Live data from Hacker News

GitHub waited 3 months to notify about potential compromise

news.ycombinator.com

51–60 of 83 posts

Re: GitHub waited 3 months to notify about potential compromise

#51
post #22

Earlier quoted context omitted.

> ... we were unable to determine whether this bug was ever exploited. > ... > Due to the variety of GitHub Apps, their possible scopes, and the repositories they may have been given access to, we are unable to advise on any potential impacts as each customer's situation will be unique. Absence of evidence is not evidence of absence.

That's true, but feels like these are always judgment calls. We can always armchair quarterback their judgment calls, but none of us have the full info. At least GH is sharing this info, which is a good call for trust building IMO.

This is only a judgment call because they have no idea. The fact that they have no idea whether your organization's data was leaked is exactly what people here are complaining about.

Re: GitHub waited 3 months to notify about potential compromise

#53

In the same minute that I learned GitHub had been acquired by Microsoft, I cancelled my pro subscription and began moving my critical repositories elsewhere. I'm old enough to remember the MS that tried to choke the life out of GNU/Linux and spread FUD about all FLOSS, the one that engaged in anti-competetive behavior during the "Browser Wars". I'm not suggesting that this blunder of a delay is related to the Microso…

memory of that stuff is just never ever going to die, is it? yet the same people use google, and facebook, and AWS, like those companies sit upon moral high ground. they do not. Linux succeeded and defeated Microsoft in every single way that matters to open source people, and the response is to continue to hate Microsoft for their loss? I do not understand. Just admit your motivation for saying things like this: you…

> Linux succeeded and defeated Microsoft in every single way that matters to open source people

I don't know, hardware still regularly does not support Linux, the Linux desktop has a risible fraction of the world's user base, popular apps still only exist for winmac.

It won on the server, sure, but that's hardly every single way that matters, at least from what I remember as an open source user in the '00s.

Re: GitHub waited 3 months to notify about potential compromise

#54
post #11

They explained it themselves - there's no evidence of abuse/exploitation. They literally have no legal requirement to even tell you as much as they did. You should be commending them for filling you in at all.

This is incorrect you should re-read the post here cause I think you misunderstood the implication. They lacked the logging at the time to know what apps were impacted and the extent to which customers were compromised by this. They are legally obligated to disclose security risks like this which is why they did. You should consider setting a higher bar for your commendations.

Re: GitHub waited 3 months to notify about potential compromise

#55

Earlier quoted context omitted.

That’s a pretty neoliberal attitude to effecting systemic change, do you think that’s enough to mitigate those behaviors considering they crop up elsewhere and ongoing

If refusing to do business with a company whose business practices you don't like is "neoliberal" then the term has officially been stripped of any meaning, significance, or usefulness.

Neoliberal has always been an meaningless slur.

Re: GitHub waited 3 months to notify about potential compromise

#56
post #55

Earlier quoted context omitted.

If refusing to do business with a company whose business practices you don't like is "neoliberal" then the term has officially been stripped of any meaning, significance, or usefulness.

Neoliberal has always been an meaningless slur.

[deleted]

Re: GitHub waited 3 months to notify about potential compromise

#58

In the same minute that I learned GitHub had been acquired by Microsoft, I cancelled my pro subscription and began moving my critical repositories elsewhere. I'm old enough to remember the MS that tried to choke the life out of GNU/Linux and spread FUD about all FLOSS, the one that engaged in anti-competetive behavior during the "Browser Wars". I'm not suggesting that this blunder of a delay is related to the Microso…

memory of that stuff is just never ever going to die, is it? yet the same people use google, and facebook, and AWS, like those companies sit upon moral high ground. they do not. Linux succeeded and defeated Microsoft in every single way that matters to open source people, and the response is to continue to hate Microsoft for their loss? I do not understand. Just admit your motivation for saying things like this: you…

> yet the same people use google, and facebook, and AWS,

Speak for yourself.

For me, the lesson I learned while growing up with the MS of the 90's was to not trust any big corporation. The power imbalance is too large, individuals have no way to protect themselves and they will take any and every opportunity to exploit that.

This pattern can be seen with in the 90's with Windows, it can be seen today with Github and LinkedIn (talk with recruiters and they will tell you how MS is jacking up the prices and removing functionality) and it can be seen with any of Big Tech in the last 20 years.

Re: GitHub waited 3 months to notify about potential compromise

#59
post #6

My recent experience with GitHub regarding a security issue was not very positive either.[1] It turned out, unlike two vendors I notified that were affected, they just didn't care. And they didn't bother to even tell me that they didn't care. It's a very edge-case issue in Enterprise SSO, so I wasn't really able to generate any blowback with disclosure either. But if you find an org with just the right setup it blows…

How is tailscale mitigating this? They can’t enforce GitHub SAML at their end, right?

The membership API returns a 403 if no SAML session exists. Check the remedy section of the post.

This was an accidental find and GitHub has refused to document it.

Re: GitHub waited 3 months to notify about potential compromise

#60

Earlier quoted context omitted.

My guess is that GitHub ignores issues so they don't have to pay out bug bounties.

I find these takes so silly. Bug bunties are a rounding error in the companies budgets, even if they paid out much more freely. There are many I think much more obvious reasons orgs are slow on issues - everything from figuring what is an issue, trying to chase down impacts and more.

I think it's not a matter of not wanting to pay, but not wanting to have your departments "we had to pay someone to fix your security bugs" metric go up.

That's also likely why issues in the core product are taken more seriously.

Post reply on HN