3 ms·
What I think happened: Someone contacted Capital One by email to responsibly disclose to them that there were SSN's and other data on a Gist. That person found
by throwawaywego 7y ago
What I think happened: Someone contacted Capital One by email to responsibly disclose to them that there were SSN's and other data on a Gist. That person found them with a simple crawler or search.
Then Cap 1 thought: If some rando can find this after a lot of damage has been done, why can't Github find these seconds after upload?
And, really, there is no technical excuse. It is perfectly possible to do this, and lots of big companies do this (or hire security companies to do this for them). Mention their name on some deep web hacking forum, a pastebin, or inside Github code, and somewhere an alarm goes off.
Github could (and should) warn if a user uploads loads of PII-like data. For the cost of running a search server and a few moderators. "Are you sure you want to upload your AWS credentials in a public repository?".
Github is somewhere halfway between moderated and a content platform. They already have a history of taking down repositories if they link to PII data (or infringe copyright, or damage U.S. national security): http://web.archive.org/web/20180619172528/https://github.com/antiboredom/ice-linkedin http://web.archive.org/web/20180619172528/https://github.com... so not acting on this specific repo with SSN numbers could be seen as a poor/shoddy job on their part. Github is certainly in the dominant position to mitigate spread of PII data, so they should have their stuff in order.