32 ms·
Hi folks, I'm the CEO of GitHub. GitHub hasn't been hacked. We accidentally shipped an un-stripped/obfuscated tarball of our GitHub Enterprise Server source co
by natfriedman 6y ago
Hi folks, I'm the CEO of GitHub.
GitHub hasn't been hacked. We accidentally shipped an un-stripped/obfuscated tarball of our GitHub Enterprise Server source code to some customers a couple of months ago. It shares code with github.com. As others have pointed out, much of GitHub is written in Ruby.
Git makes it trivial to impersonate unsigned commits, so we recommend people sign their commits and look for the 'verified' label on GitHub to ensure that things are as they appear to be.
As for repo impersonation – stay tuned, we are going to make it much more obvious when you're viewing an orphaned commit.
In summary: everything is fine, situation normal, the lark is on the wing, the snail is on the thorn, and all's right with the world.
- czbond 6y ago<had a comment, it was snarky, bad taste, removing. even if accurate>
- tomglynch 6y agoThanks for the response here Nat. Upfront and to the point. Now that most of the code is out there, will you consider making the whole project Open Source?
- chenpengcheng 6y agogreat question!
- metiscus 6y agoAnswered in part here quoted in case of edits. https://news.ycombinator.com/item?id=24995266 https://news.ycombinator.com/item?id=24995266 "It's not open source because the open source "community" is a liability and you want them far away from you at all times. I'm not trying to be mean or sarcastic or anything. Just look at how maintainers are treated for a week and you'll see exactly what I mean."
- exabrial 6y agoSituation normal? Are you guys planning on removing other random projects due to invalid/Bogus DMCA takedowns? I really wish you guys would stand up to trolls.
- natfriedman 6y agoSuggest you read about how the DMCA works: https://docs.github.com/en/free-pro-team@latest/github/site-policy/dmca-takedown-policy https://docs.github.com/en/free-pro-team@latest/github/site-...
- dannyw 6y agoFirst, thank you for coming here and responding. Some people think RIAA’s DMCA notice is not legally valid, arguing RIAA is not the copyright holder and there is no infringing material. DMCA takedowns are for taking down works you own the copyright to; not for enforcing any arbitrary aspect of legislation. It’s my understanding that service providers do not need to comply with illegal requests. For example, if I DMCA’d <an oil producer>’s repository on accused violations of environmental protection acts, I don’t think it would be taken down, would it? If GitHub was an independent company advocating for open source; would it have acted any different? Note: Microsoft is a member of the RIAA. Apple made waves and built lots of favour for resisting the FBI and challenging quasi-legal processes. They took risks and demonstrated their principles (Suing the FBI over a terrorist’s iPhone is unlikely to be the first recommendation from their legal counsel). This smells like a qausi-legal process, and it would look great for GitHub/Microsoft if you do.
- chews 6y ago"It’s my understand(sp) that service providers do not need to comply with illegal requests." winner winner chicken dinner.
- jackhughman 6y agoBut a takedown is required in the course of due process until some leaning can be established as to legality and validity of the request. It's really, really, really stupid, because it presumes guilt before innocence, standing in opposition to most general legal principles. If anything, Microsoft via Github would do well to assert itself by not conforming, forcing the court to examine the DMCA's legality and process.
- ibraheemdev 6y agoThe readme clearly states: > This is GitHub.com and GitHub Enterprise It also contains linting config, ci workflows, dockerfiles, and other build related files that you probably wouldn't put in an "un-stripped/obfuscated tarball of our GitHub Enterprise Server source code"
- natfriedman 6y agoThe key part of the word "un-stripped" that you may have missed is "un". :-)
- ibraheemdev 6y agoThe readme of GitHub ee server states that it is GitHub.com?
- czbond 6y agoIf so, they need their security team on that. They need to protect their Gemfile bc it would show attack vectors.
- czbond 6y agoBeing downvoted bc of why? I literally said THE MOST obvious purposefully and left out the 20+ other things that a good security researcher would hunt down in this - each to allow compromise of the company, build process, downstream or someone using enterprise. I am not advocating it - I am making people aware that is what leaks mean. [I randomly picked 20. Because it's usually a lot of options when you have source code access]
- TheDong 6y agoI'll try to explain why. Your comment amounts to "Github's security team should be making sure the dependencies in their Gemfile don't have vulnerabilities". Which is an obvious and pointless statement, yes, of course github's security team should make sure github's code doesn't have vulnerabilities. That's the most important duty of their job. The fact that the Gemfile has been leaked changes nothing about what the security team should be doing. Your comment doesn't really contribute to discussion because it's not presenting novel information, and it's misleading because, per the reasons above, their security team's priorities goals/responsibilities/behaviors/etc aren't really impacted by this, and your comment sorta implies otherwise.
