[HN Gopher] Sourcegraph: Incident involving unauthorized admin a...
       ___________________________________________________________________
        
       Sourcegraph: Incident involving unauthorized admin access
        
       Author : 0xedb
       Score  : 73 points
       Date   : 2023-08-30 23:09 UTC (23 hours ago)
        
 (HTM) web link (about.sourcegraph.com)
 (TXT) w3m dump (about.sourcegraph.com)
        
       | lopkeny12ko wrote:
       | [flagged]
        
         | evujumenuk wrote:
         | Please do not post obvious rage bait. Doing so generally does
         | not foster fruitful debate.
        
         | abtinf wrote:
         | That would be a solid approach to ensure that the next incident
         | is more severe and longer lasting.
        
         | pc86 wrote:
         | People make mistakes, get over it.
        
           | lopkeny12ko wrote:
           | So we are expected to just shrug off a leak of PII collected
           | from _self-hosted_ instances?
           | 
           | I would normally agree with you, but this was an egregious
           | violation of trust.
        
             | pc86 wrote:
             | I think we're reading different articles, no employee
             | leaked any PII. You're angry about something that didn't
             | happen.
        
             | Operyl wrote:
             | Realistically, you don't want to fire the person that makes
             | this mistake. It pretty much is _never_ going to happen
             | again for that employee, it's burned in their mind now.
        
             | sqs wrote:
             | The information that leaked was not collected from self-
             | hosted instances. It was from Sourcegraph.com, which
             | contains generally less sensitive information than self-
             | hosted instances. See
             | https://about.sourcegraph.com/blog/security-update-
             | august-20... for full information.
        
       | beanjuiceII wrote:
       | yikes, can i even trust this company now
        
         | bastardoperator wrote:
         | Don't ever trust a company... you're going to be disappointed
         | every time.
        
       | yorick wrote:
       | Sourcegraph seems to have collected a bunch of these (now leaked)
       | email addresses from signups on self-hosted instances.
       | 
       | I remember being very surprised when I was signed up to their
       | mailing list after I made an account on my self-hosted instance,
       | and I'm not sure about the ethics (and legality) of collecting
       | these in the first place.
        
       | mirekrusin wrote:
       | Overall very well handled and communicated. To get 11 points out
       | of 10 remove adjectives from communication. When people read
       | "quickly" they don't think "oh great they were quick, I'm going
       | to trust them more now", they think "communication is biased".
       | Just write facts (ie time stamps or if you don't have them use
       | "hours" or "same day").
        
       | [deleted]
        
       | dspillett wrote:
       | _> accidentally committed a code change that contained an active
       | site-admin access token_
       | 
       | Our regular reminder to try keep credentials and other security
       | tokens well away from any source code where-ever possible, even
       | if that might mean making things a touch less convenient.
       | 
       | I'd guess that most of us have checked in or otherwise posted a
       | credential at some point in our careers. I've certainly done it
       | in the past with an application DB connection string and had to
       | do the quick reconfigure to revoke that access1 - in that
       | instance resolution was quick & easy but for other environments
       | it might be a lot more admin.
       | 
       | Being careful isn't the solution because mistakes will always
       | happen, making it damn near impossible to accidentally post
       | credentials is the way to go.
       | 
       | --
       | 
       | [1] even though the repo checked into could only be accessed from
       | within the company, and the DB instance in question was locked
       | down so only the application servers and the limited few with
       | access to a VPN connecting to its subnet, good practise dictated
       | immediate full revocation just in case
        
       | ttyyzz wrote:
       | I don't know but it always seems to be worded like in this
       | instance: "...A small subset of customers' Sourcegraph license
       | keys may have been accessed..."
       | 
       | I don't buy that, it always seems to me like an attempt to
       | downplay something.
        
         | dcomas wrote:
         | I lead security at Sourcegraph and have been overseeing the
         | incident investigation and resolution. To give you more
         | specific details, I can say that we saw that the attacker
         | viewed a page where they would have only seen the first 20
         | items, and we were able to determine what those were at the
         | time of viewing because of stable sorting.
        
       | temp0010222 wrote:
       | https://desuarchive.org/g/thread/95694999/#95695126
       | 
       | The source of the hack.
        
         | Awaawawawa wrote:
         | [flagged]
        
         | mistrial9 wrote:
         | that is .. odd. Can someone please explain-like-I-am-five that
         | the ** is going on in that forum?
         | 
         | huggingface links and expiring proxies get mentioned a lot
        
           | neom wrote:
           | It's really hard to understand, I originally thought it was a
           | spam link, heh.
           | 
           | It looks like you can somehow use Sourcegraphs "Cody" gateway
           | to utilize Claude by Anthropic. I guess SG was rate limiting,
           | and user HopeMan gained access to SGs admin systems and is
           | asking people to drop their emails to get them un-rate-
           | limited? Best I could make of the thread.
           | 
           | https://docs.sourcegraph.com/cody/explanations/cody_gateway
           | 
           | https://claude.ai/
           | 
           | (desuarchive seems to be a 4chan archive)
        
           | fein wrote:
           | It's an archive of 4chans /g/ board. Many things are
           | discussed, many insults are leveled.
           | 
           | Are you asking what desuarchive is or are you asking what
           | 4chan is?
        
             | mistrial9 wrote:
             | no - the transactions .. what are those lists of numbers
             | being traded ? How are those valuable ? "What is going on
             | in that forum?"
             | 
             | that chat environment seems to be both a cause and a result
             | of ADHD-like existance! can I say "hellish" ?
        
       | mgiannopoulos wrote:
       | This my new personal record (3 days) between signing up for a
       | service and getting a notice that my email address has been
       | leaked :D
        
         | deathbypenguin wrote:
         | Hey! you and me both, 4 days in my case, but it's a record for
         | me.
        
         | leke wrote:
         | #metoo
        
       ___________________________________________________________________
       (page generated 2023-08-31 23:02 UTC)