Plans to Re-enable the GitHub Integration
blog.heroku.com
Plans to Re-enable the GitHub Integration
1–10 of 40 posts
Re: Plans to Re-enable the GitHub Integration
#2Re: Plans to Re-enable the GitHub Integration
#3My armchair guess is whatever method someone used to gain access more than likely took an architectural change to fix.
Re: Plans to Re-enable the GitHub Integration
#4957 hours. Pretty crazy. Can't think of another 'outage' with that kind of length on it in awhile or ever.
Re: Plans to Re-enable the GitHub Integration
#5957 hours. Pretty crazy. Can't think of another 'outage' with that kind of length on it in awhile or ever.
(We are.. a tiny fraction of Heroku, in terms of anything you like - it's excusable IMO that it was an untested procedure not smooth etc., small team with MVPs to ship.)
In 957h I would think you can start to think about bringing on a specialist on contract (or implement the new GH App based still-future version mentioned) if the permanent team can't figure it out / don't have capacity! It's not good for reputation, surely, I have to imagine it was considered low priority rather than something they actively tried but failed to fix for so long, but I don't think that's a good look, even if metrics show it's little-used or only by free tier or whatever.
Re: Plans to Re-enable the GitHub Integration
#6> I'd love to hear from someone at GitHub (anonymously or not) what they've done to be satisfied with action Heroku have taken that would allow the integration to be turned back on. My confidence in Heroku to give me accurate information on this is low.
As far as I can tell from Heroku's communications they:
- Have no idea how the attacker gained access
- Have no idea if the attacker still has access
If they do know these things then I've not seen them say so.
Re: Plans to Re-enable the GitHub Integration
#7957 hours. Pretty crazy. Can't think of another 'outage' with that kind of length on it in awhile or ever.
Re: Plans to Re-enable the GitHub Integration
#8I'm actually impressed that Heroku despite so much backlash refused to enable it until they were certain it was secure. Even if it took forever and no doubt probably lost them significant customers. My armchair guess is whatever method someone used to gain access more than likely took an architectural change to fix.
Re: Plans to Re-enable the GitHub Integration
#9> In an effort to improve the security model of the integration, we are exploring additional enhancements in partnership with GitHub…
Github permissions possibilities continually confuse me, but integrations are always asking for more github permissions than I really want to give them, more than it seems like they should need for the integration; I'm never clear in an individual case if this is because they are doing it wrong, or because github doesn't offer granular enough permissions. Some vendors with integrations in the past, when I've complained, have _claimed_ it's because github does not offer any more granular permission that includes what they need.
This announcement still leaves it unclear which it was in this case.
I wonder if the fallout of this thing will result in github fixing whatever it is about their permissions system that is leading to integrations asking for and getting more permissions than should be required?
I have seen most blame over this kerfuffle focused on heroku, but I suspect github's too blunt integration permissions could use some ire, which might help motivate Microsoft/github to improve things.
Re: Plans to Re-enable the GitHub Integration
#10I'm actually impressed that Heroku despite so much backlash refused to enable it until they were certain it was secure. Even if it took forever and no doubt probably lost them significant customers. My armchair guess is whatever method someone used to gain access more than likely took an architectural change to fix.