Live data from Hacker News

Microsoft acquires Github

blogs.microsoft.com

661–670 of 840 posts

Re: Microsoft acquires Github

#661
post #644

Earlier quoted context omitted.

> If you change the leadership and change employee incentives, it might as well be a different company. Exactly. Which is why the idea of "trusting" a corporation, or treating them like you would a human being on any level, is ludicrous. They're a plane crash and a stock dip from becoming a totally different entity.

A person is a midlife crisis[1] or a railway accident[2] away from being a totally different entity. There is no absolute trust, just risk assessment and reevaluation. [1] I thought it was just a cliche until I saw it happen to someone. She went through some things and upended her whole life. [2] https://en.wikipedia.org/wiki/Phineas_Gage

The story of Phineas Gage is a lot less common than that of a company undergoing routine changes in leadership, so it's a bit of a silly comparison.

Re: Microsoft acquires Github

#662

I guess I shouldn't be surprised that come Monday morning all the reasonable critiques are buried at the bottom of the page and all the GitHub + MS love is upvoted to the top, hyping up all the "amazing business synergies". Multibillion dollar mergers like this are huge things, especially for with a big player acquiring a smaller beloved brand like GitHub. Makes one wonder how many of those leaks over the past week w…

> Wake up call, MS ties to NSA

Sure is nice knowing the NSA will have easy access to all the private source code hosted on GitHub. I bet they will find so many new vulnerabilities.

Re: Microsoft acquires Github

#663
post #599
post #422

This is a wake up call. Too many things are relying on Github right now. Microsoft was part of the PRISM program. If Microsoft shares SSL certs with NSA they could do MITM attacks. What if in some very specific cases you download dependencies from GitHub and they give you a different version with malicious code? It's the NSA. They could be smart enough to only deploy those attacks on production servers were nobody is…

Whenever I read these kinds of posts on this website I think of Sterling Hayden in Dr. Strangelove. (The crazy SAC commander who thinks the Russians are plotting to steal Americans' precious bodily fluids). I understand that people don't trust the NSA/US government. And they shouldn't: the US government will always put its interests above yours and mine, and above those of allied countries. At the same time, this stu…

That’s why I only drink rainwater and pure grain alcohol. Purity Of Essence.

Re: Microsoft acquires Github

#664

I guess I shouldn't be surprised that come Monday morning all the reasonable critiques are buried at the bottom of the page and all the GitHub + MS love is upvoted to the top, hyping up all the "amazing business synergies". Multibillion dollar mergers like this are huge things, especially for with a big player acquiring a smaller beloved brand like GitHub. Makes one wonder how many of those leaks over the past week w…

> Wake up call, MS ties to NSA Sure is nice knowing the NSA will have easy access to all the private source code hosted on GitHub. I bet they will find so many new vulnerabilities.

Frankly, I'd be surprised if they didn't already have that access.

Re: Microsoft acquires Github

#665
post #422

This is a wake up call. Too many things are relying on Github right now. Microsoft was part of the PRISM program. If Microsoft shares SSL certs with NSA they could do MITM attacks. What if in some very specific cases you download dependencies from GitHub and they give you a different version with malicious code? It's the NSA. They could be smart enough to only deploy those attacks on production servers were nobody is…

> If Microsoft shares SSL certs with NSA they could do MITM attacks. There is zero reason to believe they do.

Your intention is correct, but your details are not (as are the OPs). Microsoft share's it's SSL certs with the entire planet. Microsoft protects it's private keys and does not share them with the NSA.

The NSA forges Microsoft's SSL keys, they do not need to ask for them.

https://en.wikipedia.org/wiki/Flame_(malware)

Even with the mitigations provided by moving away from MD5, simple integration with a CA would be much more strategically beneficial.

Re: Microsoft acquires Github

#666

I guess I shouldn't be surprised that come Monday morning all the reasonable critiques are buried at the bottom of the page and all the GitHub + MS love is upvoted to the top, hyping up all the "amazing business synergies". Multibillion dollar mergers like this are huge things, especially for with a big player acquiring a smaller beloved brand like GitHub. Makes one wonder how many of those leaks over the past week w…

> Wake up call, MS ties to NSA Sure is nice knowing the NSA will have easy access to all the private source code hosted on GitHub. I bet they will find so many new vulnerabilities.

Github has always been an American company. What makes you think they didn't have access before today?

Re: Microsoft acquires Github

#667
post #363

Earlier quoted context omitted.

Also the company that was responsible for killing the Limux project[0]. [0]: https://en.wikipedia.org/wiki/LiMux

> In November Munich city council decided to revert to Windows by 2020 with all systems being replaced by Windows 10 counterparts. > Reasons cited were adoption and users being unhappy with the lack of software available for Linux. > A report commissioned by Munich and undertaken by Accenture found the most important issues were organizational. > In 2018, journalistic group Investigate Europe released a video documen…

It's not clear-cut in the sense that Munich's IT landscape was and is fragmented which made and makes it very easy to blame IT problems on LiMux. But that doesn't make me believe even for one second that Microsoft didn't lobby their way back to Munich. Here's a little story from some years back about Microsoft's lobbying efforts to prevent usage of ODF as a standard in the UK:

https://www.computerweekly.com/news/2240234078/Government-op...

Re: Microsoft acquires Github

#668
post #422

This is a wake up call. Too many things are relying on Github right now. Microsoft was part of the PRISM program. If Microsoft shares SSL certs with NSA they could do MITM attacks. What if in some very specific cases you download dependencies from GitHub and they give you a different version with malicious code? It's the NSA. They could be smart enough to only deploy those attacks on production servers were nobody is…

There was a great post about this as a hypothetical attack vector and how CSP can help mitigate a large percentage of that surface, can’t find it now.

Re: Microsoft acquires Github

#669
post #599
post #422

This is a wake up call. Too many things are relying on Github right now. Microsoft was part of the PRISM program. If Microsoft shares SSL certs with NSA they could do MITM attacks. What if in some very specific cases you download dependencies from GitHub and they give you a different version with malicious code? It's the NSA. They could be smart enough to only deploy those attacks on production servers were nobody is…

Whenever I read these kinds of posts on this website I think of Sterling Hayden in Dr. Strangelove. (The crazy SAC commander who thinks the Russians are plotting to steal Americans' precious bodily fluids). I understand that people don't trust the NSA/US government. And they shouldn't: the US government will always put its interests above yours and mine, and above those of allied countries. At the same time, this stu…

I personally am not worried. If I was running some nuclear centrifuge in Iran/N.Korea/etc. then I'd be worried.

Re: Microsoft acquires Github

#670
post #653
post #578

Earlier quoted context omitted.

Shortly before the official announcement of the end of LiMux, Microsoft's German headquarter moved to Munich [1]. It's also estimated to cost about 89 million € to return back to Windows [2 (german)], including 24 million € for "external consulting". 1: https://mspoweruser.com/microsoft-germany-moves-into-a-new-h... 2: https://www.heise.de/ct/ausgabe/2017-26-Muenchens-Rueckfall-...

That is still conspiracy and not "Microsoft killing a project".

So, hypothetically of course, if Microsoft subtly let the new Mayor Dieter Reiter know that they will only build their new headquarter in Munich if Windows was to replace LiMux, then what about this could not be considered as Microsoft killing LiMux? Sure, they didn't directly pull the plug, but that's semantics.
Post reply on HN