So let me get this straight - They're publishing a secret key on a Gist, and then getting whiny when it somehow gets leaked. Github very clearly states that "secret" gists are NOT private: https://help.github.com/articles/about-gists/
> getting whiny
Actually, they're subpoenaing. This is necessary to identify who may have accessed it; i don't think this is a suit over the privacy of gists.
Would there be any consequence for Github themselves if they no longer had this data (for example in the hypothetical case that they only store access logs for 30 days)?
At this point the identity of the hacker is irrelevant No. Even if I leave my door unlocked, someone who comes in and steals my stereo should still be punished.
This is different than someone stealing a stereo. This is you tape the security code for your front door onto the door and then your mad at the manufacturer of the door's lock. You want the manufacturer to give any information about the person who broke into your house.
The manufacturer digitally stores the fingerprints of anyone who uses the lock. You want the manufacturer to give you a copy of the fingerprints to help you identify the person who broke into your house.
> ...and then your [sic] mad at the manufacturer of the door's lock.
Would there be any consequence for Github themselves if they no longer had this data (for example in the hypothetical case that they only store access logs for 30 days)?
No. You can't provide what you don't have, and you are not obliged to save more than you are obliged by law. I'm not aware that Github has to save anything in the first place.
So let me get this straight - They're publishing a secret key on a Gist, and then getting whiny when it somehow gets leaked. Github very clearly states that "secret" gists are NOT private: https://help.github.com/articles/about-gists/
So how is the IP address of someone that has viewed or crawled said secret Gist relevant anyways? Someone crawling a website is not probable cause (even if there is a single IP address which can be traced to specific machine, which is highly unlikely).
Secret gists are not published publicly, and thus are not crawled. You would need to have a direct link to the gist to have accessed it. Having the link either means you had access to it as an internal employee, it was shared by an internal employee, or an internal employee's system or email was accessed by someone else.
> In keeping with its image as a gas tank of ethics running on empty (...) This is the best one-sentence summary of Uber I've ever seen.
Peter Sagal on NPR's "Wait Wait...Don't Tell Me!" had a good one liner something along the lines of Uber heard Google's "Don't be evil" motto and thought "They are leaving an open market niche for us!".
At this point the identity of the hacker is irrelevant No. Even if I leave my door unlocked, someone who comes in and steals my stereo should still be punished.
The entity responsible is being punished. They're paying for identity protection for a year and taking yet another public image hit. The hacker? Whoever it was did society a favor by exposing yet another careless company giving away your data because they don't value security.
I partly agree with parfe in principle. Uber is as responsible for this breach with their carelessness as the person who exposed it. That does not change the fact that there were 50,000 victims in the disclosure.
This is different than someone stealing a stereo. This is you tape the security code for your front door onto the door and then your mad at the manufacturer of the door's lock. You want the manufacturer to give any information about the person who broke into your house.
The manufacturer digitally stores the fingerprints of anyone who uses the lock. You want the manufacturer to give you a copy of the fingerprints to help you identify the person who broke into your house. > ...and then your [sic] mad at the manufacturer of the door's lock. There is no evidence that Uber is mad at Github.
No,Uber is fishing for data they don't need. They have an IP address of the intruder. Instead of demanding all the access logs for a months long period, why not compel Github to answer the question "Did this IP address access the Gist in question? If so, what are the timestamps?"
Instead Uber wants all github's access log data for the gist in question which sounds like more incompetence and desperation on Uber's part.
So let me get this straight - They're publishing a secret key on a Gist, and then getting whiny when it somehow gets leaked. Github very clearly states that "secret" gists are NOT private: https://help.github.com/articles/about-gists/
How do we know it was a gist published by Uber, and not a third party? I couldn't find that information in the article or the subpoena.
So let me get this straight - They're publishing a secret key on a Gist, and then getting whiny when it somehow gets leaked. Github very clearly states that "secret" gists are NOT private: https://help.github.com/articles/about-gists/
> getting whiny Actually, they're subpoenaing. This is necessary to identify who may have accessed it; i don't think this is a suit over the privacy of gists.
> This is necessary to identify who may have accessed it
Actually, it's not. If Github's TOS (and their legal argument in response to the subpoena) is strong enough, Uber can go fly a kite.