LWN: Comments on "Gentoo's GitHub mirror compromised" https://lwn.net/Articles/758633/ This is a special feed containing comments posted to the individual LWN article titled "Gentoo's GitHub mirror compromised". en-us Wed, 17 Sep 2025 06:19:19 +0000 Wed, 17 Sep 2025 06:19:19 +0000 https://www.rssboard.org/rss-specification lwn@lwn.net Gentoo's GitHub mirror compromised https://lwn.net/Articles/759861/ https://lwn.net/Articles/759861/ flussence <div class="FormattedComment"> The wiki that was lost was an unofficial third-party one, and AFAIK the Arch incident was also in third-party package repos.<br> <p> The distros are to blame for this about as much as Perl is to blame for RHEL shipping an incomplete 10-year-stale perl5 out of the box.<br> </div> Sun, 15 Jul 2018 02:23:38 +0000 Gentoo's GitHub mirror compromised https://lwn.net/Articles/759649/ https://lwn.net/Articles/759649/ antiphase <div class="FormattedComment"> These are the same people whose (frankly excellent) wiki was entirely lost because no-one considered doing backups.<br> Arch, whose wiki is probably the spiritual successor of the Gentoo one, also had a similar malware injection this week.<br> <p> I suspect they are not the distributions of choice of professionals.<br> </div> Thu, 12 Jul 2018 17:00:00 +0000 Gentoo's GitHub mirror compromised https://lwn.net/Articles/758863/ https://lwn.net/Articles/758863/ fratti <div class="FormattedComment"> As far as I'm aware, someone re-used their linuxforums password on freenode as operator of many high-profile channels such as #haskell, #znc and #gentoo, and apparently also for the Gentoo GitHub org.<br> <p> Really says a lot about the security hygiene of some people even in the FOSS world.<br> </div> Mon, 02 Jul 2018 16:57:02 +0000 Gentoo's GitHub mirror compromised https://lwn.net/Articles/758790/ https://lwn.net/Articles/758790/ epa <div class="FormattedComment"> It should be possible to set up a pure ‘mirror’ on Github that clones one or more repositories from an external source, and then never does any operation other than pull changes from those. The pure mirror status would be clearly shown in the Github page heading, and any change away from that would require a new project with a new URI. Then compromise of the downstream mirror would be impossible without compromising the upstream. <br> <p> You could still have issues and pull requests, but the code changes would have to be manually applied upstream first — or else in a separate Github project. <br> </div> Mon, 02 Jul 2018 06:15:04 +0000 Gentoo's GitHub mirror compromised https://lwn.net/Articles/758771/ https://lwn.net/Articles/758771/ ceplm <div class="FormattedComment"> I guess they haven't considered it to be the one.<br> </div> Sun, 01 Jul 2018 12:19:06 +0000 Gentoo's GitHub mirror compromised https://lwn.net/Articles/758736/ https://lwn.net/Articles/758736/ pabs <div class="FormattedComment"> Timeline of events:<br> <p> <a href="https://wiki.gentoo.org/wiki/Github/2018-06-28">https://wiki.gentoo.org/wiki/Github/2018-06-28</a><br> </div> Sat, 30 Jun 2018 11:24:39 +0000 Gentoo's GitHub mirror compromised https://lwn.net/Articles/758735/ https://lwn.net/Articles/758735/ pabs <div class="FormattedComment"> Some comments:<br> <p> <a href="https://blog.sumptuouscapital.com/2018/06/my-comments-on-the-gentoo-github-hack/">https://blog.sumptuouscapital.com/2018/06/my-comments-on-...</a><br> </div> Sat, 30 Jun 2018 11:24:02 +0000 Gentoo's GitHub mirror compromised https://lwn.net/Articles/758731/ https://lwn.net/Articles/758731/ danieldk <div class="FormattedComment"> GitHub makes it possible to require two-factor authentication within an organization. One would think that they'd enable that for critical infrastructure.<br> </div> Sat, 30 Jun 2018 09:17:51 +0000 Gentoo's GitHub mirror compromised https://lwn.net/Articles/758719/ https://lwn.net/Articles/758719/ Wol <div class="FormattedComment"> From the gentoo mailing list, it looks like someone's password was compromised. How that happened isn't yet known ...<br> <p> Cheers,<br> Wol<br> </div> Fri, 29 Jun 2018 23:32:46 +0000 Gentoo's GitHub mirror compromised https://lwn.net/Articles/758696/ https://lwn.net/Articles/758696/ flussence <div class="FormattedComment"> The skill level of the “attack” makes me wonder how easy it was to break in, too.<br> </div> Fri, 29 Jun 2018 19:22:42 +0000 Gentoo's GitHub mirror compromised https://lwn.net/Articles/758658/ https://lwn.net/Articles/758658/ pizza <div class="FormattedComment"> What I consider to be a far greater concern is _how_ the "github organization" account was compromised.<br> </div> Fri, 29 Jun 2018 13:53:14 +0000 Gentoo's GitHub mirror compromised https://lwn.net/Articles/758657/ https://lwn.net/Articles/758657/ unixbhaskar <div class="FormattedComment"> This is not a big deal. And I believe Gentoo users are not going get its effect. It's a damn mirror, people generally pull stuff from other places.<br> </div> Fri, 29 Jun 2018 13:47:28 +0000