4 ms·
Sounds like Github is doing the right thing. Detecting your account is compromised and forcing a reset of credentials. It does sound like they might need to up
by olefoo 13y ago
Sounds like Github is doing the right thing. Detecting your account is compromised and forcing a reset of credentials.
It does sound like they might need to up their game on traffic monitoring, since how did the attacker get enough tries to brute force even a simple password? But that's why it's an arms race.
- nilved 13y agoNo, it'd be the right thing if they didn't get hacked to begin with. This is _GitHub_ being bested by _brute force_.
- AdamGibbins 13y agoHow do you reasonably protect from brute force? Other than enforcing secure passwords. You block IPs that make too many fail attempts - you block an entire NAT range i.e. schools. Kids like to troll each other. Alternatives?
- nilved 13y agoGitHub has rate limiting in place (for user logins), as it demonstrated when it counter-intuitively locked me out of my own account while I tried to regain access. The fact that multiple accounts were compromised through this attack (despite their rate limiting) and that it would be literally impossible to guess my password sans quantum computing indicates _their_ password was compromised, not the password of any affected account. The solution is for them to use proper password security.
- olefoo 13y agoWell, if all we have to go by is this email; it's rather hard to make judgments about what Github did or didn't do. I'd hope that github will do a post-mortem, and tell us what they know of the breaches.