3 ms·
Don't you mean on-premise?
by ifhs 10y ago
Don't you mean on-premise?
- Normal_gaussian 10y agoDatacentre's have outstanding track records, and if you secure your box correctly there are few ways to compromise it. On-premise will either be incredibly costly or missing key protections or infrastructure. Self-hosted git (through the many installable git servers or raw git) running on a correctly sized box is almost certainly the way to go
- newsat13 10y agoThis github vulnerability has nothing to do with insecure box. It has to do with a bad application logic. This can happen anywhere - self-hosted or not.
- bsder 10y agoThat is true. But, if I'm running my own instance, the probability is that it doesn't matter if someone else gets access via bad application logic. Everybody is probably employed by the same company. It's a difference of degree: compromising my self-hosted or on-premise server means that somebody already in my employ has more access than they should. If I'm a small organization, that probably doesn't matter. If I'm a big organization, I probably have an IT staff to deal with this and the people involved are still "nominally" under my control. The github mistake means that people completely unrelated to my repository can get access.
- ifhs 10y agoWell, the code can simply be made public by bad application logic. Which is why I thought you where talking of on premise where the intranet will seal off outsiders