3 ms·
Sounds like the attackers did not have write access. From the original blog post: > The account did not have permissions to modify any code or engineering syst
by thatsamonad 6y ago
Sounds like the attackers did not have write access. From the original blog post:
> The account did not have permissions to modify any code or engineering systems and our investigation further confirmed no changes were made. These accounts were investigated and remediated.
I would also hope that direct commits don’t go immediately to a production system without some sort of review. At my workplace we have branch protections for all “main” branches that would result in a deployment. At least one other person has to review changes and all of our automated checks have to pass before anything can even get close to running through a deployment pipeline.
- codezero 6y agoWhew, that's good to hear. I assume anyone trying to inject malicious code is going to try to do so in a way that doesn't go through normal code review channels.
- thatsamonad 6y agoTrue. However, hopefully that’s being mitigated through things like not allowing authors to review their own commits, not using the same accounts to push code changes and do deployments (i.e. having a read-only account for deployments), etc. However, if it were an admin account that were breached that would definitely make it possible to circumvent any number of protections in place.