logoalt Hacker News

Menethtoday at 4:57 PM2 repliesview on HN

I suppose CrowdSec isn't used to analyze GitHub's traffic, so they wouldn't have much info to go on.

If they had self-hosted their own repos, they might have had more luck.


Replies

sandeepkdtoday at 5:08 PM

It wasn't the Github that was compromised, it was the access to their private repository that was compromised so somewhere down the line the security best practices are in question for sure. Self hosted repos available on public internet would have met the same fate, may be worse, given github does provides some level of security.

Even regarding the blast radius, I do not really believe any company is honest about it. They do not have tools to verify it, if the user information was accessed with leaked token or real token. The thing that works in their favor is that no one else can verify it either which absolves them from any responsibility. Any platform engineer knows that your CICD system has the keys to the kingdom.

show 1 reply
niccetoday at 5:14 PM

GitHub Enterprise has at least some level audit log