Wow. Wowowowowowowowow. Wow.
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
It was super easy! Barely an inconvenience!
This is the only logical reaction, honestly 🤣
I'm surprised whatever software the keys were for didn't detect this and deactivate the keys. Discord did this automatically when I pushed a file to github that had a bot login token in it. Apparently Discord constantly scans github for such things, or maybe github does and sends Discord a msg, I dunno. But it was amazingly fast, like within 2 minutes.
that feature was probably deactivated, just like the feature on github which prevents uploading of SSH keys that had been explicitly disabled
No, I just checked - it's part of github's "Secret Scanning", which checks pushes for secret values and notifies partner services (like Discord) to deactivate them.
that's, uh... that's bad, right?
well, its not good
Unless you're China.
Mmmmm . . Nnno, i don’t have that one. Oh - there’s a “Ghyynah”, is that it?
Fast. Cheap. Good.
At best, pick 2.
This applies to code and coders as well, despite management's inability to comprehend reality.
OMG
...but remember, everything needs to be written in memory safe languages to stop security breaches.
"I might get mugged in a dark alley, so why should I bother locking my door at home?"
Security breeches stop your phone falling out while riding a horse.
Defund DHS.
And, when mainstream media periodically interviews republican congressmen who happen to be opposed to the Trump admin’s latest corruption/idiocy, why the hell do they never ask “Since you’re against these illegal/irresponsible actions… what the flying F are you gonna do about it?”
huh, so they've never used npm?
Honeypot?
A container of sweet stuff that you get stuck in.
Basically, a system full of juicy looking data that takes forever to collect and process... And then it was all fake data the whole time.
Plus, you can hide some real info, like the name of the machine compromised, or info about the attacker's system in the data, and then when it gets compromised, sold on the black market, and eventually published, you can reference the leaked data to see exactly which system the hackers got into, and get some insights on how they did it.
What are the odds this was AI related vs some underpaid intern
This was a dev who wanted to sync data between their home and work computers so they could do check-ins from home. This is a combination of a lazy person who values their own ease of use over basic security practices, plus a government contractor who values making as much money as possible by paying shitty devs without any real oversight over those shitty devs, plus an oversight government entity that had its funding slashed by people who only understand cutting money as opposed to national security.
Nothing can beat real organic stupidity
I’m sure that will be an excuse but no, this was lazy-ass we-dont-wanna incompetent garbage devs.
Odds are neither and it’s a “plausibly deniable” attack.
Or worse, both