Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

He didn't hack into any others' accounts, he simply (mis)used the service from his own. Suspending him is useless for security as he could set up another account in minutes.


the post at https://github.com/blog/1068-public-key-security-vulnerabili... says "Database and log analysis have shown that the user compromised three accounts (rails and two others that appear to have been proofs of concept)."

do you have any evidence for your assertion? (and why the downvote? i'm just reporting the facts....)


I think the accounts mean organisations. For instance, he exploited this vulnerability to add his public key to the authorised rails user keys. He probably did this to two other "accounts". His exploit wasn't logging in or impersonating any other accounts AFAIK.


Really splitting hairs here. He committed a change to a repository that wasn't his. He altered files that belong to other users, albeit benignly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: