5 ms·
I fail to see what GitHub did wrong here. They were attacked, they suspended the account doing the hacking, and they fixed the problem. Then, they blogged abo
by ericflo 15y ago
I fail to see what GitHub did wrong here. They were attacked, they suspended the account doing the hacking, and they fixed the problem. Then, they blogged about it, explaining in detail what happened. Apparently they weren't quite reverent enough for the person who wrote this article.
- deleted 15y ago[deleted]
- vidarh 15y agoI lost a tremendous amount of respect for Github when I heard they'd suspended his account. I have more of an issue with the Rails team for not accepting that this "feature" is a massive bug that they should've changed ages ago, though.
- ericflo 15y agoWhy? I would expect any company to suspend the account of someone hacking them.
- silentOpen 15y agoWhen you've tried to inform the vendor and have been rebuffed, a demonstration of the vulnerability helps convey the gravity of the issue.
- vidarh 15y agoHe did it under his own name, in a way dad not damage anything, using a problem that has been well known for ages, after attempting to draw attention to the issue several times and being ignored. It is pretty obvious that he did not have any malicious intent, nor intended to do damage (if he wanted to, he could've done massive damage from an anonymous account in ways that wouldn't draw attention to it). The only thing suspending his account accomplished is to punish someone who has helped draw attention to a very serious problem. It just comes across as an incredibly childish and petty response given the circumstances.
- elithrar 15y ago> He did it under his own name, in a way dad not damage anything, using a problem that has been well known for ages, after attempting to draw attention to the issue several times and being ignored. He was ignored by the Rails devs, not by GitHub. Yet GitHub became the target of his attack, because he was "bored" (his word, not mine). At no stage, as far as we know, did he raise the issue directly with GitHub. As I've said in another thread, he could have done so and requested they disclose the fix publicly (say, within 24 hours) in an effort to force the Rails devs' hands. Instead, he's punished GitHub (who, mind you, probably should have audited for this vulnerability a long while ago) because he was shunned by the Rails devs.
- hythloday 15y agoIf you read the Github advisory, he did indeed raise the issue with them "last Friday": https://github.com/blog/1068-public-key-security-vulnerability-and-mitigation#comment-17297 https://github.com/blog/1068-public-key-security-vulnerabili...
- dos1 15y agoSure, that was my knee jerk reaction too. Of course they should suspend the account! But I think that was the wrong choice. Shutting down the one account will do nothing. He can create a second account in a matter of seconds. They fixed the code that permitted the exploit, right? So the fix alone should be plenty to prevent any more malicious attacks. And now, because of the suspension, they have a wave of bad PR (justified or not). This guy is clearly infatuated with Github. He got a tattoo of the Octocat for crying out loud. Why would you punish this guy for loving your service and caring enough about it to warn you of a security vulnerability? Seems like there are only minuses to suspending the account, not a lot of pluses.
- artursapek 15y agoThe point is he did them no harm when he could have done a lot of it.
- emc12 15y agoI would expect any company to do far more than suspend the account, especially knowing exactly who did it. I would think having a suspended GitHub account would be the least of worries with a company who has presumably access to a good lawyer or two and boatloads of cash...
- deleted 15y ago[deleted]
- wycats 15y agoAll of my public comments on this topic agree that this is a problem that we should fix. Are you conflating me with other people? Am I not part of "the Rails team"?
- vidarh 15y agoThe issue is that it needed to go this far before someone actually paid attention to it. It indicates a cultural problem that is not going to get addressed by fixing a single technical issue.
- mquander 15y agoEgor is a human whose motivations were totally obvious and whose actions were transparently harmless (and, in fact, net helpful.) The Github team are behaving foolishly if they can't or won't distinguish that from an "attack." Organizations should be expected to make decisions using reasoning that amounts to more than word association, e.g. he "attacked" us, so we'll "suspend" him.
- mkramlich 15y agoPerhaps these conditions are not mutually exclusive. It can be an attack, and, something done with good intentions to illustrate a point.
- Fluxx 15y agoI would disagree with this, quite a lot. He brought up an issue with the Rails team, they pointed him at the canonical, "here is where we talked about this before, sorry." Still not satisfied, he found the same exploit in Github to prove a point. Rather than do the sensible thing by creating a dummy account and contacting Github showing how he messed things up, he barged into the Rails organization and left a silly commit. Github is first and foremost a business organization where lots of companies pay them lots of money to "take this shit seriously" and protect their data, so they did the right thing by shutting him down.
- mquander 15y agoI honestly don't see the meaningful difference between contacting Github and leaving a silly commit, except that the former would probably get the bug fixed quietly; in contrast, now everybody is aware that the bug existed in Github and is aware of the potential for it to exist everywhere. He successfully proved his point, which apparently was a pretty good point. Isn't that a better outcome? As for Github's responsibility: Github failed to protect people's data the minute the bug went live. That data was open to Egor since the moment he discovered the bug until the moment they fixed it. Making a silly commit did not make anyone's data more or less vulnerable, so I don't believe that "taking this shit seriously" implies flipping out over it.