Live data from Hacker News

GitHub is investigating unauthorized access to their internal repositories

twitter.com

61–70 of 359 posts

Re: GitHub is investigating unauthorized access to their internal repositories

#62
post #4

Is it just me or is this happening way more frequently in the last 4 or 5 months? Coincidently around the same time the models got a lot more capable?

You know how Windows used to get a majority of the malware due to market share?

Now the market share is all the AI agent users.

Re: GitHub is investigating unauthorized access to their internal repositories

#63
post #30

Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/

It’s a very popular messaging platform for tech enthusiasts.

also a very popular messaging platform for [redacted] enthusiasts

Re: GitHub is investigating unauthorized access to their internal repositories

#64

Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/

It's certainly not the right platform. It'd be one thing if they had any official communication on the matter anywhere else. Maybe they're ashamed and are trying to limit the visibility while only technically issuing an announcement.

They announced this exclusively on X.com, which ranks barely above Pinterest in terms of usage. That's below Reddit, Snapchat, WeChat, and Instagram, and requires a user account to view profiles and posts. And that's ignoring all the reasons X is a divisive platform with an extreme political bent.

GitHub chose not to announce this on any other social media either (BlueSky, Facebook, TikTok, YouTube, LinkedIn, or Mastodon, as of this posting, and with no emails sent on the matter.)

Re: GitHub is investigating unauthorized access to their internal repositories

#65
As some of us stated in the last weeks: Microsoft is working hard to get people to reconsider GitHub. All those small issues keep on adding up. Something is seriously flawed at Microsoft here - those problems did not exist in that way 2 or 3 years ago. It coincides with the rise of AI.

Re: GitHub is investigating unauthorized access to their internal repositories

#66
post #26
post #14

GitHub: "We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity."

It reminds me of the famous "mistakes were made" Nixon quote. "We are investigating unauthorized access" sounds much better than "we've been hacked"

This reminds me of George Carlin standup routine about PTSD. If you want to make any bad news sound less bad, just wrap the concept around complicated jargon to sterilize it.

Re: GitHub is investigating unauthorized access to their internal repositories

#69
post #6

- Use Static analysis for GHA to catch security issues: https://github.com/zizmorcore/zizmor - set locally: pnpm config set minimum-release-age 4320 # 3 days in minutes https://pnpm.io/supply-chain-security for other package managers check: https://gist.github.com/mcollina/b294a6c39ee700d24073c0e5a4e... - add Socket Free Firewall when installing npm packages on CI https://docs.socket.dev/docs/socket-firewall-free#git…

Disabling vscode/cursor extensions auto-updates also makes sense

Re: GitHub is investigating unauthorized access to their internal repositories

#70

non-twitter link: https://xcancel.com/github/status/2056884788179726685#m

This should be the defacto for all X links. For users who aren't signed in, X is such a hostile website you can't see anything.

I guess it's hostile to signed in users in a different way.

Post reply on HN