- github_drop_ice 6y agoNo Nat, all is NOT right in the world. Right now children are being separated from parents at the border. The "uterus collector" is performing forced hysterectomies on detained women. All of this is being done by ICE, a government organization you have defended and your company supports & profits from: https://github.blog/2019-10-09-github-and-us-government-developers/ https://github.blog/2019-10-09-github-and-us-government-deve... So please check yourself before swooping in to make ridiculous statements about the state of the world. The world is NOT right and GitHub is NOT helping.
- sneak 6y agohttps://galaxypress.com/inspired-philip-k-dick/ https://galaxypress.com/inspired-philip-k-dick/
- chrisfinazzo 6y agoSome people don't sign their commits before pushing to a branch? Insane. (Reading docs...) The desktop client explicitly does not support this, why is that?
- czbond 6y agoTesla did not (a few years back if I recall). If I had to swing, I'd say 98% of companies do not. Git does not make it trivial to impersonate commits. http://www.linuxjournal.com/content/signing-git-commits http://www.linuxjournal.com/content/signing-git-commits
- jfrunyon 6y agoWhat? Git absolutely makes it trivial to impersonate commits. All you have to do is change some Git config settings. Or, export your commit into a patch/email file (git format-patch), modify it, and then import it (git am). Or, set some environment variables (GIT_COMMITTER_NAME and GIT_COMMITTER_EMAIL). etc. As you yourself mentioned, very, very, very few projects/people sign their commits. Even fewer actually verify them.
- czbond 6y agoSign with GPG for the hash, as linked. The methods you mentioned do allow malicious modification. Signing the commit with a public key makes it a lot more difficult. In the same vein, one can spoof email - but DKIM, SPF, DMARC together as controls make it much more difficult.
- jfrunyon 6y agoAgain, as you yourself mentioned, very, very, very few projects/people sign their commits. Even fewer actually verify them. That has nothing to do with how easy Git makes it to impersonate commits. In fact, whether you sign or not, you can still easily impersonate commits with any Git tool unless the person on the other end actively verifies the signature. (Which GitHub makes much easier than git, since they also maintain & automatically check a verified mapping of email -> GPG key, instead of you having to somehow get the key and then make sure it's the right one and then explicitly tell git to verify the signature) I am well aware that you can sign commits with Git. I do, personally and professionally, and my coworkers and I are required to, by policy that I wrote. That has absolutely no bearing on the topic at hand even tangentially.
- surround 6y agoWhy is GitHub not open source?
- tylersmith 6y agoIt's not in line with their business model of running a propriety SaaS.
- dclowd9901 6y agoThere are ways to monetize open source. GitHub could make the repository/PR code open source and host the repo management/hooks/actions/etc code for enterprise.
- ehnto 6y agoGithub is a company not a community project though, they don't gain anything by going open source, it makes no sense to do so. There are hidden costs to going open source as well as expected ones. Could you imagine the number of PRs, issues and discussions over trivial shit the GitHub userbase would create against an open GH repo? Nightmare. Not to mention code cleanliness expectations and buildability expectations and so on. Of course they "could do this" or "do it that way," but the fact that they don't should tell you their priorities lie elsewhere, and that's fine. Closed source isn't evil and we have other open source git hosting platforms.
- SheinhardtWigCo 6y agoTheir nearest competitor is open core and very far behind. Sure, there are ways to monetize - fewer and more difficult ways.
- sofixa 6y agoFar behind in terms of popular usage maybe, but IMHO it's far more advanced features-wise and it's probably more popular in enterprises.
- deleted 6y ago[deleted]
- bootcampwhere 6y agoCool, fuck you.
- steve76 6y agoHi folks, This is what your bailout money bought. Hi folks, Your job interview is now an Olympic event. Our jobs will always be protected. Hi folks, Be sure to live in a trailer if you move here. It's the only place you can afford. Hi folks, Just step over the passed out junkie in the street. It's your fault anyways. In summary: something something something cute, you deal with it I'm rich In all seriousness, if I do something like this, I don't eat!
- hashtagmarkup 6y agoHi CEO of GitHub. You "hacked" yourself. A majority of commits are not "verified", and a majority of users don't know to "look for" the verified label. Why didn't you make signing mandatory if you recommend it? As for repercussions to your mismanagement, I will certainly stay tuned. In summary: you're fucked.
- jfrunyon 6y agoBecause the vast majority of their users don't want (or need, really) to bother with setting up GPG, making a key, adding their key to their account, etc. Also, if users don't know the very basics of how Git works, they probably shouldn't be using it, and certainly not trusting it.
- hashtagmarkup 6y agoYou're right... the vast majority of users should certainly no longer trust github.
