Vote at the ballot box and with your dollars. Do not reward executives, lawyers, or engineers who dissemble or obfuscate.
GitHub waited 3 months to notify about potential compromise
31–40 of 83 posts
Re: GitHub waited 3 months to notify about potential compromise
#32Earlier quoted context omitted.
>Each of these tokens are valid for up to 1 hour. > GitHub quickly fixed the issue and established that this bug was recently introduced, existing for approximately 5 days between 2022-02-25 18:28 UTC and 2022-03-02 20:47 UTC. It doesn't sound like there is anything you can or need to do with respect to these tokens (whether they were used to take action with elevated permissions is a different thing, but it doesn't…
It seems like the appropriate thing to do would be to inform anyone who had tokens created during the affected time period, so they could assess if any of the permissions led to undesired changes. Instead of GitHub saying “we don’t have hard proof of anything bad happening” and waiting 3 months, just give the customer the time of relevant token creations.
Re: GitHub waited 3 months to notify about potential compromise
#33Earlier quoted context omitted.
> They literally have no legal requirement to even tell you as much as they did. Is ‘fulfilling legal requirements’ all you look for in a business relationship? A restaurant has no legal requirement to make this food tasty but it’s what I’m looking for when choosing where to go.
As someone who works in the reputation management sector, fulling legal requirements is crucial in establishing a presence in key markets. However, oversharing of internal information that's not required by legal requirements can lead to unnecessary reputation damage, which would lead to a decrease in value for key stakeholders. I think many engineers often overlook the business implication of disclosing security iss…
Re: GitHub waited 3 months to notify about potential compromise
#34In the same minute that I learned GitHub had been acquired by Microsoft, I cancelled my pro subscription and began moving my critical repositories elsewhere. I'm old enough to remember the MS that tried to choke the life out of GNU/Linux and spread FUD about all FLOSS, the one that engaged in anti-competetive behavior during the "Browser Wars". I'm not suggesting that this blunder of a delay is related to the Microso…
Re: GitHub waited 3 months to notify about potential compromise
#35In the same minute that I learned GitHub had been acquired by Microsoft, I cancelled my pro subscription and began moving my critical repositories elsewhere. I'm old enough to remember the MS that tried to choke the life out of GNU/Linux and spread FUD about all FLOSS, the one that engaged in anti-competetive behavior during the "Browser Wars". I'm not suggesting that this blunder of a delay is related to the Microso…
Re: GitHub waited 3 months to notify about potential compromise
#36In the same minute that I learned GitHub had been acquired by Microsoft, I cancelled my pro subscription and began moving my critical repositories elsewhere. I'm old enough to remember the MS that tried to choke the life out of GNU/Linux and spread FUD about all FLOSS, the one that engaged in anti-competetive behavior during the "Browser Wars". I'm not suggesting that this blunder of a delay is related to the Microso…
What are you using now? I've only heard of GNU Savannah.
Re: GitHub waited 3 months to notify about potential compromise
#37My recent experience with GitHub regarding a security issue was not very positive either.[1] It turned out, unlike two vendors I notified that were affected, they just didn't care. And they didn't bother to even tell me that they didn't care. It's a very edge-case issue in Enterprise SSO, so I wasn't really able to generate any blowback with disclosure either. But if you find an org with just the right setup it blows…
Re: GitHub waited 3 months to notify about potential compromise
#38Given it existed for 5 days and you’re only now finding out about it, it sounds to me like it was perhaps a bug that was fixed without realising the full impact of it, or perhaps without realising it made it to production; and only an audit that happened later caught it. Not ideal by any means. I’d be curious to know if my theory is correct or not.
Their statements indicate they were aware and investigating. My frustration is that they didn't give users the opportunity to do their own timely investigation. > GitHub learned via a customer support ticket that GitHub Apps were able to generate scoped installation tokens with elevated permissions. Each of these tokens are valid for up to 1 hour. > GitHub quickly fixed the issue and established that this bug was rec…
Re: GitHub waited 3 months to notify about potential compromise
#39In the same minute that I learned GitHub had been acquired by Microsoft, I cancelled my pro subscription and began moving my critical repositories elsewhere. I'm old enough to remember the MS that tried to choke the life out of GNU/Linux and spread FUD about all FLOSS, the one that engaged in anti-competetive behavior during the "Browser Wars". I'm not suggesting that this blunder of a delay is related to the Microso…
yet the same people use google, and facebook, and AWS, like those companies sit upon moral high ground. they do not.
Linux succeeded and defeated Microsoft in every single way that matters to open source people, and the response is to continue to hate Microsoft for their loss? I do not understand.
Just admit your motivation for saying things like this: you hate Microsoft because Slashdot told you to, or tells you to, and you want to let people know about that, unprompted. Nothing about Microsoft's behavior in the 1990s has any bearing on what GitHub does today.
Re: GitHub waited 3 months to notify about potential compromise
#40I just got it as well and don't understand what I can do. Can I somehow force all generated tokens to be revoked and get apps to generate new tokens to be on the safe side? Or, rather, is there a way to do this without uninstalling the apps and installing them again?