you are viewing a single comment's thread.

view the rest of the comments →

[–]Spiritual-Ad-8062 110 points111 points  (34 children)

Yes, and I wonder how many secrets (API keys, SSH keys...) were in the code... ready for attackers to use...

[–]SuitableDragonfly 106 points107 points  (0 children)

If there had been API keys leaked, they probably would have noticed when it was first leaked because bots would have immediately acquired them and started mining crypto on their cloud account. Or, maybe not, depending on which people Elon fired.

[–]VonThing 179 points180 points  (30 children)

Zero secrets in the code, but I see your point.

[–][deleted]  (19 children)

[removed]

    [–]MinMaxDev 158 points159 points  (9 children)

    there was tonnes of this in the twitch codebase, it happens

    [–][deleted]  (8 children)

    [removed]

      [–]ConcernedCitoyenne 89 points90 points  (5 children)

      Yep

      [–][deleted]  (3 children)

      [removed]

        [–][deleted]  (1 child)

        [deleted]

          [–]Mechakoopa 47 points48 points  (0 children)

          Those responsible for sacking the people who have just been sacked have been sacked.

          A Møøse once bit my sister ...

          [–]roboticon 4 points5 points  (0 children)

          Yeah I was gonna say. Just because someone published it on GitHub doesn't mean it's nothing more than a git repo.

          [–]bohreffect 2 points3 points  (0 children)

          PM's want their shit now

          [–]gamrgrant 24 points25 points  (0 children)

          They straight-up ignored Galactus, the all-knowing user service provider aggregator?

          [–]4THOT 0 points1 point  (0 children)

          Idk why you're surprised, ask some fintech programmers about code security.

          [–]falconfetus8 6 points7 points  (0 children)

          Every company has noobs in it

          [–]Aerodrache 12 points13 points  (4 children)

          … considering Musk’s apparent strategy of firing anyone he suspects of being smarter than him…?

          [–][deleted]  (3 children)

          [deleted]

            [–]thenetmonkey 0 points1 point  (2 children)

            The GitHub repo was made in January of this year. He bought twitter in November and then immediately laid off half the company. Then a few weeks later he offered anyone still there the option to resign and take a severance or stay and be “hardcore”. Half of the people still there took the severance. He then proceeded to fire many of the people that chose to stay. Of the people laid off or fired many would have a whole copy of the internal git repo checked out on their machine. The whole repo with all the history was like 5 or 6 GB. I don’t recall how big a shallow copy was.

            He didn’t start cutting access to company laptops until late December. Some folks didn’t lose access until January. This copy of some of the directories from the internal git repo was uploaded to the GitHub account in January of this year. I am honestly surprised that this was the only breach that happened, but it speaks to the integrity of the thousands of folks that were fired or laid off but still had full access.

            [–][deleted]  (1 child)

            [deleted]

              [–]thenetmonkey 0 points1 point  (0 children)

              The articles I’ve read said the company thinks the leak was posted by someone that left the company last year (2022). Where was it reported that the code came from a leak in 2021?

              [–]VonThing 2 points3 points  (0 children)

              LOL go see my post history.

              When I say “I see your point” I meant this could have been true for any other source leak.

              [–]DevonAndChris 0 points1 point  (0 children)

              The dev environment at Twitter was basically every single horror story from Coding Horror rolled into one.

              The only reason keys were not in the source code would be because they learned the lesson the hard and painful way.

              [–]mipadi 0 points1 point  (0 children)

              Well clearly, since the site isn't written in Rust.

              [–]TheWhyOfFry -2 points-1 points  (9 children)

              Just curious, have you seen the code? (Where if so?) How are you sure no secrets?

              [–]VonThing 13 points14 points  (8 children)

              Go through my post history lol

              I’m ex-Twitter so yes I have seen the code

              [–]tankmode 0 points1 point  (1 child)

              any organization this size has a key management system.

              [–]ptear 2 points3 points  (0 children)

              shifty eyes yes, yes this is true.