Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That wouldn't fix it.

I own the key. I set the owner of the key to you. You now own the key that I have on my machine. I commit to your repo.

I'm sure the github team has authorization at a model level, preventing access to other user's resources. This wasn't an instance of accessing another user's resources via rails, it was assigning your own resources to another user, then abusing that fact via git.



Actually, that's true. I stand corrected. I think I was distracted by the rather obvious issue in the example code that the OP posted, which did not include this basic protection.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: