NHS England is making all its public GitHub repos private by 11 May because AI models might find vulnerabilities in the code.
-
NHS England is making all its public GitHub repos private by 11 May because AI models might find vulnerabilities in the code.
The code that has been public for years. Already scraped. Already archived. Already ingested into the very models they are worried about.
This is bolting the barn door after the horses have left the county.
π§΅/1
-
NHS England is making all its public GitHub repos private by 11 May because AI models might find vulnerabilities in the code.
The code that has been public for years. Already scraped. Already archived. Already ingested into the very models they are worried about.
This is bolting the barn door after the horses have left the county.
π§΅/1
You cannot unpublish what has been public. To truly remediate, you would need to rewrite the bulk of your codebase β at which point, start fresh.
Instead of reactive redaction, try this:
β Use the AI tools to find your own bugs before someone else does
β Focus resources on the critical systems protecting personal and financial data
β Make new repos private by default where appropriate
β Stop pretending obscurity equals security
π§΅/2
-
You cannot unpublish what has been public. To truly remediate, you would need to rewrite the bulk of your codebase β at which point, start fresh.
Instead of reactive redaction, try this:
β Use the AI tools to find your own bugs before someone else does
β Focus resources on the critical systems protecting personal and financial data
β Make new repos private by default where appropriate
β Stop pretending obscurity equals security
π§΅/2
The NHS pioneered public sector open source in the UK. The Covid contact tracing app was published openly and caused zero security incidents.
That was leadership.
This is panic.
π§΅/3 (fin)
-
R relay@relay.infosec.exchange shared this topic