Live data from Hacker News

How I hacked Github again

homakov.blogspot.com

21–30 of 202 posts

Re: How I hacked Github again

#21

Shame on github for making these mistakes in the first place, but kudos to them for doing such a great job of engaging the white hats.

If we're shaming any code with security flaws, no one is free of shame. I'm excited by the bounty program, it's a great way to get things like this identified and responsibly disclosed

Re: How I hacked Github again

#22
post #15

Earlier quoted context omitted.

Of course, there's probably also a large chance that he finds nothing in those 8 hours

"nothing" never happened IRL. I either work extra for free trying to find more, and punch myself until I find something.

There are always n+1 bugs. I presume the same could be said for security holes- especially considering they are sometimes the result of bugs.

Re: How I hacked Github again

#24
"P.S.2 Love donating? Help Egor on coinbase or paypal: homakov@gmail.com"

Maybe it's just me, but asking for donations after saying you bill clients at $400/hr seems weird to me. I wish I could bill at that rate.

Re: How I hacked Github again

#25
post #15

Earlier quoted context omitted.

Of course, there's probably also a large chance that he finds nothing in those 8 hours

"nothing" never happened IRL. I either work extra for free trying to find more, and punch myself until I find something.

Really great attitude.

I would make this your tagline in some way -

"I will find vulnerabilities. If I don't, I will become a vulnerability to my own body and attack myself until I do!"

Re: How I hacked Github again

#26
If @homakov is finding security holes without access to Github repositories, imagine what he'd find if you had him code audit for a few days... He's clearly been going about this the proper white-hat way and ensuring holes are patched before open disclosure... what's there to lose?

On the flip side, you could go about doing what you're doing under the presumption nobody is maliciously targeting your user base. In this scenario, it's possible you have a couple bad actors that see a net benefit greater than your bug bounties and are silently stealing and selling supposedly secure code from your users. You could be supporting a hacker black market where they sell and trade codebases to popular online sites. Imagine how easy it would be for them to find vulnerabilities in these sites if given access to the source code.

That, my friends, would be a catastrophe.

Re: How I hacked Github again

#28
post #24

"P.S.2 Love donating? Help Egor on coinbase or paypal: homakov@gmail.com" Maybe it's just me, but asking for donations after saying you bill clients at $400/hr seems weird to me. I wish I could bill at that rate.

Not everyone's time is equal. If you're finding security holes like Egor then an hour of your time is absolutely worth $400/hr.

Re: How I hacked Github again

#29
post #24

"P.S.2 Love donating? Help Egor on coinbase or paypal: homakov@gmail.com" Maybe it's just me, but asking for donations after saying you bill clients at $400/hr seems weird to me. I wish I could bill at that rate.

There's a number of people who would like donate but not interested in consulting..

There were always people complaining "Add a donate address"

Now "why you added a donate address". Oh, Internet.

Re: How I hacked Github again

#30
post #24

"P.S.2 Love donating? Help Egor on coinbase or paypal: homakov@gmail.com" Maybe it's just me, but asking for donations after saying you bill clients at $400/hr seems weird to me. I wish I could bill at that rate.

Sure, I had a similar first reaction, but thought about it. If you have skills but haven't yet developed a deep-enough client base, you're in a quandary. You can't bill for $10/hour, or no one will take you seriously. You need perceived value, so you have to quote some reasonably high rate, even if you case-by-case discount it or work gratis.

(At least that's how I imagine it must work. I've never consulted.)

Post reply on HN