5 ms·
Did they then change their minds? The github repository is gone (404), and the user does not have any repositories: https://github.com/MICROSOFT-XBOX-ATG/MICRO
by Ironlink 10y ago
Did they then change their minds? The github repository is gone (404), and the user does not have any repositories:
https://github.com/MICROSOFT-XBOX-ATG/MICROSOFT_UWP_UNREAL https://github.com/MICROSOFT-XBOX-ATG/MICROSOFT_UWP_UNREAL
https://github.com/MICROSOFT-XBOX-ATG?tab=repositories https://github.com/MICROSOFT-XBOX-ATG?tab=repositories
- ocdtrekkie 10y agoIf you read the linked post, it explains how you need to connect GitHub to your Epic Games account to see the repo if you see the 404 error. (I didn't know this sort of thing was a GitHub feature, so it was interesting to me. I initially made the same mistake.)
- htaunay 10y ago404 is Github's default answer for when you try to access a private repo you don't have access to. You can test it by logging out of our account and attempting to access a private repo url you usually can access.
- jandrese 10y agoShouldn't this be a 403? Making it a 404 is confusing.
- ocdtrekkie 10y agoThe primary reason to do this is the same as why most logins will just say "incorrect username or password" rather than revealing the username is in fact, correct, and just the password is wrong. You don't want to reveal the identity or location of something that is hidden. If I have an unannounced project at github.com/ocdtrekkie/unannouncedproject, you might discover the name of my unannounced project by fishing for URLs that come up 403 instead of 404. Confirming something exists narrows what someone looking to find out something secret has to look for. If you know what my username is, you only have to guess passwords for that username. If you know what my project name is, you only need to look for references elsewhere to that project name. Just knowing the project exists could be telling, if your project was like... github.com/apple/nintendo-igameboyphone it would potentially be a really revealing thing if you hadn't announced it yet. Slack had a big fiasco when entering a fake @whatever.com address would let someone see whatever.com's teams prior to email verification. From just room names alone you could discern some potential acquisitions in negotiation, teams at Microsoft or Apple you might not have otherwise known existed, etc.
- MichaelGG 10y agoA command line timing attack I just tried seems to be able to distinguish between the two. It seems that, as a logged-in user, the real repo takes around 5% longer to respond than a fake one. But this might not be robust - I just used time + loop in bash. Perhaps someone wants to setup a list of nonpublic+fake repos and see if there's consistent difference.
- jandrese 10y agoSeems to me if you don't want a project to be public knowledge don't put it on the Internet. Private projects are what internal repositories are for. You can always transition it to Github once it's open to the public. At the very least, the administrators at Github are going to know about your project, and you don't know who they all are.
- jimcsharp 10y agoI was just noodling about this idea for my current project. I suppose 403ing would enable an adversary to know if something exists or not?
- mike1o1 10y agoAs mentioned in the post, you need to register for the repository. Steps are below: "If you see a 404 page, you need to complete the enrollment process: Create a GitHub account. Sign up for the Epic program Follow the instructions to associate your Epic Program account with your GitHub account. Join the Epic GitHub Org (from the email invitation you receive after Step 3)"
- cocotino 10y agoI hope somebody mirrors this elsewhere. This is just perverse.
- Kubuxu 10y agoThis would be against the license. It is hard because this is the way for the EULA and Licanse of the software to be enforceable.
- detaro 10y agoWhat's perverse? That they use Github for proprietary software? That they give source-code access to users of their software?
- huac 10y agoI don't agree with mirroring the repo elsewhere but agree that the process could be much more streamlined.
- milcron 10y agoFYI these restrictions are due to Epic, not Microsoft.
- deleted 10y ago[deleted]
- electroly 10y agoThat's what it looks like when a repository is made private and you don't have access to it. UE4's code is only available to licensees; I'm sure it was never supposed to be publicly viewable.