13 ms·
Tencent WeChat is now a GitHub secret scanning partner
- okokwhatever 4y agoIs this a joke? I'm not laughing.
- Arnt 4y agoNo joke. «GitHub will forward access tokens found in public repositories to Tencent WeChat, who will notify affected users.» In other words, Tencent now has access to all of your public repositories. Also, Github now has code recognise Tencent access tokens.
- _jplc 4y ago> We have partnered with Tencent WeChat to scan for *THEIR* tokens
- rafael09ed 4y agoNo one owns random strings. They can claim whatever they want to be "their" tokens
- blitzar 4y agoNot your random string not your coins. Not your random string not your monkey picture.
- Arnt 4y agoTencent isn't claiming ownership of these strings, it's claiming that strings with a particular format have special meaning wrt. Tencent's APIs. It has told Github about that format. This is fundamentally similar to how UPS, DHL etc. document how to recognise their tracking numbers. "Their" and genitive in general doesn't necessarily mean ownership. It's often used for various sorts of connection. For example, "my address" doesn't claim ownership of either the street or the house, "my age", "my wife", all connected to me somehow but not owned by me.
- andrewaylett 4y agoTencent already had access to all your public repositories? They're public.
- blitzar 4y agoThats one thing, but its not like they have access to my public instagram photos, tweets or anything like that (/s?)
- jkaplowitz 4y ago> In other words, Tencent now has access to all of your public repositories. They already did. That's what public means. This is just an optimization to make it harder for WeChat access tokens to be inadvertently compromised without getting noticed. If you're worried about the Chinese government having inappropriate influence over or access to various things outside China, that's in general a valid concern indeed, but facilitating credential scanning in public repositories really doesn't seem worrying.
- andrewaylett 4y agoThis is part of https://docs.github.com/en/developers/overview/secret-scanning-partner-program https://docs.github.com/en/developers/overview/secret-scanni... It lets WeChat revoke tokens that GitHub finds in public repositories.
- mmaunder 4y agoIt lets WeChat see tokens that GitHub forwards to them. What they do with it is up to them, but the intent is that they mitigate the issue. “GitHub will forward access tokens found in public repositories to Tencent WeChat, who will notify affected users.”
- vxNsr 4y agoWhy did you edit the full quote? Here’s what I just copied from the blog post without modification: > We have partnered with Tencent WeChat to scan for their tokens and help secure our mutual users on all public repositories and private repositories with GitHub Advanced Security. It’s not just public repos, it’s private repos too.
- somehnguy 4y agoA comment above says that the for private repos only the repo owner will be notified vs sending the secret to the partner for public repos
- angry_octet 4y agoThat is insane. They just leak data from your private repos to a hostile foreign govt agency. Unbelievable. Edit: apparently they notify you for private repos, not Tencent. Still not thrilled.
- nomercy400 4y agoWait, what? So any string (which Github deems an access token) is forwarded to Tencent? Or will Tencent share all their current access tokens with github?
- AlbertVAustin 4y agoAny string that matches access token regexp provided by Tencent (see https://docs.github.com/en/developers/overview/secret-scanning-partner-program https://docs.github.com/en/developers/overview/secret-scanni...).
- plugin-baby 4y ago.* ;-)
- Pathogen-David 4y agoFor public repositories only though. For private repos it's optional, and when enabled the repo admins get an alert to handle it themselves without it going to the vendor.
- ilyt 4y agoSo it is just one bad regexp away from sending them other companies secrets
- mukesh610 4y agoI don't see what your comment is trying to point out. The same could be said for all the other Secret Scanning partners GitHub has, like AWS and so on. That being said, it's impossible that a "bad regexp" is gonna make its way to the GitHub codebase.
- kredd 4y agoYou can already do the former by using GitHub Events API. This simply helps with the accidental leak of tokens into the public, so Tencent / Repo owner can revoke it before it gets abused. https://docs.github.com/en/rest/activity/events?apiVersion=2022-11-28 https://docs.github.com/en/rest/activity/events?apiVersion=2...
