3 ms·
Why not use your knowledge of these exposed secrets for good? You know which repo they're coming from, it'd be super simple to let the owner know rather than po
by nitza 10y ago
Why not use your knowledge of these exposed secrets for good? You know which repo they're coming from, it'd be super simple to let the owner know rather than potentially costing them time and money.
It also seems as though the only use of this site is to capitalise on other people's mistakes? It looks like you're just handing over leaked data to people who will definitely abuse it, which seems to go against your core business of preventing data leaks?
- lrusnac 10y agoI agree with what you wrote. My two cents are: seems that getting attention goes against being nice to others, such a shame living in such a society.
- tokenizerrr 10y agoYet if people don't know the risk exists, they'll continue being ignorant and fucking up. Awareness is a good thing.
- nitza 10y agoThis isn't awareness though. This is like telling a specific set of people about all the houses near by that have their front door key under the mat. You only become aware of the issue when it is too late.
- koolba 10y agoWould it be considered spamming to pull the email address of the commits and send them an automated email?
- nitza 10y agoWell, you don't need to send an email necessarily, a GitHub issue with a guide on how to include sensitive data in a public repo would probably suffice.
- johncolanduoni 10y agoI suspect it would be easy to secure GitHub's cooperation in this, but almost certainly not for money or via a black box.
- rmc 10y agoWould it be against the GitHub terms of service to do such an email?