Live data from Hacker News

GitHub is investigating unauthorized access to their internal repositories

twitter.com

51–60 of 359 posts

Re: GitHub is investigating unauthorized access to their internal repositories

#51

https://pbs.twimg.com/media/HItbXhvW4AAMD8W?format=jpg&name=... All of their repos have been copied and are up for sale. Attackers are TeamPCP, the creators of the Shai-Hulud malware.

If that’s true and they do intend on shredding their copy on sale, what stops GitHub from buying it back themselves? (through a proxy, obv)

I probably wouldn't believe that "shredding". Also there will be legal consequences I think?

Re: GitHub is investigating unauthorized access to their internal repositories

#53
post #4

Is it just me or is this happening way more frequently in the last 4 or 5 months? Coincidently around the same time the models got a lot more capable?

I heard an engineer at Anthropic was submitting 150 PRs per day. That's one PR every 5 to 10 minutes, so you can guess the level of review and quality control involved.

I have days with those kinds of PRs. Usually because I'm too lazy to check color compatibility outside the browser.

Re: GitHub is investigating unauthorized access to their internal repositories

#54
post #48
post #31

Earlier quoted context omitted.

There is a 100% chance that people are using LLMs to find vulnerabilities and build exploits. If it was possible for something to be a 101% chance, that's what it would be.

Apologies to all - I am British. The phrase "non-zero" does cover every case other than zero, but the intent is that it covers some cases more than others. What I'm trying to say is: yes. My intent was just to push back on this specific (and slightly bizarre to me) instance of kind-of-vagueposting, to my eyes written to imply that it might be some sort of unnoticed conspiracy, detectable only by the most enlightened…

Right, no, what I'm snarkily saying is that basically everybody who has ever looked for a vulnerability before is now using LLMs to do it. It's a huge thing in exploit development right now.

Re: GitHub is investigating unauthorized access to their internal repositories

#55
post #30

Earlier quoted context omitted.

It’s a very popular messaging platform for tech enthusiasts.

So? Is this where your corporate paying clients should find out about an issue of this severity? Not to mention Twitter is not an open platform anymore! (A) I'm an employee in an organization paying for Github. (B) I don't have a Twitter account. I already have a Github account because of (A). Why should (B) stop/delay me from getting official comms about this?

I can't imagine they'd spam every account with an email address, though an email to organization owners would make more sense.

Re: GitHub is investigating unauthorized access to their internal repositories

#56

Earlier quoted context omitted.

So? Is this where your corporate paying clients should find out about an issue of this severity? Not to mention Twitter is not an open platform anymore! (A) I'm an employee in an organization paying for Github. (B) I don't have a Twitter account. I already have a Github account because of (A). Why should (B) stop/delay me from getting official comms about this?

I can't imagine they'd spam every account with an email address, though an email to organization owners would make more sense.

> I can't imagine they'd spam every account with an email address

It's not "spam" if it is relevant to me, such as security incident disclosures.

Also, as tiffanyh pointed out, what's wrong with Github blog or is that exclusively for marketing fluff now? That would've been appropriate enough, without having to spend Sendgrid credits.

Re: GitHub is investigating unauthorized access to their internal repositories

#57

Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/

Probably the best option after sending a mass email when customers need to take action. The status page is for reliability issues impacting end users & the blog is for in-depth analysis.

Re: GitHub is investigating unauthorized access to their internal repositories

#58
post #18

The security issue aside, seeing more companies push announcements like these on X as the only official source is a trend I'm not sure I like. I can understand the rationale, this feels lighter and not something that belongs on status.github.com or the blog. Maybe what's actually missing is an official channel for ephemeral stuff on a domain they own, somewhere between a status page and a tweet? Just sharing an obser…

My understanding is that when it's something that requires user action they'd directly send comms to customers.

Re: GitHub is investigating unauthorized access to their internal repositories

#60

https://pbs.twimg.com/media/HItbXhvW4AAMD8W?format=jpg&name=... All of their repos have been copied and are up for sale. Attackers are TeamPCP, the creators of the Shai-Hulud malware.

If that’s true and they do intend on shredding their copy on sale, what stops GitHub from buying it back themselves? (through a proxy, obv)

Nothing, this is one of the most common types of ransomware going on right now, exfiltration only extortion.
Post reply on HN