- jfrunyon 6y agoPlease let me know when you figure out how your complaint is in any way specific to GitHub, as opposed to git in general.
- hashtagmarkup 6y agoMy personal git isn't used by millions of people, as opposed to github.com that is used by millions of people in general.
- robertlagrant 6y agoYour personal git isn't relevant to the question.
- hashtagmarkup 6y ago
- neilparikh 6y agoI understand how this user made themself look like you, but I don't understand how they were able to push a commit to the github/dmca repo. Wouldn't that require them to be a collaborator on the repo?
- speedgoose 6y agoThey made a fork of the dmca repository, and pushed the commit to their fork. But Github uses the same single Git repository for all forks, and they have an issue where you can access a branch/commit of a fork from the main repository if you know its hash. They should probably fix that at some point.
- neilparikh 6y ago> Github uses the same single Git repository for all forks Ah I see, thanks for the explanation. I didn't know this was the case. I thought each fork would have its own `.git` folder. Seems like this approach could allow forkers to mess with the original repo, but maybe Git is designed in a way that this is mostly safe.
- eternalban 6y ago> all's right with the world. No, it is not. https://github.com/youtube-dl2/youtube-dl https://github.com/youtube-dl2/youtube-dl
- im3w1l 6y ago> we recommend people sign their commits and look for the 'verified' label on GitHub to ensure that things are as they appear to be. One issue is that you are loading profile images and creating links based on unverified emails (if I click the little picture next to the commit message I get to the impersonated profile). I mean I get that a proper solution might introduce unacceptable friction, but you can't really blame users for misunderstandings in the current state either.
- DarkWiiPlayer 6y agoMaybe, instead of just not having a green "verified" indicator, add a red "unverified" indicator for users that do have a PGP key added? Maybe add a checkbox in your profile like "Specifically mark unsigned commits" or even "don't associate unsigned commits to my account" as well.
- OJFord 6y agoOr: > (!) This user usually signs their commits, but this commit is not signed. [Learn more] Is what I've been surprised there isn't something like in the past.
- easton 6y agoThey have a grey unverified thing that pops up if there was an error when using GPG to sign the commit, I wonder why it doesn’t show up the rest of the time when you don’t sign something at all.
- octoberfranklin 6y ago> In summary: everything is fine, situation normal, the lark is on the wing, the snail is on the thorn, and all's right with the world. Funds are safu?
- dancemethis 6y agoWell, Github not being Free Software in the first place already means "everything is fine" is false.
- LeonB 6y ago> the lark is on the wing, the snail is on the thorn, and all's right with the world bit of a Wodehousian twist there. appreciated.
- neop1x 6y ago> The year's at the spring > And day's at the morn; > Morning's at seven; > The hill-side's dew-pearled; > The lark's on the wing; > The snail's on the thorn; > God's in His heaven— > All's right with the world! Robert Browning, Pippa Passes (1901) A nice one. I didn't know it.
- m4rtink 6y agoReminds me of NGE. :)
- dmurray 6y agoIt's from a Browning poem that predates Wodehouse, though Bertie Wooster did occasionally quote or misquote it. https://www.goodreads.com/quotes/314320-the-year-s-at-the-spring-and-day-s-at-the-morn https://www.goodreads.com/quotes/314320-the-year-s-at-the-sp...
- LeonB 6y agoMy fave is when he (often) asks Jeeves to help him out with a line of poetry. Jeeves always knows.
- robertlagrant 6y ago> As others have pointed out, much of GitHub is written in Ruby. Security by oh yuck it's Ruby.
- shuringai 6y agoI can see your PR staff in my head, standing behind your monitor and saying: "now you have to write everything is in order, everything is normal, this is not a bug but a feature".
- danicgross 6y agoI don’t think quotes from Browning poems come from a PR staff. https://romantic-circles.org/editions/poets/texts/theyears.html https://romantic-circles.org/editions/poets/texts/theyears.h...
- Havoc 6y agoOr maybe experienced CEOs have been around long enough to learn a thing or two from the PR staff
- anticensor 6y agoWhy does GitHub add PRs into repository as new commits even before author adds a merge commit rather than doing a usual multi-remote non-FF merge when merge action gets triggered?
- laksdjfkasljdf 6y agogit downfall is the "smart" features that prevent people from understanding what git really is. Instead of making conflict messages clearer and easier to work with using local files, contributors keep thinking the users are too dumb and adding (and changing) merge resolution hacks. This boils up to github, as can be seen by teams who do not understand the very basic about git commits, and enable "squash commits by default" on their repos. With these teams, git commit history cease to be bit sized changes in a larger changeset, and become useless displays of the author interacting with the remote server while they upload small changes to tests to make the continuous builds get green.