- galuggus 4y agoIsn't this information already public?
- pixl97 4y agoWhich information? Your wechat tokens, no that should never be public, hence why this feature exist? That github reports that you leaked your wechat tokens, it was announced just recently, hence the post. That github is giving wechat your secrets, not that is not what this is about although the article title would make you think that.
- hunter2_ 4y agoGitHub is indeed giving WeChat our information, but only when it looks just like WeChat secrets, and only once it's already publicly leaked (any leaked via private repo instead goes to the repo admin). So technically the answer to GP is 'yes'.
- b4je7d7wb 4y agoI dont think you can claim an API key is your information. It is quite by definition information created by WeChat and Github is sharing only that with them a few minutes before it shares it with bad actors.
- hunter2_ 4y agoIt's not necessarily created by WeChat. It just needs to follow the same pattern as a key generated by WeChat (thus all the .* regex jokes here). It could very well be anyone's information, but information about to be public anyway (making "yes" the answer to the question "Isn't this information already public?").
- 255 4y agoOptics of this article could be improved. However, this is already a well established and useful thing. When you publish your AWS (for example) secrets to your public repo, it will scan it and stop it leaking before damage can be done. This is just the same for another service.
- civopsec 4y agoWhy could the optics be improved?
- nottorp 4y agoBrilliant title for the article. Even though I'm a paid github customer, I had no idea they had a program called "secret scanning" and that it's actually beneficial. So I obviously assumed they're letting China scan my private repos. They really need to work on wording.
- jasode 4y ago>, I had no idea they had a program called "secret scanning" and that it's actually beneficial. Fyi... this feature was also previously mentioned in the news for public repos: https://techcrunch.com/2022/12/15/github-brings-free-secret-scanning-to-all-repos/ https://techcrunch.com/2022/12/15/github-brings-free-secret-... >So I obviously assumed they're letting China scan my private repos. To clarify, it's Microsoft/Github doing the scanning of private repos on behalf of the partners. They're just forwarding the tokens that match the partners' regexp.
- nottorp 4y agoYeah I read the article and the comments on HN so I know what it's about now. I still think they (not HN) should change the title to include what secret scanning means. Edit: how about dropping the corporatese and title it "github will now scan public repos for secret WeChat tokens"?
- justaka 4y agoThis is 100x better than the original!
- pixl97 4y agoYea, but you don't get panic clickthru with this message.
- More-nitors 4y agohmm it's a pity github blog didn't have any advertisement...
- Traubenfuchs 4y agoWhy is everyone upset? This is a good thing. Where are you seeing a privacy or security risk?
- pontilanda 4y agoIt’s a combination of missing hyphens (it should be “secret-scanning partners” to avoid adjective ambiguity) and people’s inability to open links and read anything past the title. Sprinkle a bit of Sinophobia and we’re golden.
- jhugo 4y agoTencent provides a list of regexps, and anything matching those regexps is passed to them. As far as I can tell, we don't get to know what those regexps are (and presumably they can be changed at Tencent's whim). Can you not see the issue?
- pontilanda 4y agoI cannot see the issue because the regex are pre-approved by GitHub. And even then, the service will only return the string, not who wrote it. Unless GitHub approves /Jonh Doe said:.*/ there is no issue whatsoever.
- jhugo 4y agoI guess I just have a lot less faith in the ability of companies to design perfect processes, and the ability of humans to perfectly carry them out, than you do.
- MonkeyClub 4y ago> I cannot see the issue because the regex are pre-approved by GitHub. GitHub is a private company with one dual obligation, to prolong its existence and keep increasing its profit margin. It is not any sort of arbiter for morality - morality being an externality to its central obligation - so it cannot be relief upon to “do the right thing”. So it is not in any position of authority that would enable it to “approve”, in the moral sense of the word. They can only “allow” for the regex to be ran and the results sent off. For example, the “right thing” for GH would be to increase profit, while for another entity might instead be to uphold its users’ privacy. (You may think that it’s only for public repos, so they’re already made public, but isn’t GH here facilitating an aggressive collection and summation of information, that would otherwise be much more difficult and error-prone?) The power of approval would rather come from an elected entity that would also determine who may request that such searches are executed, and which reasons would be valid. Otherwise, we get a William Gibson-esque megacorp cyberspace future with clear but corporate Orwellian overtones. Isn’t this obvious? (I’m not being snarky at all - I’m genuinely asking: isn’t this glaringly and terrifyingly obvious?)
