches it!

Re: How I hacked Github again

#195
Thanks for continuing to make Github safer for all, @homakov. Someday I might even host a private repo there again, but I haven't done that since your first mass assignment exploit. You continue to prove that my decision was a good one.

Re: How I hacked Github again

#196

Earlier quoted context omitted.

I'm wondering if someone of Github's caliber can be hacked so easily, what about the rest of the masses developing web apps. What do you think makes Github that much better than all the rest?

It's a dream job for developers, in some ways a lot more so than the big boys like Google and Facebook. They have a hiring pipeline any tech company would kill for. They probably don't have the deep security talent that say Google or Microsoft have, but they should have enough.

Working in ruby using git? Sounds horrible to me :)

Re: How I hacked Github again

#197
post #106
post #101

Earlier quoted context omitted.

I don't get why Github just hasn't hired the guy already.

In his earlier work at least, he's seemed like a loose cannon.

I think his behaviour was commendable - he tried many many times to warn, going to multiple people and projects, but they all ignored him - they were too busy being Gem installing Ruby hipster Brogrammers to consider security, and it bit them hard in the backside.

Re: How I hacked Github again

#198

Earlier quoted context omitted.

What opinions does infosec in general have of correctness? What about languages like Haskell which focus on separating IO and pure functions?

well it gives the advantage that (used to?) keep desktop-Linux clear of most viruses: it's too little a fish for blackhats to go after. until that's different it's harder to answer your actual question. my guess, it'll be better but inevitably still have some holes.

I specifically what infosec (or anyone involved in the industry) thought of separating pure and impure functions which affect the outside world.

It seems to me that it would drastically reduce the surface areas of attack.

Re: How I hacked Github again

#199
post #189
post #178

Earlier quoted context omitted.

$400/hr is meaningless if comes from an one-off gig.

That's about $13000 THB / hour. Considering that it isn't uncommon for junior programmers in Bangkok to make (and live on) 20-30K / MONTH....

400 USD/hour is a great rate anywhere in the world, even the most expensive cities.

But abcd_f's comment is right about one-off 4-hour projects vs. long-term contracting. Non-billable time overhead spent on finding clients, negotiating contracts, mentally switching projects, or just sitting idle can negate the benefits of a high hourly rate.

Post reply on HN