3 ms·
Could you please give me a link to that? Are users in danger of a possible hack?
by bkovacev 9y ago
Could you please give me a link to that? Are users in danger of a possible hack?
- lstamour 9y agohttps://news.ycombinator.com/item?id=15442636 https://news.ycombinator.com/item?id=15442636 - No more a danger than on most sites, it's just something to consider
- wlesieutre 9y agoThe difference pointed out in the headline being that when NYT, Amazon, Wikipedia, etc, have compromised scripts they can serve fake flash updates. If CircleCI has them they can compromise my source code and API keys. The vulnerability might be the same, but the danger to users is not. Excerpt for reference: This is a problem because the CircleCI browser context has full access to the CircleCI API, which is hosted on the same domain, so all eight of those companies' scripts can make requests to CircleCI API endpoints. Furthermore CircleCI customers frequently either include credentials in source code or as environment variables in CircleCI. Set these, and you are trusting that CircleCI won't get compromised, or at least, your application is at most as secure as CircleCI is.
- nikolay 9y agoPotentially, yes! Here's the post about CircleCI: https://news.ycombinator.com/item?id=15442636 https://news.ycombinator.com/item?id=15442636