- NormenNomen 6y ago> This boils up to github, as can be seen by teams who do not understand the very basic about git commits, and enable "squash commits by default" on their repos. If I ever work on a team that agrees on how to commit I'll eat my hat. This is absolutely nowhere in the private tech sector.
- sleepless 6y agoAre there plans to address "Setup gpg signing" for the desktop app? https://github.com/desktop/desktop/issues/78 https://github.com/desktop/desktop/issues/78
- WrtCdEvrydy 6y agoYou should issue a DMCA against this repo since it contains your intellectual property (https://web.archive.org/web/20201104050026if_/https://github.com/github/dmca/tree/565ece486c7c1652754d7b6d2b5ed9cb4097f9d5 https://web.archive.org/web/20201104050026if_/https://github...). Doesn't failure to do so mean you don't care about DMCA?
- ElijahLynn 6y agoAll is not right with the world. The GitHub code is still closed source. You need to open the source code of GitHub up Nat. Open it up. Do the right thing.
- kordlessagain 6y agoNat while you are here addressing this related issue, any thoughts on changing Github's handling of commits by users who later can't be tracked down to directly address removal or changes of various viral license schemes your platform supports and promotes for use?
- deleted 6y ago[deleted]
- fabianhjr 6y agoThat is a legal/copyright issue of each project; if you are concerned about that you should requiere a CAA/CLA though this is not legal advice and I am not a lawyer, consult with one for the specifics.
- kordlessagain 6y agoI won't be applying any type of Open Source license to any code I am writing but people should definitely consider getting each and every developer to agree to identifying themselves legally so they can be contacted in the case of license changes.
- usui 6y agoDid you just put pressure on archive.org to take down the link? The archive.org link is no longer working and it says "This URL has been excluded from the Wayback Machine." https://web.archive.org/web/20201104050026if_/https://github.com/github/dmca/tree/565ece486c7c1652754d7b6d2b5ed9cb4097f9d5 https://web.archive.org/web/20201104050026if_/https://github...
- paraknight 6y agoYou don't have to pressure them to remove a page. I remember that all you needed to do was add a line to your robots.txt to have a page excluded, and you can also just request to have a page excluded (that you own).
- usui 6y agoI know about that because i use robots.txt on my personal website to exclude, but how do you automatically exclude links that were already archived?
- lrvick 6y agoWait... so after years of multiple security researchers including me privately and publicly demoing this issue, it took us virally trolling you with it before you would finally acknowledge it is an issue and try to fix? Why does it always come to this. By the way the serious design flaw where GitHub forges signatures on merge commits I told you about when you joined as CEO... Still not fixed. The fact a commit can be shown as "verified" in the interface when I didn't sign it with my Yubikey is totally broken.
- deleted 6y ago[deleted]
- interestedTom 6y ago⢀⣠⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⠀⠀⠀⣠⣤⣶⣶ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⠀⠀⢰⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣧⣀⣀⣾⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⡏⠉⠛⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⣿ ⣿⣿⣿⣿⣿⣿⠀⠀⠀⠈⠛⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠛⠉⠁⠀⣿ ⣿⣿⣿⣿⣿⣿⣧⡀⠀⠀⠀⠀⠙⠿⠿⠿⠻⠿⠿⠟⠿⠛⠉⠀⠀⠀⠀⠀⣸⣿ ⣿⣿⣿⣿⣿⣿⣿⣷⣄⠀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⠏⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠠⣴⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⡟⠀⠀⢰⣹⡆⠀⠀⠀⠀⠀⠀⣭⣷⠀⠀⠀⠸⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⠃⠀⠀⠈⠉⠀⠀⠤⠄⠀⠀⠀⠉⠁⠀⠀⠀⠀⢿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⢾⣿⣷⠀⠀⠀⠀⡠⠤⢄⠀⠀⠀⠠⣿⣿⣷⠀⢸⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⡀⠉⠀⠀⠀⠀⠀⢄⠀⢀⠀⠀⠀⠀⠉⠉⠁⠀⠀⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣧⠀⠀⠀⠀⠀⠀⠀⠈⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢹⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⠃⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⣿⣿
- the5avage 6y ago> the lark is on the wing, the snail is on the thorn, and all's right with the world. Are you aware of the fact that it is irony in the original work? https://en.wikipedia.org/wiki/Pippa_Passes https://en.wikipedia.org/wiki/Pippa_Passes Have you read the newspaper in the last months? I suspect irony on your side and if it's true you are kind of funny...
- NormenNomen 6y ago> GitHub hasn't been hacked. Interesting way to position a potential source code leak.... one would think this would improve the security of the code.
- vkaku 6y ago@natfriedman - you guys need to start allowing comments in Git commits, it will help enrich Git commits with any other tracking information available. Hopefully it's helpful.