[HN Gopher] Sourcegraph: Incident involving unauthorized admin a...
___________________________________________________________________
Sourcegraph: Incident involving unauthorized admin access
Author : 0xedb
Score : 73 points
Date : 2023-08-30 23:09 UTC (23 hours ago)
(HTM) web link (about.sourcegraph.com)
(TXT) w3m dump (about.sourcegraph.com)
| lopkeny12ko wrote:
| [flagged]
| evujumenuk wrote:
| Please do not post obvious rage bait. Doing so generally does
| not foster fruitful debate.
| abtinf wrote:
| That would be a solid approach to ensure that the next incident
| is more severe and longer lasting.
| pc86 wrote:
| People make mistakes, get over it.
| lopkeny12ko wrote:
| So we are expected to just shrug off a leak of PII collected
| from _self-hosted_ instances?
|
| I would normally agree with you, but this was an egregious
| violation of trust.
| pc86 wrote:
| I think we're reading different articles, no employee
| leaked any PII. You're angry about something that didn't
| happen.
| Operyl wrote:
| Realistically, you don't want to fire the person that makes
| this mistake. It pretty much is _never_ going to happen
| again for that employee, it's burned in their mind now.
| sqs wrote:
| The information that leaked was not collected from self-
| hosted instances. It was from Sourcegraph.com, which
| contains generally less sensitive information than self-
| hosted instances. See
| https://about.sourcegraph.com/blog/security-update-
| august-20... for full information.
| beanjuiceII wrote:
| yikes, can i even trust this company now
| bastardoperator wrote:
| Don't ever trust a company... you're going to be disappointed
| every time.
| yorick wrote:
| Sourcegraph seems to have collected a bunch of these (now leaked)
| email addresses from signups on self-hosted instances.
|
| I remember being very surprised when I was signed up to their
| mailing list after I made an account on my self-hosted instance,
| and I'm not sure about the ethics (and legality) of collecting
| these in the first place.
| mirekrusin wrote:
| Overall very well handled and communicated. To get 11 points out
| of 10 remove adjectives from communication. When people read
| "quickly" they don't think "oh great they were quick, I'm going
| to trust them more now", they think "communication is biased".
| Just write facts (ie time stamps or if you don't have them use
| "hours" or "same day").
| [deleted]
| dspillett wrote:
| _> accidentally committed a code change that contained an active
| site-admin access token_
|
| Our regular reminder to try keep credentials and other security
| tokens well away from any source code where-ever possible, even
| if that might mean making things a touch less convenient.
|
| I'd guess that most of us have checked in or otherwise posted a
| credential at some point in our careers. I've certainly done it
| in the past with an application DB connection string and had to
| do the quick reconfigure to revoke that access1 - in that
| instance resolution was quick & easy but for other environments
| it might be a lot more admin.
|
| Being careful isn't the solution because mistakes will always
| happen, making it damn near impossible to accidentally post
| credentials is the way to go.
|
| --
|
| [1] even though the repo checked into could only be accessed from
| within the company, and the DB instance in question was locked
| down so only the application servers and the limited few with
| access to a VPN connecting to its subnet, good practise dictated
| immediate full revocation just in case
| ttyyzz wrote:
| I don't know but it always seems to be worded like in this
| instance: "...A small subset of customers' Sourcegraph license
| keys may have been accessed..."
|
| I don't buy that, it always seems to me like an attempt to
| downplay something.
| dcomas wrote:
| I lead security at Sourcegraph and have been overseeing the
| incident investigation and resolution. To give you more
| specific details, I can say that we saw that the attacker
| viewed a page where they would have only seen the first 20
| items, and we were able to determine what those were at the
| time of viewing because of stable sorting.
| temp0010222 wrote:
| https://desuarchive.org/g/thread/95694999/#95695126
|
| The source of the hack.
| Awaawawawa wrote:
| [flagged]
| mistrial9 wrote:
| that is .. odd. Can someone please explain-like-I-am-five that
| the ** is going on in that forum?
|
| huggingface links and expiring proxies get mentioned a lot
| neom wrote:
| It's really hard to understand, I originally thought it was a
| spam link, heh.
|
| It looks like you can somehow use Sourcegraphs "Cody" gateway
| to utilize Claude by Anthropic. I guess SG was rate limiting,
| and user HopeMan gained access to SGs admin systems and is
| asking people to drop their emails to get them un-rate-
| limited? Best I could make of the thread.
|
| https://docs.sourcegraph.com/cody/explanations/cody_gateway
|
| https://claude.ai/
|
| (desuarchive seems to be a 4chan archive)
| fein wrote:
| It's an archive of 4chans /g/ board. Many things are
| discussed, many insults are leveled.
|
| Are you asking what desuarchive is or are you asking what
| 4chan is?
| mistrial9 wrote:
| no - the transactions .. what are those lists of numbers
| being traded ? How are those valuable ? "What is going on
| in that forum?"
|
| that chat environment seems to be both a cause and a result
| of ADHD-like existance! can I say "hellish" ?
| mgiannopoulos wrote:
| This my new personal record (3 days) between signing up for a
| service and getting a notice that my email address has been
| leaked :D
| deathbypenguin wrote:
| Hey! you and me both, 4 days in my case, but it's a record for
| me.
| leke wrote:
| #metoo
___________________________________________________________________
(page generated 2023-08-31 23:02 UTC)