Anyone can Access Deleted and Private Repository Data on GitHub. (trufflesecurity.com)
from ModerateImprovement@sh.itjust.works to technology@lemmy.world on 26 Jul 2024 06:26
https://sh.itjust.works/post/22780038

#technology

threaded - newest

itsathursday@lemmy.world on 26 Jul 2024 06:50 next collapse

Even if you rewrite history?

sem@lemmy.ml on 26 Jul 2024 06:53 next collapse

The title is very click bait imo. It is not about any private data. It is a very specific case of deleted fork of the public repository. It is a bug, of course. But it doesn’t look so serious as I was thinking when saw the title.

tyler@programming.dev on 26 Jul 2024 07:11 collapse

It was purposefully designed that way so it’s not a bug. It’s just bad design. Like they say at the end of the article, people view private vs public as a security boundary. So it’s incredibly surprising and unintuitive behavior that has clearly resulted in security breaches.

radivojevic@discuss.online on 26 Jul 2024 07:12 collapse

Imagine putting private code online lol.

TrickDacy@lemmy.world on 26 Jul 2024 11:33 collapse

Of course it should only be on 5.25" floppy disk

radivojevic@discuss.online on 26 Jul 2024 16:00 collapse

Typewriter.