Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

GitHub themselves acknowledged that he only compromised 3 accounts and none of them seriously: https://github.com/blog/1068-public-key-security-vulnerabili....

Seeing the comments he made days prior to this and also knowing what an appalling security vulnerability attr_accessible is I'm very pleased he did this. The issue needs to be addressed and for some reason everyone's been sweeping it under the carpet.

The guy was clear and resonable in the earlier bugs and suggestions he posted and then simply escalated them (with no harm done) to illustrate the issue.

Frankly this is a whole less worrying than firesheep and way more easily addressable.



Are they assuming he only used one account?


Presumably Github is currently auditing their db for keys added to organizations by users who are not admins of those organizations.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: