16 ms·
In this sense "hacked" doesn't make sense. 8f everything was intended for open source.
by scared2 6y ago
In this sense "hacked" doesn't make sense. 8f everything was intended for open source.
- badRNG 6y agoI think there are still two concerns here even if everything is intended to eventually become open source. One, this doesn't address exactly how the repo was compromised. Likely one of the many folks with access had their credentials compromised, but until we know, there may be risk to other projects. Two, as the article mentions, it may not have had all passwords or API keys scrubbed.
- tlbsofware 6y agoThe culprit would now have the ability to merge pull requests and make changes to the open source codes master branch. So if one of these owner accounts was hacked. Then yes this is a hack.
- dependenttypes 6y agoHaving openpgp-signed commits would prevent such an issue.
- jlgaddis 6y agoWould it? Couldn't the "hacker" have simply generated a new GPG key and added it to the account he had control of?
- dependenttypes 6y agoThe users would have specific keys trusted.
- as300 6y agoSure, but isn't the point of git to be able to roll back all changes on any branch? And since GitHub is owned by Microsoft, they themselves would surely be able to regain ownership of the account. This seems like a non-story.
- MauranKilom 6y agoHow much code with malicious modifications has been pulled from these repos since then? There's no evidence this happened, but we can't just handwave it away with "we can undo changes".