Live data from Hacker News

Chef-sugar stands its grounds against ICE contract

github.com

1–9 of 9 posts

Re: Chef-sugar stands its grounds against ICE contract

#4
> Earlier today, a former Chef employee removed several Ruby Gems, impacting production systems for a number of our customers.

That's some horrendous infosec. Why would ICE or anyone use this? Can't Chef use, err, Chef or something like that to remove all credentials as soon as employees leave the organization?

Re: Chef-sugar stands its grounds against ICE contract

#6

Chef's official stance remains unchanged. Their blogpost: https://blog.chef.io/2019/09/19/chefs-position-on-customer-e...

> For context, we began working with DHS-ICE during the previous administration

That should have been Chef's only response, really. (That, and they still need to explain how a former developer somehow managed to break something.)

Re: Chef-sugar stands its grounds against ICE contract

#7
post #6

Chef's official stance remains unchanged. Their blogpost: https://blog.chef.io/2019/09/19/chefs-position-on-customer-e...

> For context, we began working with DHS-ICE during the previous administration That should have been Chef's only response, really. (That, and they still need to explain how a former developer somehow managed to break something.)

The most depressing part is that people will only care about what ICE are doing until the next election

Re: Chef-sugar stands its grounds against ICE contract

#8
post #4

> Earlier today, a former Chef employee removed several Ruby Gems, impacting production systems for a number of our customers. That's some horrendous infosec. Why would ICE or anyone use this? Can't Chef use, err, Chef or something like that to remove all credentials as soon as employees leave the organization?

It was his own gem, hosted under his own account, not Chef's. It's apparently just relied on by almost the entire Chef ecosystem, including Chef's own systems.