4 ms·
Github audit log is unusable when trying to figure out what the "suspicious activity" is. For the repo category only the actions which change something are logg
by NuMessiah 4y ago
Github audit log is unusable when trying to figure out what the "suspicious activity" is. For the repo category only the actions which change something are logged. At least for the enterprise plan I would like to see the audit log more like the AWS CloudTrail. Just log all the API calls.
- ethbr0 4y agoAnd maybe highlight some? Github's internal systems already triggered on something, so why not (at least generally, to preserve method) indicate that to a user?
- NuMessiah 4y agoYup! Corp comm has failed here. Not issuing any additional statement and not communication with the (paying) customers about the (for customers potentially damaging) actions taken. This just erodes the corp image and the customers trust.
- whaleofatw2022 4y agoDevils Advocate: depending on level of access an attacker has, that info could be used to more carefully hide surreptitious actions.
- NuMessiah 4y agoThis would be plain security by obscurity which is the worst kind of security.
- ilyt 4y agoI hate that trend in modern services. They just decide something's wrong with your account but don't tell user what, or why it was decided.