3 ms·
I'm sorry you took it that way. The scope of our security hole was exactly as big as the Rubygems vulnerability. If I'd omitted that comparison, I was sure some
by seldo 13y ago
I'm sorry you took it that way. The scope of our security hole was exactly as big as the Rubygems vulnerability. If I'd omitted that comparison, I was sure somebody would say "these guys were just as bad as ruby but they're covering that up!" At the same time, I wanted to make it clear that the only reason this wasn't a game-over disaster for us is because we were lucky. We weren't any smarter, or better designed. Just luckier.
- imbriaco 13y agoI think the problem I had with it had to do with the way the sentences were constructed. For example: "... this could have been a disaster, very much like the rubygems.org security breach in early 2013" This implies that the issue you had wasn't as serious as the RubyGems issue. Similarly, the following sentence likewise implies that the breach was not as severe: "Unlike that incident, there’s no evidence that, other than ourselves, the engineers who reported the bugs, and a few members of the GitHub security team who knew about the issue, anyone knew about this hole." This implies a confidence in the presumption that you weren't breached that you then backpedal on in the following sentence by saying "of course we're not positive because we didn't have logs". Both of the sentences I cite lead a reasonable reader to a different impression than the one you say you were attempting to convey. I'm glad to see you clarify things here, but I hope you can see why people would misconstrue things based on the words in the post.
- seldo 13y agoIt turns out we were incorrect about the scope of the Rubygems incident, and have issued a correction: http://blog.npmjs.org/post/80307645782/correction-to-previous-post-about-security http://blog.npmjs.org/post/80307645782/correction-to-previou...
- imbriaco 13y agoGlad to see the correction, it solves the one problem with an otherwise very well written incident report. Kudos for setting the record straight and taking the criticism so well.
- btilly 13y agoTruly exactly as big? The Rubygems vulnerability was the ability to run any code you want. What you describe is remote file browsing/access.