4 ms·
If you got an email you should: - Change your password on https://hub.docker.com https://hub.docker.com - Check https://github.com/settings/security https://g
by lugg 7y ago
If you got an email you should:
- Change your password on https://hub.docker.com https://hub.docker.com
- Check https://github.com/settings/security https://github.com/settings/security
- Reconnect oauth for Automated Builds
- Roll over effected passwords and API keys stored in private repos / containers
Quick take:
- Password hashes
- Github tokens
- Bitbucket tokens
- Your Automated Builds might need new tokens
Checking my github logs - It looks like they've known about this for at least a full 24 hours. Most people aren't going to have this looked at until Monday which kind of sucks. Hopefully there is more of a postmortem coming.
Is anyone from github able to comment on this as well?
There doesn't seem to be a way for us to tell if a repo was read by these keys over that time period.
- judge2020 7y agoYep - my "deleted by associated Oauth application" event was triggered 2019-04-25 20:12:25 -0400
- typpo 7y agoYesterday at 9pm PT my private Github repo produced this notification: The following SSH key was added to the foo/bar repository by myorg-dockerhub-user: Docker Cloud Build 39:31:51:be:d6:00:c4:ef:c7:74:c2:16:66:33:93:06 If you believe this key was added in error, you can remove the key and disable access... I wonder if this is related? Dockerhub integration and its keys were still present on Github. In any case, I've revoked everything until the impact becomes clearer.
- reidrac 7y agoAt the moment I can't change the password. It fails with "Failed to save password" error, no more information. EDIT: it finally worked, 4th attempt, and very slowly. Looks like something isn't working 100% as it should EDIT 2: aaaand I can't login now with the new password. A password reset did work, but it looks like their password database is under some stress at the moment.
- franee 7y agoSame can't change password
- sodosopa 7y agoI could as of 10 minutes ago
- hn_throwaway_99 7y agoMy guess is their auth system is/was under a ton of load. Specifically to make the password database more secure, the generation of password hashes is very computationally intensive by design (e.g. that's the whole point of something like bcrypt vs. sha1) Password systems really shouldn't be designed to handle a 10x or 100x load without some slowdown. If they could handle that, it means their password DB probably isn't as hardened as it should be.
- shepardrtc 7y agoPassword reset worked for me. Trying to change it from the account page did not.
- rqs 7y agoCan I complain a bit about GitHub? Why I can only authorize my entire GitHub account for third-party access? Could things be slightly better if the authorization is done at repository level?
- Sukram21 7y agoGitHub provides a way for more granular third-party access: GitHub Apps. There, access can be set on a repository level [1]. E.g. Netlify can be configured as a GitHub app. It seems like Docker Hub is implemented as an OAuth app [2], where these granular options are not available and you have to grant access to all your repositories. [1] https://developer.github.com/apps/differences-between-apps/ https://developer.github.com/apps/differences-between-apps/ [2] https://docs.docker.com/docker-hub/builds/link-source/ https://docs.docker.com/docker-hub/builds/link-source/
- andy_ppp 7y agoYou can implement OAuth per repo if github wanted though, or alternatively can you grant access to a specific organisation? Not sure. The default should be per repo auth IMO.
- mmmeff 7y agoHoly shit this is a crazy attack vector.
- matthewaveryusa 7y agoI just looked at github OAuth scopes ( https://developer.github.com/apps/building-oauth-apps/understanding-scopes-for-oauth-apps/ https://developer.github.com/apps/building-oauth-apps/unders... ) honest question, what's the point of using OAuth when the Authz is so coarse? Why not augment to have scopes per repo? Is it considered bad practice to have have a variable (repo name) as a scope?
- nickgros 7y agoIIRC the OAuth2-interfacing application needs to (or at least should) know beforehand exactly what to request access to, so if that's read/write access to all of the user's content, it's trivial. For the external application to know something specific like a particular resource is more complicated to deal with (especially with private/hidden content), so most OAuth providers don't provide that level of granularity. It can be done, it just requires more engineering than most (all?) off-the-shelf OAuth solutions provide, and it's more control than most users actually need.