6 ms·
IntelliJ GitHub Plugin leaking credentials
- that_guy_iain 2y agoThis is the second time today I’ve seen this but it is dated the 10th how come it’s taken everyone so long to notice?
- refulgentis 2y agoI don't understand what you mean: a blog post was published on the 10th, you saw a link to it twice today, so "everyone" took "so long to notice"? I'm teasing, it's just a surprisingly increasing fallacy I see: "Why is the rate at which I saw things not the rate I expect? What did They mean by this?"
- that_guy_iain 2y agoWell considering the amount I’m on here, Reddit, and various tech slacks seeing something like this repeatedly normally means it’s just been posted. I’m kinda wondering if they didn’t do the usual promotion.
- EdwardDiego 2y agoObviously Big Kotlin is suppressing the news.
- bdhcuidbebe 2y ago> I'm teasing, it's just a surprisingly increasing fallacy I see: "Why is the rate at which I saw things not the rate I expect? What did They mean by this?" Indeed, I have been noticing this form of fallacity lately too. it pops up everywhere. It seems to be related to the recent trend of boldly stating opinions about anything, without having any domain knowledge, which seem to have been popularized by a certain orange.
- manquer 2y agoIt didnt ? I have got three different advisories from infosec this week, even customers have asked about it
- deleted 2y ago[deleted]
- stuff4ben 2y agoGood idea to rotate your tokens on a regular basis, but in this case, go ahead and do it now (if you use this tool and plugin)
- thund 2y agobetter even, don’t use never-expiring tokens/credentials that need rotation.
- WorldMaker 2y agoExpiration is still a form of rotation. Also, GitHub doesn't provide never-expiring tokens, all of their tokens have expiration policies and need regular rotation. That doesn't mean that there aren't good reasons (such as in this case vulnerable applications) to manually rotate even before the expiration date.
- paulryanrogers 2y agoIIRC, GH classic tokens can never expire.
- Merad 2y agoIt seems like GitHub is rejecting requests from affected IDE versions. We discovered this yesterday because PR integration was not working even though the GitHub login/token was correct. Issue resolved by upgrading the IDE to the latest version.
- mattjaynes 2y agoI have a client who was using JetBrains' TeamCity CI product. Was a clown show of vulnerabilities that allowed attackers access to internals. Do not use their products. If you must for some reason, be sure you subscribe to critical CVEs of the products you are using and update them immediately and rotate your credentials. Ideally re-install on a fresh server. Never have the service available via the public web, it will be hacked - only use their products behind a VPN. https://blog.jetbrains.com/teamcity/2024/02/critical-security-issue-affecting-teamcity-on-premises-cve-2024-23917/ https://blog.jetbrains.com/teamcity/2024/02/critical-securit... https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/ https://blog.jetbrains.com/teamcity/2024/03/additional-criti...
- rf15 2y agoTheir plugins are a (very) mixed bag, but saying to not use their products is a bit too alarmist if you ask me - the baseline IDE is doing fairly well, and teamcity and doing your GitHub-specific PR-stuff from within intelliJ is kind of niche overall I would assume (I've never used either, only the stock git client they have)
- mattjaynes 2y agoThat's fair. I have limited experience with the rest of their offerings. They only came onto my radar because of regular critical CVEs that needed urgent fixing. The communication from the company had no hint of apology - just "hey, better fix this before your server is p0wned" - which did not seem like they were to be taken seriously.
- manquer 2y agoAndroid Studio is built on IntelliJ platform, this is not a choice a developer always can make —- P.S. yes it is possible to develop Android apps without studio, but it is painful to setup and manage , developers should not be fighting the system to do their jobs
- lyu07282 2y agoI kind of have to agree but their software products are huge, it's difficult to say if they are particularly bad. Don't expose their products on the open web is good advice but it applies to many products not just theirs (like gitlab/gitea). https://stack.watch/product/jetbrains/ https://stack.watch/product/jetbrains/
- orf 2y agoWhat is the actual vulnerability? The post is super light on details.
- lostmsu 2y agoSounds like they added token to all requests done by the plugin, so when you opened a pull request and linked an image from 3rd party, the 3rd party would receive your token.
- deleted 2y ago[deleted]
- albert_e 2y agoOff topic -- how does the JetBrains website display "IntelliJ" text in stylized "iJ" at the end of IntelliJ? Some CSS magic? I tried editing the text using the developer tools and this styling only applies when the text is IntelliJ or any word that starts with this exact string (case sensitive)
- yen223 2y agoThat effect comes from their font - "Jetbrain Sans"
- muningis 2y agoThat’s font ligature. Basically when two glyphs/symbols are one after another, they have a different glyph to show both of them.
- raincole 2y agoHave you seen whose weird "fonts for programmers" that make != look like a single character? Same thing. (Btw I hate that)
- deleted 2y ago[deleted]