Earlier quoted context omitted.
> ... we were unable to determine whether this bug was ever exploited. > ... > Due to the variety of GitHub Apps, their possible scopes, and the repositories they may have been given access to, we are unable to advise on any potential impacts as each customer's situation will be unique. Absence of evidence is not evidence of absence.
That's true, but feels like these are always judgment calls. We can always armchair quarterback their judgment calls, but none of us have the full info. At least GH is sharing this info, which is a good call for trust building IMO.
GitHub waited 3 months to notify about potential compromise
51–60 of 83 posts
Re: GitHub waited 3 months to notify about potential compromise
#52Re: GitHub waited 3 months to notify about potential compromise
#53In the same minute that I learned GitHub had been acquired by Microsoft, I cancelled my pro subscription and began moving my critical repositories elsewhere. I'm old enough to remember the MS that tried to choke the life out of GNU/Linux and spread FUD about all FLOSS, the one that engaged in anti-competetive behavior during the "Browser Wars". I'm not suggesting that this blunder of a delay is related to the Microso…
memory of that stuff is just never ever going to die, is it? yet the same people use google, and facebook, and AWS, like those companies sit upon moral high ground. they do not. Linux succeeded and defeated Microsoft in every single way that matters to open source people, and the response is to continue to hate Microsoft for their loss? I do not understand. Just admit your motivation for saying things like this: you…
I don't know, hardware still regularly does not support Linux, the Linux desktop has a risible fraction of the world's user base, popular apps still only exist for winmac.
It won on the server, sure, but that's hardly every single way that matters, at least from what I remember as an open source user in the '00s.
Re: GitHub waited 3 months to notify about potential compromise
#54They explained it themselves - there's no evidence of abuse/exploitation. They literally have no legal requirement to even tell you as much as they did. You should be commending them for filling you in at all.
Re: GitHub waited 3 months to notify about potential compromise
#55Earlier quoted context omitted.
That’s a pretty neoliberal attitude to effecting systemic change, do you think that’s enough to mitigate those behaviors considering they crop up elsewhere and ongoing
If refusing to do business with a company whose business practices you don't like is "neoliberal" then the term has officially been stripped of any meaning, significance, or usefulness.
Re: GitHub waited 3 months to notify about potential compromise
#56Re: GitHub waited 3 months to notify about potential compromise
#57Re: GitHub waited 3 months to notify about potential compromise
#58In the same minute that I learned GitHub had been acquired by Microsoft, I cancelled my pro subscription and began moving my critical repositories elsewhere. I'm old enough to remember the MS that tried to choke the life out of GNU/Linux and spread FUD about all FLOSS, the one that engaged in anti-competetive behavior during the "Browser Wars". I'm not suggesting that this blunder of a delay is related to the Microso…
memory of that stuff is just never ever going to die, is it? yet the same people use google, and facebook, and AWS, like those companies sit upon moral high ground. they do not. Linux succeeded and defeated Microsoft in every single way that matters to open source people, and the response is to continue to hate Microsoft for their loss? I do not understand. Just admit your motivation for saying things like this: you…
Speak for yourself.
For me, the lesson I learned while growing up with the MS of the 90's was to not trust any big corporation. The power imbalance is too large, individuals have no way to protect themselves and they will take any and every opportunity to exploit that.
This pattern can be seen with in the 90's with Windows, it can be seen today with Github and LinkedIn (talk with recruiters and they will tell you how MS is jacking up the prices and removing functionality) and it can be seen with any of Big Tech in the last 20 years.
Re: GitHub waited 3 months to notify about potential compromise
#59My recent experience with GitHub regarding a security issue was not very positive either.[1] It turned out, unlike two vendors I notified that were affected, they just didn't care. And they didn't bother to even tell me that they didn't care. It's a very edge-case issue in Enterprise SSO, so I wasn't really able to generate any blowback with disclosure either. But if you find an org with just the right setup it blows…
How is tailscale mitigating this? They can’t enforce GitHub SAML at their end, right?
This was an accidental find and GitHub has refused to document it.
Re: GitHub waited 3 months to notify about potential compromise
#60Earlier quoted context omitted.
My guess is that GitHub ignores issues so they don't have to pay out bug bounties.
I find these takes so silly. Bug bunties are a rounding error in the companies budgets, even if they paid out much more freely. There are many I think much more obvious reasons orgs are slow on issues - everything from figuring what is an issue, trying to chase down impacts and more.
That's also likely why issues in the core product are taken more seriously.