4 ms·
Of course, that's because you did something morally wrong. This is different than what people label as 'echo chamber'. In there you'd have either 100% love or
by quickben 10y ago
Of course, that's because you did something morally wrong.
This is different than what people label as 'echo chamber'. In there you'd have either 100% love or hate.
Having mixed responses verging toward hate, says you screwed up and the general public doesn't approve of it.
- daenney 10y agoThey didn't do anything morally wrong. The data is already public and easily searchable with a few regex tricks. They just made it a tiny bit more convenient but anyone that's thought of this as a source of credentials can easily scrape it themselves. If anything what they're doing might help shine a light on how big of an issue this actually is and provide a helpful corpus of data to train algorithms on to detect this better. The issue at this point is far too big to be able to go around and notify everyone about this. There's also plenty of repositories that are abandoned or maintainers that are MIA so you'll never be able to properly resolve all of it.
- quickben 10y agoMorality depends on current life views, upbringing, societal norms etc. You may disagree and that is fully in your right. However, account for the fact that not all HN readers are from US. In other countries what they did is in some case against the law (promoting/enabling criminal behaviour and activities/etc).
- daenney 10y agoI'm not from the US so that's already accounted for.
- cookiecaper 10y agoThis is part of the disclosure debate that's been going on in the security industry for decades now. Some people take an aggressive full-disclosure stance and believe every flaw should be publicized immediately and some take a non-disclosure stance and say flaws should never be published until they've become entirely irrelevant. Most have come to the middle and settled on a "responsible disclosure" paradigm, where researchers notify the maintainers and work with them to set a reasonable timeline for the correction of the issue. The issue is publicly disclosed somewhere between 30-90 days after the private disclosure to maintainers; this gives them time to correct the issue and push out updates, and it also incentivizes them to fix the issue instead of sitting on it forever and allowing it to be exploited as a zero-day. It would've been good to see this paradigm applied here; the search could've sent a message to the repository owner with a note that the result would become public in 60 days, and to ensure all keys had been rotated and that secrets were no longer stored in git after that point. In any case, none of these people are operating from a morally dubious perspective. I would suggest you refrain from impugning their motives. Virtually everyone in the security community has the end goal of promoting secure software. Aggressive full disclosure advocates believe that their methods will work most effectively not only at getting issues that exist fixed ASAP, but also at ensuring companies adopt strong and safe practices moving forward, since there won't be second chances.