TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Heroku April 2022 Incident Review

118 点作者 glennericksen将近 3 年前

3 条评论

ezekg将近 3 年前
&gt; We began investigating how the threat actor gained initial access to the environment and determined it was obtained by leveraging a compromised token for a Heroku machine account. We determined that the unidentified threat actor gained access to the machine account from an archived private GitHub repository containing Heroku source code. We assessed that the threat actor accessed the repository via a third-party integration with that repository. We continue to work closely with our partners, but have been unable to definitively confirm the third-party integration that was the source of the attack<p>So they still don&#x27;t know how it happened.
评论 #31743300 未加载
评论 #31745632 未加载
评论 #31743310 未加载
评论 #31743430 未加载
btown将近 3 年前
&gt; Additionally, according to GitHub, the threat actor accessed and cloned private repositories stored in GitHub owned by a small number of our customers. When this was detected, we notified customers on April 15, 2022, revoked all existing tokens from the Heroku Dashboard GitHub integration, and prevented new OAuth tokens from being created.<p>Various customers received an email from Heroku on April 15 saying &quot;We value transparency and wanted to notify you of an incident we&#x27;re actively investigating that may lead to unauthorized access to your GitHub repositories connected to Heroku.&quot;<p>The way this incident review (to call it a post-mortem would be an insult to those who write good post-mortems) phrases things, customers have no way of knowing if that email meant they were one of those &quot;small number of customers&quot; or not. And what is a small number, anyways? Is 49% of customers a small number of customers? It&#x27;s an absurd situation.
drusepth将近 3 年前
Side note on Heroku: they&#x27;ve been very aggressively upgrading old app dependencies this week (I&#x27;ve had ~9 apps go down for mandatory Postgres maintenance in the last 24h, with almost no notice for some of them). With how little information they&#x27;ve given regarding this incident, I can&#x27;t help but wonder if it&#x27;s related.