frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

What does GitHub's security team even do?

https://orchidfiles.com/github-security-team/
47•theorchid•1h ago

Comments

adityashankar•31m ago
I generally believe in hanlons razor (assume stupidity rather than maliciousness), it's likely that github saw the easiest possible solution rather than diving deeper into the cause of the problem to fix it permanently
woodruffw•28m ago
GitHub's response time on malicious repositories is often lackluster. However, from conversations with folks at GitHub, my suspicion is that this is because they're being starved for resources, not incompetency or maliciousness.

This (IMO) points to a perverse reality: things need to get worse before they can get better. In other words, Microsoft probably needs to feel more pain (in the form of negative revenue pressure) before they take their own platform responsibilities (vis a vis not distributing malware) seriously.

We say this play out recently with improvements to GitHub Actions security, I expect we'll see the same here.

(Edit: to be absolutely clear, I have first-hand experience that GitHub's security folks work extremely hard, and are often doing the kinds of invisible, thankless "deck-swabbing" work that nobody even thinks about. They're just under-resourced.)

nickphx•23m ago
"security" is a cost-center, it does not generate revenue. Incidents from lack of "security" need to have a greater impact on revenue before the typical corporate entity spends money.
ofjcihen•22m ago
So far this year 40% of my contracts have been a recovery from a Shai Hulud like attack. That’s in the area of 750k profit and more spent by the companies.

The instability and security issues that come of relying on the software supply chain has been pointed out for around 30 years. Seriously, go look. Multiple articles have pointed out the problems we’re seeing.

I used to ask the same question on behalf of clients but after multiple non-answers and silence my response now is just put something between you and GitHub that you can control.

dasil003•19m ago
The only reason they deleted the static list of identified repositories was because of the negative PR of hitting HN. Although I have no affiliation with GitHub, I would imagine that no one with any resource allocation power is incentivized to take action to police public repos in general. The reality is that as soon as they start, it will become an arms race, and they will have to deal with false positives and the community headache that comes with that. They also have bigger fish to fry with the effect the influx of AI slop is having to their open source bread and butter. The two problems are not entirely disjoint, and I suspect solutions won't come until the problem gets much worse, and the agentic coding space stabilizes a bit more.
sscaryterry•19m ago
GitHub today isn't GitHub from the early-mid 2010's. Today it is a Microsoft side-gig, something they bought simply because nobody wanted theirs. But, GitHub makes good money, and turns out they're a great source of training material.

They're just limping along. In reality, I think Microsoft wants to kill the GitHub brand, they're just doing it slowly, feeding poison.

PunchyHamster•17m ago
And embrace extend extinguish lives on
jmward01•12m ago
This is like US healthcare. Almost nobody in US healthcare starts of evil. Almost none of the processes start with a clear evil intent. The problem is that the only real reward is money so the processes and people that generate money stay while the processes and people that merely made things better, but didn't increase revenue, slowly fade away.

Does GH get money for taking these actions? Do they have any monetary incentive other than 'their reputation', which clearly isn't changing usage, to improve? Maybe the best question here is why is it that after a lot of black eyes on data usage, reliability and monitoring aren't people switching. What keeps you using GH after stories like this?

I have a suggestion. PyPi and similar package managers should start publishing security warnings about the hosts of projects. That in turn can eventually lead to bans of packages from generally insecure places. Maybe if we start seeing 'WARNING: projects from github.com may contain malware!' after doing pip install XXX MS will start listening.

woodruffw•4m ago
> PyPi and similar package managers should start publishing security warnings about the hosts of projects. That in turn can eventually lead to bans of packages from generally insecure places. Maybe if we start seeing 'WARNING: projects from github.com may contain malware!' after doing pip install XXX MS will start listening.

PyPI goes out of its way to not be an arbiter of package quality or security. PyPI really doesn't want people assuming those things based on presence, since it's (1) an open index, and (2) the resources needed to make those kinds of determinations at PyPI's scale are several orders of magnitude greater than what PyPI actually has access to.

(This is different from PyPI removing malware based on user reports, which does happen. But that's a reactive task and not one that comes with any sort of blanket guarantee.)

mschuster91•9m ago
> Why did they stop and take no further action?

Simple: further action was not requested in the Jira ticket, and what is not in a Jira ticket is not getting done because the team responsible for doing the needful is already overloaded with other crap.

Or maybe because the higher-up whose authorization is needed to go on a few days worth of deep dive other than doing exactly what is asked and accounted for in tickets doesn't have the time for a few minutes to explain to them why it is needed, or the higher-up needs authorization from finance or legal first.

Obvious /s, but I wouldn't be surprised at all if this is exactly what happened. If I were to guess, the "legal" is my biggest suspicion - if a provider reacts on notice of illegal/harmful content, they're just fulfilling legal obligations. But if they go and actively wade through the archives to find more incriminating content, that might be construed as Github doing active moderation of their own, leading to a loss of pure content hoster legal protections.

