6 ms·
What's to prevent Egor from setting up a new account and using it to exploit the vulnerability he's found?
by kpanghmc 15y ago
What's to prevent Egor from setting up a new account and using it to exploit the vulnerability he's found?
- marshray 15y agoI believe Github has patched this specific vulnerability.
- jannes 15y agoThey claim to have fixed it. http://news.ycombinator.com/item?id=3663313 http://news.ycombinator.com/item?id=3663313 If they were thorough enough to fix it everywhere in their code is a different matter, though.
- rdtsc 15y agoThat is why this just seems like petty bureaucratic revenge. It looks good for PR purposes and placates other users ("look we got rid of the problem, the hacker has been eliminated").
- stock_toaster 15y agoI think it is more likely they need to verify that he only did what is currently known about and nothing else (such as if he had granted himself access to some private repos, for instance). Much safer to suspend/terminate his account first just in case. They are likely combing access logs, etc. Maybe they will reinstate it later after a review. Who knows other than Github. It could also be to reduce legal culpability. If they left his account enabled and he had granted himself access, and later did more damage, they might be liable for negligence? Not sure. IANAL, etc.
- rdtsc 15y ago> It could also be to reduce legal culpability. Ok that makes sense. In light of that they most likely acted rationally and correctly.
- deleted 15y ago[deleted]
- rmc 15y agoEthics? He's made his point.