info on the github breach appears to only be available on xitter ๐ , I fished it out for you.
-
info on the github breach appears to only be available on xitter
, I fished it out for you. -
info on the github breach appears to only be available on xitter
, I fished it out for you. @0xabad1dea sigh, thanks
-
info on the github breach appears to only be available on xitter
, I fished it out for you. @0xabad1dea hereโs a xcancel link: https://xcancel.com/i/status/2056949168208552080
-
info on the github breach appears to only be available on xitter
, I fished it out for you. @0xabad1dea wth is 'directionally consistent'
-
@0xabad1dea wth is 'directionally consistent'
@tati operational speak for "looks like it's probably correct"
-
info on the github breach appears to only be available on xitter
, I fished it out for you. @0xabad1dea Happy GitHub Breach Day! Enjoy this one. Starting next week we will go back to just calling it Wednesday again.
-
info on the github breach appears to only be available on xitter
, I fished it out for you. @0xabad1dea Glad to have deleted my GitHub Account when they introduced "AI". #github
-
@0xabad1dea Glad to have deleted my GitHub Account when they introduced "AI". #github
@GerhardD @0xabad1dea Glad to have left Github behind when it was about to be consumed by Viboslop.
(Yeah, I know, itโs still a supply chain attack free for all fest causing much hurt.)
-
info on the github breach appears to only be available on xitter
, I fished it out for you. @0xabad1dea maybe they'll build a status page some day. they're still a scrappy startup though, they probably have higher priorities like making investor pitch decks.
-
@0xabad1dea wth is 'directionally consistent'
@tati @0xabad1dea I don't know how someone decides to use the phrase "directionally consistent". Maybe they took too many drugs, or not enough. Anyway, something went wrong, for sure.
-
info on the github breach appears to only be available on xitter
, I fished it out for you. @0xabad1dea My favorite take so far: "holy shit, how did the attackers find a large enough uptime window to get in?"
-
@0xabad1dea wth is 'directionally consistent'
@tati @0xabad1dea โwe donโt think we can get away with denying itโ
-
info on the github breach appears to only be available on xitter
, I fished it out for you. @0xabad1dea while this is not directly related to AI as far as reported, I can't help but imagine that hiring people who buy into the AI idiocy is a surefire way to get your entire organization packed full of imbeciles likely to make this fuck up one day or another
-
info on the github breach appears to only be available on xitter
, I fished it out for you. @0xabad1dea Huh. Itโs almost as if an editor with a marketplace for extensions and zero thought to the security model (beyond โextensions have complete access to your computerโ) might not have been the best idea after all.
-
info on the github breach appears to only be available on xitter
, I fished it out for you. @0xabad1dea (horselegged/sanserif Swastikas...)
-
@0xabad1dea Huh. Itโs almost as if an editor with a marketplace for extensions and zero thought to the security model (beyond โextensions have complete access to your computerโ) might not have been the best idea after all.
@david_chisnall@infosec.exchange @0xabad1dea@infosec.exchange
While yes, I think it's more about the perception of extensions being secure. Emacs has the same security model, but you don't see Big News
about it.
Granted part of this is that Emacs itself requires a certain level of understanding to use so it filters out users who Just Install Things
but still. -
info on the github breach appears to only be available on xitter
, I fished it out for you. gonna gently push back that there's no reason (according to github's version of the story) to associate this with AI or with spectacular incompetence on the part of the employee; the issue is that industry standard, extremely widely used text editor Visual Studio Code has a big button that says "click here to add useful functionality to do your job" that has a 1% chance of installing ransomware
-
R relay@relay.infosec.exchange shared this topic
-
info on the github breach appears to only be available on xitter
, I fished it out for you. They wrote:
> "2/ Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. [โฆ]
3/ We moved quickly to reduce risk. Critical secrets were rotated yesterday and overnight with the highest-impact credentials prioritized first."Do they really put "Critical secrets" in their "GitHub-internal repositories" !?
-
They wrote:
> "2/ Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. [โฆ]
3/ We moved quickly to reduce risk. Critical secrets were rotated yesterday and overnight with the highest-impact credentials prioritized first."Do they really put "Critical secrets" in their "GitHub-internal repositories" !?
@benoitb every large organization, knowingly or unintentionally (usually both), has internal secrets embedded in their internal codebase. so yeah
-
gonna gently push back that there's no reason (according to github's version of the story) to associate this with AI or with spectacular incompetence on the part of the employee; the issue is that industry standard, extremely widely used text editor Visual Studio Code has a big button that says "click here to add useful functionality to do your job" that has a 1% chance of installing ransomware
@0xabad1dea Or the extension was legitimate and got compromised (their use of the term "poisoned" makes me think that).
Supply chain attacks are on the rise; the best course of action is to admit when they happen, learn from them, and use those learnings to prevent it in the future.