TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Did GitHub Suspend Egor Homakov account?

329 pointsby VuongNabout 13 years ago
I hope this isn't the beginning of something ugly with GitHub.

18 comments

vascoabout 13 years ago
Suspending him only shows that if a vulnerability exists (and they always do) in the future people won't go about it so openly because what they'll get for their troubles will be an account suspension. The guy could have done real harm if he kept silent and used it maliciously, chose not to, and got suspended. Github should pay him for finding the vulnerability instead!
评论 #3664139 未加载
评论 #3664516 未加载
评论 #3664773 未加载
评论 #3664799 未加载
ricardobeatabout 13 years ago
Well, this is not exactly what I expected to find in the ToS:<p><i>GitHub, in its sole discretion, has the right to suspend or terminate your account and refuse any and all current or future use of the Service, or any other GitHub service, for any reason at any time. Such termination of the Service will result in the deactivation or deletion of your Account or your access to your Account, and the forfeiture and relinquishment of all Content in your Account. GitHub reserves the right to refuse service to anyone for any reason at any time</i><p>That means my company's code can be wiped out by GH at any time, for any reason. Please don't hurt me :(
评论 #3664102 未加载
评论 #3664069 未加载
评论 #3664130 未加载
评论 #3664209 未加载
评论 #3664133 未加载
评论 #3666226 未加载
ricardobeatabout 13 years ago
Remember when Zed Shaw took down GitHub for purely personal reasons, disturbing service for millions? I don't remember him getting suspended, his account is live and well at <a href="http://github.com/zedshaw" rel="nofollow">http://github.com/zedshaw</a><p><a href="http://sheddingbikes.com/posts/1306816425.html" rel="nofollow">http://sheddingbikes.com/posts/1306816425.html</a>
评论 #3664717 未加载
T-Winsnesabout 13 years ago
So if I got this right, this is the order of how things happened.<p>1. Egor finds a vulnerability and reports it. <a href="https://github.com/rails/rails/issues/5228" rel="nofollow">https://github.com/rails/rails/issues/5228</a><p>2. It gets ignored and he is being called a troll.<p>3. He proves that he was right by doing a harmless commit to to the rails master repo.<p>4. The vulnerability gets fixed quickly as it got the focus of the community.<p>5. His account gets suspended<p>Not sure I agree with the suspension.
评论 #3664557 未加载
abaloneabout 13 years ago
He has a get out of jail free card.<p><a href="http://homakov.blogspot.com/2011/07/octocat-tattoo.html" rel="nofollow">http://homakov.blogspot.com/2011/07/octocat-tattoo.html</a>
评论 #3666351 未加载
chbrownabout 13 years ago
Why is someone who can hack Github working for $30/hr on oDesk? @Egor, quit selling yourself short!
评论 #3665149 未加载
eliabout 13 years ago
Not sure that's the call I would have made, but hacking into other users' accounts does seem like a pretty valid reason for account termination.
评论 #3664002 未加载
评论 #3664035 未加载
评论 #3663999 未加载
kpanghmcabout 13 years ago
What's to prevent Egor from setting up a new account and using it to exploit the vulnerability he's found?
评论 #3664165 未加载
评论 #3664101 未加载
评论 #3664086 未加载
评论 #3666234 未加载
heimidalabout 13 years ago
His account has been reinstated, Github has patched their service, and the Rails team has committed a patch with new defaults. All in less than eight hours. Let's move on.
评论 #3664807 未加载
评论 #3664882 未加载
VuongNabout 13 years ago
Is this supposed to prevent him from doing further damage? I hope this isn't the beginning of something ugly with GH.
评论 #3664061 未加载
评论 #3664017 未加载
sriramkabout 13 years ago
I'm sorry but I have to defend Egor here. Here's how you actually report a vulnerability, demonstrated by dfranke here on HN -&#62; <a href="http://news.ycombinator.com/item?id=639976" rel="nofollow">http://news.ycombinator.com/item?id=639976</a><p>What Egor did was to violate sensible disclosure rules. He should have contacted GitHub in private, created a test repo and demonstrated his exploit there, rather than impersonate users and compromise multiple accounts.<p>If I was in Github's shoes and I was trying to figure out what damage was done, the first step would be to suspend the account doing the damage to make sure no further surprises were headed my way.
mtkdabout 13 years ago
They should be hiring him.
narsilabout 13 years ago
What I would like to know is if this is permanent or just till github completes their security audit. It doesn't seem like homakov intended or caused any real harm, although it was a bit immature to draw attention to the vulnerability that way.
评论 #3664122 未加载
xpaulbettsxabout 13 years ago
In the future, if folks find vulnerabilities in GitHub, please report them via an Email to security@github.com or support@github.com.
评论 #3664157 未加载
评论 #3664486 未加载
评论 #3664701 未加载
rurounijonesabout 13 years ago
His account has been unsuspended.<p><a href="https://github.com/rails/rails/commit/b83965785db1eec019edf1fc272b1aa393e6dc57#commitcomment-1041295" rel="nofollow">https://github.com/rails/rails/commit/b83965785db1eec019edf1...</a>
espeedabout 13 years ago
Don't suspend him -- hire him.
aquarinabout 13 years ago
This is really childish attitude. Egor grow up.
评论 #3664219 未加载
krobertsonabout 13 years ago
He clearly violated their Terms Of Service. If you like and enjoy a service, exploiting it to prove a point is not the way to do it. It takes no time to spot the clause about exploiting the service.<p>Legally, it wouldn't be good to have a TOS and then not enforce it. You never how that could bite you later on if you get dragged into a dispute.<p>All this "they should give it back when they're done" is pointless. You can't reward stupid behavior.
评论 #3664084 未加载