Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Suspending him only shows that if a vulnerability exists (and they always do) in the future people won't go about it so openly because what they'll get for their troubles will be an account suspension. The guy could have done real harm if he kept silent and used it maliciously, chose not to, and got suspended. Github should pay him for finding the vulnerability instead!


Actually now that they've suspended him, I kind of wish did some real damage. The whole 'get hung for a lamb' saying.

That is why I don't really believe in 'white hat hacker' label. Organization when humiliated by their vulnerability strike back and treat the white hacker as a criminal. Or I guess since he actually modified a file or to instead of just publicly commented about the theoretical vulnerability, he is now a gray hat hacker ... ? But if he just blogged about the vulnerability without proving it, he wouldn't have been taken seriously and less people would have believed him (did you know about this guy before this happened? I didn't).

That is why I think, as an individual, if you hack, always be a black hat hacker. Organizations do not have mercy and will not treat you with respect if you just break in to point out a problem to try to help them. So might as well do some real damage, hide and or profit from it, by selling it on a black market.

(Note, not saying that I condone, or personally agree with such activities, just proposing a better course of actions for those who do).


That is why I don't really believe in 'white hat hacker' label. Organization when humiliated by their vulnerability strike back and treat the white hacker as a criminal.

Supposedly, a white hat hacker is someone hired (or at least, legally authorized) by the company itself to test their security by trying to break in.


I thought it was more of a moral label than anything else. One who find vulnerabilities but doesn't exploit them or doesn't do it with a malicious purpose vs. the ones that do it with malice, Of course you can't read someone's mind, but you can see the actions and go from there. It looks extremely unlikely that this is a case of hacking for profit or to cause harm.


Remind me to never play Prisoner's Dilemma with you.


I wouldn't even play it with myself ;-)


Would that be some form of strategic onanism?


Strategic onanism. LOL


When you hack something, even with good intents, you always end exposing yourself to some form of retorsion.

You can point your fingers to vulnerabilities every day full time just to make the web a better place and many will thank you for this but much more will just threaten you or file a complaint.

This is one of the main motivation behind the no more free bugs movement: http://blog.trailofbits.com/2009/03/22/no-more-free-bugs/


How does anyone know he hasn't placed a thousand backdoors elsewhere on GH? This could have been just the harmless shot across the bow. The real vulns being traded in the online underground market now (or in the near future)?


GitHub themselves acknowledged that he only compromised 3 accounts and none of them seriously: https://github.com/blog/1068-public-key-security-vulnerabili....

Seeing the comments he made days prior to this and also knowing what an appalling security vulnerability attr_accessible is I'm very pleased he did this. The issue needs to be addressed and for some reason everyone's been sweeping it under the carpet.

The guy was clear and resonable in the earlier bugs and suggestions he posted and then simply escalated them (with no harm done) to illustrate the issue.

Frankly this is a whole less worrying than firesheep and way more easily addressable.


Are they assuming he only used one account?


Presumably Github is currently auditing their db for keys added to organizations by users who are not admins of those organizations.


It is possible but why would he disclose it then if he was trading it on the black market? Kind would shot himself in the foot then since the vulnerability would be fixed and the price of it would go down to 0.

Actually, that was my original point. If he is already treated as a criminal and a hacker, might as well profit from it. Instead of trying to disclose it publicly and get treated as a criminal, might as well sell it on the black market, don't tell anyone about it and at least profit from all this work.


Agreed. He used an account trivially tied to himself, and posted publicly with his full name and picture on his blog explaining what he did, after having complained about the existence of this problem in public in the past (though apparently not specifically about Github).

He might have been stupid to do this, and a bit childish in his approach, but he did not go about it in a way that's reasonably interpreted as malice.

As a Github user, it angers me that they've responded in this way.


I think another issue is that as much as we adults want every white hat hacker to discreetly file a vulnerability report to a designated email address, teenagers, just won't ever do this! That is just the way things are. When you are young, you want to brag about things publicly without really thinking about your actions. I also think a vast majority of teenage pen testers have illusions that their exploits will lead to job offers.

In my opinion: an appropriate response is that, once a talented teenager pen tester is identified, to pay some attention to him/her and guide their abilities. Maybe you can create a private bounty program for them and provide some rules to abide by or even teach them how to do things correctly in an adult world.

Suspending their account immediately might actually be a good initial slap on the wrist for a teenager. Going forward, I would reinstate their account after some guidance has been provided. Especially for someone who is such a fan of GH.

I think that Western countries have a culture of villainizing teenagers who have some technical ability in pen testing. This needs to change in a way that those talents are guided in a more positive direction. Rather than tasking FBI to send teenagers to jail, why not put these talents to work disrupting China's extensive cyber offensive? Maybe this is why China is kicking our collective butts in cyber security.


Just a note: @homakov is no longer suspended, as of about 25 minutes ago: https://github.com/rails/rails/commit/b83965785db1eec019edf1...


Yeah I expected this as many github-ers are also HNers and it looks like this PR battle is not theirs to win this time (there is some backlash happening). This is good, they listen to developers and I think that is a good decision. As ultimately developers are their customers (either indepent ones or the ones working for large companies).




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: