7 ms·
This raises a big question: How effective is GitHub’s abuse reporting system against large-scale malware campaigns? If 1,000+ malicious repos can persist for mo
by linwangg 2y ago
This raises a big question: How effective is GitHub’s abuse reporting system against large-scale malware campaigns? If 1,000+ malicious repos can persist for months, does this mean GitHub lacks automated scanning or relies too much on user reports?
- EVa5I7bHFq9mnYK 2y agoAutomated scanning is easily bypassed - just fine-tune the submission until it passes the checks.
- david_allison 2y agoInsufficient. Reporting is a fairly manual process, has UX issues which discourage reporting, and is heavily rate limited. Response times can very from hours to what feels like months, and they rarely handle reports based on patterns of abuse.
- arp242 2y agoThe abuse reporting on GitHub completely sucks. You need to send a support ticket, which typically takes more than a month to get a reply to. And if by that time the comment or repo has been deleted they'll say "well it's deleted now, so we can't do anything". Because yes, I'm going to let spam sit around for over a month on my repo... :-/
- Evidlo 2y agoCan't you just report it and hide it?
- Jimmc414 2y ago> If 1,000+ malicious repos can persist for months 3 years unfortunately https://github.com/Jalynn0922/steal-cook https://github.com/Jalynn0922/steal-cook
- andrewchilds 2y agoI mean, do a search for "steal cookie": https://github.com/search?q=steal+cookie&type=repositories https://github.com/search?q=steal+cookie&type=repositories This one has been up for two years: https://github.com/Aker490/Steal-Cookie-Roblox https://github.com/Aker490/Steal-Cookie-Roblox It would be good to hear an official response from GitHub on where the boundaries are, since it seems like there's plenty of examples of clearly malicious repos hosted for years.