Anthropic versus the entire tech industry

https://twitter.com/DavidSacks/status/2081470576653406328
1•delichon•1m ago•0 comments

We have proof automation now

https://www.imperialviolet.org/2026/07/26/zstd-lean.html
1•zdw•1m ago•0 comments

Show_HN: ~bhyvxe/hypermpd – hypermpd emerges with competitive features vs. MPD

https://git.sr.ht/~bhyvxe/hypermpd
1•icmpkitty•2m ago•0 comments

Multiway Turing Machines (2021 pre-ai)

https://bulletins.wolframphysics.org/2021/02/multiway-turing-machines/
1•marysminefnuf•5m ago•1 comments

The Half We Don't Measure

http://rishigoomar.com/the-half-we-dont-measure
1•rgoomar•6m ago•0 comments

A small CLI for running isolated GenesisDB containers behind one HTTPS proxy

https://github.com/genesisdb-io/genesisdb-orchestrator
5•patriceckhart•10m ago•0 comments

Microsoft's new TPM rule won't stop your pirated Windows from working

https://www.windowslatest.com/2026/07/27/you-heard-wrong-microsoft-isnt-ending-pirated-windows-11...
1•Abhijith__MB•17m ago•0 comments

Israeli settlers set fire to mosques, cars and farm land in West Bank

https://www.bbc.com/news/articles/cjrv77gl4deo
3•tcp_handshaker•17m ago•0 comments

How Web Browsers Work

https://arnauc.me/blog/how-browsers-work/
3•ErenayDev•22m ago•0 comments

Plasma Tunnels Reveal How Dying Satellites Fall to Earth

https://spectrum.ieee.org/space-debris-atmosphere-burn-up
1•marc__1•23m ago•0 comments

The fifth dimension could be possibility

https://gingerjuice.club/article/the-dimensional-stacking-principle-a-geometric-framework-for-the...
2•streetai•23m ago•1 comments

Ask HN: What's the best hands-on path to learn ML inference infrastructure?

2•censor5•26m ago•1 comments

AI is set to drive surging electricity demand from data centres (2025)

https://www.iea.org/news/ai-is-set-to-drive-surging-electricity-demand-from-data-centres-while-of...
2•dredmorbius•29m ago•0 comments

Making a cache cluster more effective

https://basta.substack.com/p/making-a-cache-cluster-more-effective
1•tyre•32m ago•0 comments

Gary Stevenson to quit YouTube channel, citing health concerns

https://www.theguardian.com/business/2026/jul/26/gary-stevenson-to-quit-youtube-channel-garys-eco...
1•jimnotgym•35m ago•0 comments

CuNi v01

https://cuni-studio.fly.dev/
1•agentrider•35m ago•0 comments

Why Everyone Got Spain's Blackout Wrong [video]

https://www.youtube.com/watch?v=Rb9oWsQuENE
1•pepperoni_pizza•40m ago•0 comments

An Open-Source Static AI Capability and Risk Analyzer – First Week Report

https://github.com/ikaruscareer/SafeAI
1•ikaruscareer•42m ago•0 comments

1877–1878 El Niño event

https://en.wikipedia.org/wiki/1877%E2%80%931878_El_Ni%C3%B1o_event
2•simonebrunozzi•42m ago•0 comments

Doom for PC-FX [video]

https://www.youtube.com/watch?v=wUd5IGMbe48
1•cedel2k1•43m ago•0 comments

Buying a Home Has Gotten Harder for Young Adults in Most U.S. Metro Areas

https://www.pewresearch.org/short-reads/2026/06/24/buying-a-home-has-gotten-harder-for-young-adul...
1•karakoram•43m ago•0 comments

PGSimCity – an explorable 3D model that shows how Postgres works

https://github.com/NikolayS/pgsimcity
1•samokhvalov•43m ago•0 comments

Big Tech accused of stonewalling European social media researchers

https://www.wired.com/story/european-researchers-want-to-study-social-medias-harms-but-cant-get-t...
3•logickkk1•47m ago•0 comments

Wright's Law Edges Out Moore's Law in Predicting Technology Development (2012)

https://spectrum.ieee.org/wrights-law-edges-out-moores-law-in-predicting-technology-development
1•simonpure•52m ago•0 comments

Coding Has Agents. Trading Has One

https://henryzhang.substack.com/p/coding-has-agents-trading-finally
1•henryzhangpku•52m ago•0 comments

Simulate cassette tape audio profiles using FFmpeg

https://github.com/AARomanov1985/Audio-Cassette-Simulation
2•xterminal•52m ago•1 comments

Show HN: Infinite Jigsaw Game

https://infinitejigsaw.com
3•impostervt•53m ago•0 comments

The Sustained Performance Gap: Why Laptop Specs Don't Tell the Whole Story

https://psyll.com/articles/technology/tech-gadgets/thermal-throttling-why-laptops-lie-about-speed
1•lucasfletcher•53m ago•0 comments

The Lego Problem, Revisited

https://seths.blog/2026/07/the-lego-problem/
1•herbertl•55m ago•0 comments

Most Americans Say Financial Milestones Are Harder for Today's Young Adults

https://www.pewresearch.org/short-reads/2026/07/17/majorities-of-americans-say-key-financial-mile...
5•karakoram•58m ago•0 comments