Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Breaking some poor dude's window probably causes a whole bunch more economic damage than a spurious commit into a github repos.


Do you have any idea how much it costs to clean up after an "intrusion" or "data breach"?

Of course, it's unfair to blame all those costs on the guy who had to go as far as actually escalating his privileges in order to unmask the Rails developers for being such knuckleheads.


Cleaning up after the breach constitutes of two parts: 1. Changing passwords, removing unauthorized changes/fraudulent transactions, etc. dealing with evil people accessing info that shouldn't be accessed. 2. Notifying clients of vulnerability existence, securing the system properly and changing procedures so that such kind of breach would have less chance of happening again.

In the white hat scenario, the first part does not exist and the white hat does not actually do anything harmful. The second part still exists and can cost tons of money, but this part is not the fault of the person who found the problem.

So while the costs _after_ a benign "intrusion" like was done to Github can be substantial - both in money and reputation, the costs _because_ of it are much less, since most of the costs weren't caused by it, it only exposed the pre-existing need of bear those costs. Like a doctor diagnosing somebody with serious illness - he's not at fault that the person now has to spend tons of money on drugs and medical procedures.


As I understand it, for all you know, there were other intrusions anyway and you'd have to go looking for them and clean up after them anyway as soon as you learned that there was an exploit. Whether one dude actually posted something under someone else's name doesn't affect that there has been a huge hole in github for (apparently?) years.


Right. As if this guy who reported it was the only one at the time who could have pwned Github with it.

For all we know, this bug has been abused for a long time to commit backdoors to other projects (perhaps those too big and active to notice).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: