TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Tips for finding security issues in GitHub projects

115 pointsby geekraxover 7 years ago

3 comments

latchkeyover 7 years ago
Thanks for sharing! Seems like a company that does this as an automated service (for private orgs/repos) would be $.
评论 #15422734 未加载
_asummersover 7 years ago
What does the author mean about timing attacks on HMACs with Array.equals? Does HMAC leak info and is it subject to timing attacks if you HMAC on both sides before doing equality checks? Does he mean for e.g. session cookies?
评论 #15423647 未加载
reconbotover 7 years ago
Some of the links are bad but this is a great list of things to keep in mind when seeing where your work is with regards to security.