3 ms·
You can mitigate that pretty easily by checking whether recent commits from this person are linked to that GitHub account.
by Denvercoder9 6y ago
You can mitigate that pretty easily by checking whether recent commits from this person are linked to that GitHub account.
- Sebb767 6y agoIf the person had a GitHub account before, it could be newly created by the attacker. Or they could have had different e-mails for php.net and GitHub, i.e. something like php@xy.com and github@xy.com. In a perfect world, this would be fine, yes. But when adding work on top of a probably already very stressful workday, the likelihood of this creating additional problems is there.
- Denvercoder9 6y ago> If the person had a GitHub account before, it could be newly created by the attacker Doesn't GitHub require e-mail validation before it associates commits with that e-mail address? > Or they could have had different e-mails for php.net and GitHub, i.e. something like php@xy.com and github@xy.com. Then require them to add their php.net mail address to their GitHub account. > the likelihood of this creating additional problems is there. That I agree with.
- 1f60c 6y ago> Doesn't GitHub require e-mail validation before it associates commits with that e-mail address? IIRC, nope! You can say your email is Linus Torvalds’, and GitHub will not question it (and even link to his GitHub profile in the commit history!)
- Denvercoder9 6y ago> You can say your email is Linus Torvalds’, and GitHub will not question it (and even link to his GitHub profile in the commit history!) That's the other way around though -- claiming the victims GitHub profile made a commit controlled by the attacker, instead of claiming the attackers GitHub profile made a commit controlled by the victim.
- Sebb767 6y agoNo, you could claim the commits made by the victim this way. The steps would be: 1. Look for a contributor without GitHub account (i.e. xy@gmail.com ) 2. Add xy@gmail.com to your GitHub account/create one with that address [0] 2.1 The commits made by the victim will now link to your account on GitHub 3. Send a mail to Nikita with your faked GitHub-profile None of this will survive a thorough check, but under pressure this will easily pass a surface-level check. [0] I think you need to confirm your primary E-Mail, but not secondary ones. Alternatively, you could look for commits made from an now deleted mail account.
- jwilk 6y agoYup, AFAICS GitHub associates secondary addresses with your account without verification. Although the victim would be notified that their address was added to a rogue account, the notification mail says: "If this wasn’t you, please ignore this email." Ugh.
- deleted 6y ago[deleted]
- JimDabell 6y ago> recent commits from this person Given that the attacker managed to push unauthorised commits, I don’t see how recent commits can be considered a reliable method of authentication.
- Denvercoder9 6y agoYou need to audit the commits anyway, and presumably after the audit they can be trusted again.