SHARE
Facebook X Pinterest WhatsApp

Github Security is Broken

Mar 5, 2012

githubFrom the ‘Bender from the Future’ files:

Over the last several years, github has become the premier development hub for all things open source. 

So when the github platform as a whole has a security problem, open source developers really need to take notice.

Late last week, a flaw in the underlying github ruby code was discovered and reported to github. Github disagreed with the severity and closed the bug without fixing it, which led to one of the best back/forth discussions I’ve ever seen in an open forum about a security issue. You see the researcher that discovered the flaw, Egor Homakov didn’t stay quiet, he kept pushing the issue.

One of my favorite Homakov posts was titled,” geez. github y u SO open?” which was part of his thread, “I’m Bender from Future.”

For his efforts, Github didn’t reward Homakov, instead they suspended him from Github. To Github’s credit they did eventually reinstate Homakov.

“Now that we’ve had a chance to review his activity, and have determined that no malicious intent was present, @homakov‘s account has been reinstated,” Github’s blog states.

The problem with this whole security issue, is that at the core, it’s an exploit that could have enabled anyone to inject anything they wanted to, into any Github account. That’s a major problem, whether it’s in Rails or anything else on Github. Instead of dealing with Homakov responsibly, Github put roadblocks in his way, until he forced their hand.

I strongly suspect that after this issue, Github won’t be as flippant the next time a security flaw is reported. I really do wonder however how many other issues are in the Github platform that have been ignored, issues where the researcher wasn’t as aggressive as Homakov.

Sean Michael Kerner is a senior editor at InternetNews.com, the news service of the IT Business Edge Network, the network for technology professionals. Follow him on Twitter @TechJournalist.

Recommended for you...

Insteon’s Surprise Failure Highlights the Problems with Smart Home Tech
Rob Enderle
Apr 22, 2022
Does Meta Have a Death Wish?
Rob Enderle
Apr 14, 2022
U.S. Needs to Protect Tech Leadership: Qualcomm
Rob Enderle
Apr 8, 2022
Best Internet Security Software
Devin Partida
Mar 23, 2022
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.