3 ms·
As a developer or security researcher, you're able to download and run GitHub Enterprise Server. I'm not sure having access to the full source code makes a mean
by auscompgeek 5mo ago
As a developer or security researcher, you're able to download and run GitHub Enterprise Server. I'm not sure having access to the full source code makes a meaningful difference for most of GitHub's surface area, given it's largely Ruby.
- DanielHB 5mo agoLLMs can't really parse compiled code to find exploits, maybe code in scripting languages (python, js, etc) even if minified. So I don't quite agree with you, having access to the source can definitely help find exploits even in pre-LLM days.
- deleted 5mo ago[deleted]
- pixl97 5mo agoPretty much everyone disagrees with you, especially when you add in decompiler tools to the LLM.
- Yiin 5mo agohow to say you haven't tried llms since 2023 without saying it, that's quite literally one of the things they excel at
- ammar2 5mo agoAlso, the Github enterprise code is "obfuscated" but it uses a trivially reversible method just meant to be a minor roadblock. After you get past that you get the full ruby source code, no minification or anything. For a while the key was literally: > This obfuscation is intended to discourage GitHub Enterprise customers from making modifications to the VM. We know this 'encryption' is easily broken.