- redleader55 4y agoIt would be nice of Github if they could publish a transparency repo with all the partners and all the regex along with this initiative. I see a lot of people in this thread worried that "China gets their data" and this transparency repo could alleviate some of that.
- tomudding 4y agoThere is a list of partners [0], I thought I had seen regexes at some point but I can no longer find them. [0]: https://docs.github.com/en/enterprise-cloud@latest/code-security/secret-scanning/secret-scanning-patterns https://docs.github.com/en/enterprise-cloud@latest/code-secu...
- boredhedgehog 4y agoWhy do people worry about China so much? There is barely any cooperation between Chinese intelligence and the rest of the world. If I was forced to pick one government to share my secrets with, it would be the Chinese, because there's nothing they can do about it. My own government and its allies is infinitely more dangerous to me than such a foreign one.
- mylidlpony 4y ago> because there's nothing they can do about it Are you talking about the China that bought huge areas in ports around the world? The same one that has secret police stations as well?
- nicce 4y agoSo, basically... nothing? You should go into China to get a real threat. On the other hand, there is global cooperation with intelligence agencies of USA and many European countries.
- pell 4y agoChina spies on Uyghurs in other countries, puts pressure on them and has been known to run secret police stations as well. China spying on Uyghurs in Sweden: https://www.rferl.org/a/Sweden_Jails_Uyghur_Chinese_Man_For_Spying/1977995.html https://www.rferl.org/a/Sweden_Jails_Uyghur_Chinese_Man_For_... China controls dissidents abroad through relatives back home: https://www.reuters.com/article/us-china-uighurs-idUSKBN0UD1BE20151230 https://www.reuters.com/article/us-china-uighurs-idUSKBN0UD1... China's secret police stations in Europe: https://www.spiegel.de/international/world/beijing-s-long-arm-china-s-secret-police-stations-in-europe-a-d6732094-ca32-4c0a-8e6f-58b395b946aa https://www.spiegel.de/international/world/beijing-s-long-ar... >On the other hand, there is global cooperation with intelligence agencies of USA and many European countries. Two wrongs don't make a right.
- nintendo1889 4y agoThey should scan for Bitcoin seeds too.
- Alifatisk 4y agohttps://github.com/eth0izzle/shhgit https://github.com/eth0izzle/shhgit
- luc_ 4y agoThey had to have titled it like this on purpose. I almost spat out my tea.
- gbtw 4y agoWhat does a wechat token look like, as in can i scan my repo to see if i do not leak anything unwanted to wechat? That said, could one also generate tokens and essentially DDOS the wechat org by having them inform their customers unnecessarily?
- munhitsu 4y agoJust make sure your secret doesn’t look like a WeChat secret
- lopkeny12ko 4y agoJust a reminder that Git is a decentralized protocol and Github is merely a (poor) implementation of it. Microsoft-Github have been increasingly introducing antifeatures, just one of which is sending repository contents to China automatically. For the last few years I've been running Git off my own servers with a cgit [0] frontend, and couldn't be happier. [0] https://git.zx2c4.com/cgit/about/ https://git.zx2c4.com/cgit/about/
- bswinnerton 4y agoRepository contents aren’t “sent” to China, companies like Tencent specify the shape of tokens to GitHub and GitHub does the scanning and then notifies Tencent to revoke the token if one is found.
- Alifatisk 4y agoHow is Githun a poor implementation of Git? Because it’s centralized?
- boomboomsubban 4y agoI believe it's roughly a quote from Linus Torvalds, the creator of git who has many issues with githubs decisions. See https://www.wired.com/2012/05/torvalds-github/ https://www.wired.com/2012/05/torvalds-github/ for a start, his opinion hasn't improved over the decade.
