6 ms·
> On March 2, 2021, we received a report via our support team from a user who, while using GitHub.com logged in as their own user, was suddenly authenticated as
by skytreader 6y ago
> On March 2, 2021, we received a report via our support team from a user who, while using GitHub.com logged in as their own user, was suddenly authenticated as another user.
Sobering thought for me is how probable it is that a similar issue might be present in other platforms. The title calls it "rare" but given (a) the number of complex-enough web/app platforms in use today, (b) just the endless number of ways/infra permutations for "doing x", and (c) the size of a typical company's codebase and dependencies, could it be a more common occurrence than we think?
Total anecdote, up for you to believe: Back in April 2016, one of my then-housemates bought a brand-new Macbook Air. A week into his ownership, he exclaims surprise that he is logged-in to another Facebook account, someone we are totally not acquainted with. I borrow his MBA and try to investigate but, alas, I lack expertise for it. The only relevant thing I can eke out is that they both went to the same event a week or so ago and probably shared a Wifi AP, where a "leak" could've happened. Or maybe a hash collision in FB's side?
I would've reported it to FB but then I don't have enough details; with the two conjectures I have, I'm basically holding water with a sieve. But now the thought that someone I totally don't know might end up logged-in in my FB account is a possibility that bothers me. And I have no idea how to prevent it other than minimizing what could be compromised (and no, "Get off FB!" just isn't in the cards, I'm sorry).
Kudos for Github for investigating and fixing this issue. Another thought that occurred to me while writing this is how many users of other platforms might be filing issues like this but can't provide enough detail and so their reports are eventually marked as "Could Not Reproduce". Not exactly leaky sessions but just general security mishaps that they would struggle to describe to support.
- deleted 6y ago[deleted]
- thraway123412 6y agoAlso on GOG: https://www.gog.com/forum/general/warning_massive_security_risk_on_gog/page1 https://www.gog.com/forum/general/warning_massive_security_r... > Hello everyone! This is forum regular fronzelneekburm, posting from the account of some poor Chinese guy that gog randomly logged me into. I'll explain the situation in further detail in another post from my actual account once I logged out of this one.
- exdsq 6y agoDon’t sell yourself short, I’m sure you’re more than experienced to get your own MBA!
- ficklepickle 6y agoIf it were a hash collision, I would think the odds of it involving two users geographically close to each other would be quite small. That's a weird one, thanks for sharing it!
- tcgv 6y agoNot if you consider that FB servers are somewhat geographically partitioned to optmize response times
- wholien 6y agoThe earlier report[1] says: > The underlying bug existed on GitHub.com for a cumulative period of less than two weeks at various times between February 8, 2021 and March 5, 2021. Once the root cause was identified and a fix developed, we immediately patched GitHub.com on March 5. A second patch was deployed on March 8 to implement additional measures to further harden our application from this type of bug. There is no indication that other GitHub.com properties or products were affected by this issue, including GitHub Enterprise Server. We believe that this session misrouting occurred in fewer than 0.001% of authenticated sessions on GitHub.com. If we use the 0.001% figure and assume all 56 million of their users are authenticated, then this occurred with 560 sessions at most. You are right in that when something only happens to a minuscule % of users is hard to investigate and repro. But at the same time something as critical as "I logged in and was authenticated as another user" should probably be immediately escalated to the highest levels within your company. 1: https://github.blog/2021-03-08-github-security-update-a-bug-related-to-handling-of-authenticated-sessions/ https://github.blog/2021-03-08-github-security-update-a-bug-...
- abdupo 6y agoSo I am one of the users who reported this. I quickly filed a support ticket but then I also searched my network to find someone on GH's security team to email. I'm not sure if support or the security person I emailed escalated it first.
- nodesocket 6y agoDid you get any bounty?
- codethief 6y agoI recently reported a phishing site to GitHub which looked exactly like GitHub.com and GitHub responded within a day. So maybe your escalation wouldn't even have been necessary. :)
- deckard1 6y ago> The title calls it "rare" I believe they are referring to the rarity of hitting this bug during the period of time it was broken, and not the rarity of the bug in general. People were speculating on this here: https://news.ycombinator.com/item?id=26395138 https://news.ycombinator.com/item?id=26395138, and I even left a comment about this type of bug, but on Node. This category of bug, where session data leaks across requests, is actually incredibly common.
- BurningFrog 6y ago> one of my then-housemates bought a brand-new Macbook Air My most fun theories are 1. Somewhere in the supply chain, someone logged in to their FB account on this machine. 2. During the first week he owned it, someone logged in to their FB account on this machine. 3. You ex housemate lied about this. Crazy people are rare, but MUCH more common likely bugs that could cause this.
- sellyme 6y ago> The only relevant thing I can eke out is that they both went to the same event a week or so ago and probably shared a Wifi AP, where a "leak" could've happened. Or maybe a hash collision in FB's side? Given two users in extremely close geographic proximity, the chances of them having manually logged in on the device themselves with your housemate either forgetting or not knowing are much much higher than the chances of an authentication exploit in the world's most popular site that would have gone undiscovered for a subsequent five years at this point. Probably somewhere between the two (but closer to the "they just logged in on that computer" side of things) is the chance of the LAN being some eldritch abomination that just occasionally serves responses to the wrong local IPs, but that's not something any online service needs to care about.
- mschuster91 6y ago> is the chance of the LAN being some eldritch abomination that just occasionally serves responses to the wrong local IPs This could have worked in ye olde pre HTTP days, but with HTTPS this cannot reasonably have happened.
- vanviegen 6y agoThat sounds like the event was forcing the use of an HTTP proxy server with over-eager caching. But in 2016, that would be a bit anachronistic..
- robindebaets 6y agoI once had the exact same thing happen on PayPal. I logged into my account, but was greeted by the information of another user. I immediately logged out. I never reported it and it it never happened again.