Live data from Hacker News

GitHub is investigating unauthorized access to their internal repositories

twitter.com

221–230 of 359 posts

Re: GitHub is investigating unauthorized access to their internal repositories

#221

Earlier quoted context omitted.

If that’s true and they do intend on shredding their copy on sale, what stops GitHub from buying it back themselves? (through a proxy, obv)

I probably wouldn't believe that "shredding". Also there will be legal consequences I think?

counter intuitively criminal ransomware gangs operate on trust. They have to ensure that we believe they really will shred it, otherwise no victim will ever pay a ransom ever again.

Therefore one way to weaken these criminals would be to weaken this trust factor. In a way therefore comments like "can we actually believe they will really shred it" goes towards this aim.

I have to wonder what criminal hacking gangs that do not operate on trust would do. Would it be like the replacement of organized crime (mafia) with the arguably wider damaging unorganized violent drug gangs?

Re: GitHub is investigating unauthorized access to their internal repositories

#222
post #212
post #103

Do they know what the attackers were after? Maybe they were just trying to help fix the availability problems.

The availibilty problems are caused by incapable managers overloading Azure boxes, code fixes will not help much. Maybe they get into HR and help get them fired. And help rehire the ones who could fix it. But that needs a nation state actor, not just your best hacker group.

No, that is only the cause of some of the uptime issues. Some have clearly been caused by deploying briken code.

Re: GitHub is investigating unauthorized access to their internal repositories

#223
> I think one key detail is that all malicious extensions were masquerading as "themes". Creating a permission system would mitigate that, where a theme should only have permission to change visual attributes of VsCode.

upvote here: https://github.com/microsoft/vscode/issues/52116#issuecommen...

VsCode and other IDEs have basically no permission system (spoiler alert: Browser Extension permission system is also weak).

People like myself and many others have called this out over the years, but Micro$lop and others just didn't act at all - at least there's some irony in that they were hacked by way of their own unsecure permission architecture.

Re: GitHub is investigating unauthorized access to their internal repositories

#224
post #155
post #150

Earlier quoted context omitted.

You are kind of saying it's a good idea or at least a totally acceptable one. You're saying Twitter is famous for being famous, and looking down at someone who expresses dismay at this for being behind the times.

I do not have a Twitter account. You do. It is the cesspool of humanity and one of the reason the Internet has become so shit. Please try not to contradict my very words to make a point. That’s very Twitter-like of you.

Much more reasonable to oppose 2026 X as the default platform than it was to oppose 2015 Twitter as the default platform.

I mean reasonable both times but you obviously understand why one might have changed their mind in recent years

Re: GitHub is investigating unauthorized access to their internal repositories

#225
post #159
post #155

Earlier quoted context omitted.

I do not have a Twitter account. You do. It is the cesspool of humanity and one of the reason the Internet has become so shit. Please try not to contradict my very words to make a point. That’s very Twitter-like of you.

Fair enough! Not a fan of Twitter either. Which is why I wouldn't want to normalize it being the kind of place where company announcements are made. IMO anyone who sees it as worrying is right, and I'm glad they're not desensitized. Just because it's been going on for a decade doesn't make it any less crazy that Twitter has become a primary source of news.

> Just because it's been going on for a decade doesn't make it any less crazy that Twitter has become a primary source of news.

I agree. Still, this is the state of things, and well outside my control.

Re: GitHub is investigating unauthorized access to their internal repositories

#226

non-twitter link: https://xcancel.com/github/status/2056884788179726685#m

This should be the defacto for all X links. For users who aren't signed in, X is such a hostile website you can't see anything. I guess it's hostile to signed in users in a different way.

I just have an xcancel extension rewrite the links on the fly

Re: GitHub is investigating unauthorized access to their internal repositories

#227

> I think one key detail is that all malicious extensions were masquerading as "themes". Creating a permission system would mitigate that, where a theme should only have permission to change visual attributes of VsCode. upvote here: https://github.com/microsoft/vscode/issues/52116#issuecommen... VsCode and other IDEs have basically no permission system (spoiler alert: Browser Extension permission system is also weak)…

PS: People would be best to run your IDE Extensions in devcontainers only ... also better put VSCode in a VM as well.

Re: GitHub is investigating unauthorized access to their internal repositories

#228
post #155

Earlier quoted context omitted.

I do not have a Twitter account. You do. It is the cesspool of humanity and one of the reason the Internet has become so shit. Please try not to contradict my very words to make a point. That’s very Twitter-like of you.

Much more reasonable to oppose 2026 X as the default platform than it was to oppose 2015 Twitter as the default platform. I mean reasonable both times but you obviously understand why one might have changed their mind in recent years

Asking on behalf of Github’s PR team: what is the suggested alternative to X to post our updates to reach the largest amount of people, companies, as well as promote our brand?

I haven’t seen any suggestion in this thread. status.github.com fails many of these criteria.

Re: GitHub is investigating unauthorized access to their internal repositories

#229
post #17

Earlier quoted context omitted.

It's more likely that it isn't coincidental at all: software development-oriented LLMs became a lot better towards the end of 2025, and so there's a non-zero chance that people are using them to find new security exploits. (People are not sleeping on this and it is not something people have failed to notice. I don't use LLMs at all and even I have noticed it - largely because there is approximately nobody that isn't…

I think the other side is much more important. With company mandates to use AI as much as possible, there has been a deluge of low-quality PRs. Everybody is feeling tired from reviewing those, and quite possibly numerous security issues have been introduced since.

This really feels like what's happening where i work. Management wants everything done yesterday. Juniors and seniors alike are giving me pure slop PRs to review. I point out an issue and the next draft from Claude has two more. It's extremely exhausting, and it's not like I'm reviewing every PR or catching every issue.

Re: GitHub is investigating unauthorized access to their internal repositories

#230
post #63
post #30

Earlier quoted context omitted.

It’s a very popular messaging platform for tech enthusiasts.

also a very popular messaging platform for [redacted] enthusiasts

The only metric that matters when choosing a platform to broadcast announcements is ‘very popular’.
Post reply on HN