[HN Gopher] GitHub UX has operational security risks
       ___________________________________________________________________
        
       GitHub UX has operational security risks
        
       Author : davydog187
       Score  : 27 points
       Date   : 2024-07-04 17:52 UTC (5 hours ago)
        
 (HTM) web link (twitter.com)
 (TXT) w3m dump (twitter.com)
        
       | lijok wrote:
       | It does show people in your org first, but you have to search by
       | username, not full name.
        
         | rad_gruchalski wrote:
         | And that is a problem. Do you know gh usernames or everyone in
         | your org? I sure know most names of the people in my org but no
         | clue about their handles... I most often depend on gh
         | suggestions.
        
           | bitfilped wrote:
           | I know people in my org by their handles better than their
           | names haha, guess it just depends on the culture of the place
           | you're at.
        
       | wrs wrote:
       | I agree this is a real problem. If the repo is in an
       | organization, I would like to have to check a box like "include
       | outside users".
        
       | fjni wrote:
       | Github ux is an unmitigated disaster from an operational security
       | perspective. In their defense, it did start out as an open-source
       | tool. The fact that enterprises adopted it so blindly despite
       | this is pretty interesting.
        
         | okanat wrote:
         | It really didn't start out as an open-souce tool. Github was
         | founded for selling private repo access for Git and got popular
         | in the FOSS community since they provided free storage.
        
       | brobdingnag_pp wrote:
       | Accidentally @tagging people in private PRs is always fun too!
        
       ___________________________________________________________________
       (page generated 2024-07-04 23:01 UTC)