4 ms·
Hey HN -- one of the creators here. I saw a few people mention this in the comments and want to re-iterate: this is NOT a bug on GitHub. This is a feature of Gi
by agrinman 8y ago
Hey HN -- one of the creators here. I saw a few people mention this in the comments and want to re-iterate: this is NOT a bug on GitHub. This is a feature of Git that GitHub has to support because we often need to push commits on behalf of other users.
However -- this does illustrate a clear reason why it sometimes makes sense to PGP-sign your releases/commits.
- saagarjha 8y agoI think the title should be changed from "GitHub Commit Forgery" to "Git Commit Forgery".
- geofft 8y agoYeah, I figure you all know that :) I just think calling it "forgery" / "fraudulent" makes it sound like a Git/GitHub vulnerability. It's a feature that depends on trust and goodwill, and the fact that trust can be abused isn't interesting. For instance, if I wrote "Hey HN, one of the creators here" when I'm not, people wouldn't call that "HN comment forgery" - they'd just call it regular lying.
- EthanHeilman 8y ago>It's a feature that depends on trust and goodwill Such features can be a vulnerability, a vulnerability does not have to be an accident >the fact that trust can be abused isn't interesting As a security researcher it is interesting to me but clearly YMMV
- geofft 8y agoAlso I looked at your actual product (a U2F implementation that forwards things to your phone) and it seems pretty cool! Definitely more secure than TOTP. You should Show HN that :-)