- rightbyte 4y agoHis oppositions seems to be nitpicking and he says it is fine for hosting?
- boomboomsubban 4y agoThe issues with the way they handle commits is a fairly fundamental disagreement, one that ensures he will never use github for development without it being changed.
- whoevercares 4y agoIt’s absolutely shocking to observe how hostile HN is to Chinese affairs. While in real life many must have collaborated A LOT with Chinese engineers & managers. Are you worry about bias bleeding into real life? I’m indeed worried as a Chinese immigrant working in tech
- masterof0 4y agoIs simply xenophobia, as it is with Russians or Russia-related issues. This is how the internet works in the Western world. When you point it out, they simply downvote you; if your account is new, they will claim it is a bot or that you are an agent/collaborator, and so on.
- b4je7d7wb 4y agoIt's mostly because of the government. Don't take it personally. I have quite strong opinions of China, but I don't let it influence my relationships with my chinese collegues.
- AntiRemoteWork 4y ago
- trompetenaccoun 4y agoTo everyone portraying this as harmless and as Wechat just looking for security breaches: Tencent itself is the security breach. Not only can Chinese ppl not sign up without providing a phone number, just to get a SIM card they now take your government ID, a picture of your face and a fingerprint! Xi is making absolutely sure that every single internet user is IDed and has their conversations tracked on apps like Wechat. Whatsapp, Signal & co are banned. These "leaked" secrets GitHub forwards might be dissidents getting access without being tracked. It might not be a WeChat secret at all who knows? They're not a trustworthy partner, nothing should be shared with this company. And to the folks saying it's public information and they already have it: That makes no sense, then they don't need GitHubs help. Obviously GitHub is supporting their scanning efforts here.
- anaganisk 4y agoWait a second, the requirement of a government to get a sim card is kinda standard practice in multiple countries. Also, when it comes to privacy, US based companies must be last ones to talk, like as if China is the only bad guy who infringes upon peoples right to privacy. China is dangerous, but it's not the only dangerous thing in the room. Also, your comment doesn't make sense. If you are committing your public credentials while diseenting against the government, you are doing it wrong. Also, any publicly committed credentials are like literally tracked by thousands of both within minutes. Its not like if China really want to scan them, they can't do it without Github telling them they found something.
- trompetenaccoun 4y agoYou may have misunderstood. There is no way to anonymously access Weixin from China unless you have hacked credentials. You need a phone number. Note that local Weixin and foreign Wechat are not the same. Last time my Mainland friend bought a SIM card the vendor had a government app on his phone, snapped a picture of my friend's face, scanned the ID (身份证) and had him take a fingerprint with a reader he also had connected to his phone. All this data gets uploaded directly to the Chinese government. There isn't a country in the world which does this. But the details are also not the main point, it's how extremely restricted and controlled simple access to information or forums of free expression is for people in China. Tencent has party officials working within the company. This isn't a regular business as Westerners might imagine it, it's an extended part of the CCP just like any other large corporation under Xi. Again, people are saying it's no big deal but why would GitHub help them at all? It's not a good cause.
- gpjanik 4y agoThis is simultaneously an epic clickbait and a very accurate represenatation of reality that is very boring and not shocking at all. Congrats to whoever wrote the line.
- dang 4y agoLame corporate partnership announcements aren't on topic for HN, and the wording here looks to have been a boilerplate malfunction: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=now%20a%20github%20secret%20scanning%20partner&sort=byDate&type=story https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que.... Poor functionary creates political incident with humble template...sounds like a Gogol short story. "but it worked great for redirect.pizza!" Btw I assume this recent thread was about the same feature: Secret scanning is now available for free on public repositories - https://news.ycombinator.com/item?id=34007637 https://news.ycombinator.com/item?id=34007637 - Dec 2022 (70 comments)
- olksdhdkdbdj 4y ago1. If their regex matches my company token, will it be send to them? 2. Can Wechat update the token regex to collect tokens from competitor company? 3. Can Tencent collect information about applications that use wechat?