Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In what way do they have to prevent him from ever accessing the site from any account ever again? The best they can do is suspend his account per policy while they are investigating.


In what way do they have to prevent him from ever accessing the site from any account ever again?

Who said they did?

The best they can do is suspend his account per policy while they are investigating.

Why? What's the point of suspending his account?


Why? What's the point of suspending his account?

There are two issues with any exploit: (1) prevent future exploits and (2) making sure that whoever discovered the exploit hasn't retained any unauthorized access.

Fixing the bug addresses (1) and suspending his account gives them time to address (2).


But the thing here is that if he genuinely wanted to retain unauthorized access, he had at the very least several days to create a ton of alternative accounts to make use of this exploit with.

Suspending his account wouldn't have affected him if he was being black hat about this. A suspension in this case serves pretty much no purpose other than to make Github feel better about themselves.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: