4 ms·
"or presenting an obituary then waiting for 21 days" this part feels a little loose to me. Say you have a falling out with someone and forget to remove them as
by dreadlordbone 5y ago
"or presenting an obituary then waiting for 21 days" this part feels a little loose to me. Say you have a falling out with someone and forget to remove them as a successor, this could be socially engineered.
- NobodyNada 5y agoPresumably, this is why an obituary has a 21-day countdown rather than a 7-day countdown like a death certificate. I would imagine, but I do not know, that the successee would recieve an email allowing them to cancel the transfer within this window.
- killingtime74 5y agoMany what-ifs in your statement. you add them, you fall out, you forget to remove them, they socially engineer an obituary, you some how don’t respond in 21 days?
- dreadlordbone 5y agoFrom personal experience people tend to forget things. I think we'll see a front page hackernews article about a "stolen" repo with this method at some point in the future.
- NoSorryCannot 5y agoIt will probably happen but if that were enough to make for a bad idea, there wouldn't be any good ones.
- woodruffw 5y agoAt least in the US, the legal repercussions for faking someone else's death should hopefully deter anyone who would go this particular route in order to take over a repository. Other countries may present a challenge. I'm a big fan of this feature, but I do think GitHub would do well to institute a "real name"/identity policy for successors. That won't be infallible either, but it's another hurdle for a would-be fraudster to climb over.
- richardwhiuk 5y agoFrom https://docs.github.com/en/github/site-policy/github-deceased-user-policy https://docs.github.com/en/github/site-policy/github-decease... > Once we have received your request, we may follow up with a request for additional information, such as a copy of your photo identification, copy of the death certificate, and documentation confirming you are authorized to act in relation to the deceased user’s account, to verify that we are properly authorized to process your request.
- coderintherye 5y agoAgreed, or in what will be a more likely case, someone who you have designated as a successor has their account compromised. Then, the attacker escalates that into an attack on your repositories. The 21-day countdown would still be a deterrent, but as an attacker it would be worthwhile to try this on every account you have successor access to and see if perhaps someone doesn't check their email.
- prepend 5y agoObituaries seem hard to link to a specific individual. Step 1, find a repo managed by someone with a common name (eg, Jane Smith). Step 2 wait for anyone in the world with that name to die. Step 3 wait for them to go on a long break and present the obit to GitHub for access.
- johannes1234321 5y agoThat misses the step 1.5: Get the user to mark you as their successor. With moa tpeople that isn't easy.
- prepend 5y agoGood point, I missed that pet and I think prevents the whole scenario I wrote. So it seems safe given that people aren’t likely to appoint randos their successor.