Live data from Hacker News

Home Depot GitHub token exposed for a year, granted access to internal systems

techcrunch.com

81–90 of 169 posts

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#82
post #6

Given the absolute state of their website on mobile it's hardly surprising. It's faster to find an employee and ask them where an item is at instead of waiting for the search to finish, see that it the "current store" now points to a random location somewhere in a different state, pick the correct store and re-do the search

+1 also, when I'm in my local store it seems like cell connection goes to shit for some reason and then I have to jump on their in store wifi in order to search their website

> when I'm in my local store it seems like cell connection goes to shit for some reason

It's a giant steel and concrete box, that's probably the reason.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#83
post #72

Earlier quoted context omitted.

Yeah, I'm not sure why so many people seem pro-theft for a lack of a better term. I don't believe they are but there's so much resistance to locking up high value items especially if they're valuable ones.

People are anti-surveillance, not pro-theft. Although, plenty of people are pro-theft from the corporations sucking our towns and local economies dry and paying so little that their employees have to rely on foodstamps.

Home Depot making money doesn't make my town rich, the smaller shops making money do. The big corps just suck suck suck.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#84
post #59

Earlier quoted context omitted.

I had to check what the gold standard McMaster-Carr does: their torque wrench drive size widget is sorted 1/4", 3/8", 1/2", 3/4", 1", 1 1/2". Glorious. https://www.mcmaster.com/products/torque-wrenches/

Is it weird that I kinda want to work there?

No. You are likely and automatically extrapolating the attention to detail seen in the outcome into believing that it is a reflection of the attention , thought and method of their internal workings.

Which is a good indicator, but you can’t be sure of. Additionally you may imagine liking it but not enjoy it in life, even if true.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#86
post #73

Earlier quoted context omitted.

Indeed, Home Depot's software is generally so bad. I remember around 2017/2018 time frame when they started showing up to big tech conferences (especially K8s and React.js conferences) really trying to modernize. I spent a few minutes talking to the people manning the booth (which were surprisingly high ranking in the company, at least by title), and came away thinking "I'm glad you're making an effort, but y'all rea…

I'll bet money any new React/K8s/${WEBSCALE} stuff they're building is still just a wrapper over the same old inventory management they've been using for years...probably something like JDEdwards on AS/400.

You would lose that bet. Walmart has invested a LOT in modernizing stuff over the last 10 years. You cannot deliver groceries in less than an hour using the old inventory. It's not perfect, but what it's been done given the scale , it's nothing short of a miracle. Source: I have been working there for 10 years.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#87
post #72
post #32

Earlier quoted context omitted.

Not entirely unsurprising due to the theft issues they face

Yeah, I'm not sure why so many people seem pro-theft for a lack of a better term. I don't believe they are but there's so much resistance to locking up high value items especially if they're valuable ones.

Perhaps just anti-shitty UX.

https://dan.bulwinkle.net/blog/trader-joes-does-not-have-sur...

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#89
post #34

I’m surprised that GitHub, OpenAI etc. doesn’t have automation to scan the usual surfaces for hashes of their access tokens. It seems like a cheap and simple thing to offer your customers a little extra safety. Anybody interested in starting a platform agnostic service to do this?

They do scan but they miss a lot. The frequency decreased after Github started scanning all repositories but I still report leaked secrets to bug bounty programs pretty often. Unfortunately Home Depot don't have a bug bounty program so I don't scan them.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#90

Given the absolute state of their website on mobile it's hardly surprising. It's faster to find an employee and ask them where an item is at instead of waiting for the search to finish, see that it the "current store" now points to a random location somewhere in a different state, pick the correct store and re-do the search

I've never had an employee know what a tool is, much less where to find it. All they're doing is doing this process on a slower, ruggedized phone. I literally watched someone Google "masonry bit" right in front of me.

It varies a lot by store. I’ve been to HDs where they’re all useless, and others where there’s a good number of knowledgeable DIYers working there.

I think a lot of people just expect too much from a big box store employee making $17/hr… You go to HD because you have an easy job and you’re as cheap as their MBAs. If you need help, go to a supply house or an Ace Hardware or something.

Post reply on HN