Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So users can add other users' SSH keys (sourced from GitLab, ....) to their GitHub profile, essentially depriving the actual key owner from using GitHub


But then that opens them up to having their victim commit code to their repos directly, as well.


Not a big deal for an attacker to create a dummy account.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: