TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Tencent WeChat is now a GitHub secret scanning partner

154 点作者 5amdotis超过 2 年前

18 条评论

dang超过 2 年前
Lame corporate partnership announcements aren&#x27;t on topic for HN, and the wording here looks to have been a boilerplate malfunction: <a href="https:&#x2F;&#x2F;hn.algolia.com&#x2F;?dateRange=all&amp;page=0&amp;prefix=true&amp;query=now%20a%20github%20secret%20scanning%20partner&amp;sort=byDate&amp;type=story" rel="nofollow">https:&#x2F;&#x2F;hn.algolia.com&#x2F;?dateRange=all&amp;page=0&amp;prefix=true&amp;que...</a>.<p>Poor functionary creates political incident with humble template...sounds like a Gogol short story. &quot;but it worked great for redirect.pizza!&quot;<p>Btw I assume this recent thread was about the same feature:<p><i>Secret scanning is now available for free on public repositories</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34007637" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34007637</a> - Dec 2022 (70 comments)
gpjanik超过 2 年前
This is simultaneously an epic clickbait and a very accurate represenatation of reality that is very boring and not shocking at all. Congrats to whoever wrote the line.
nottorp超过 2 年前
Brilliant title for the article.<p>Even though I&#x27;m a paid github customer, I had no idea they had a program called &quot;secret scanning&quot; and that it&#x27;s actually beneficial.<p>So I obviously assumed they&#x27;re letting China scan my private repos.<p>They really need to work on wording.
评论 #34064825 未加载
评论 #34067090 未加载
评论 #34066012 未加载
评论 #34066564 未加载
评论 #34067097 未加载
评论 #34068799 未加载
评论 #34067330 未加载
评论 #34065203 未加载
trompetenaccoun超过 2 年前
To everyone portraying this as harmless and as Wechat just looking for security breaches: Tencent itself is the security breach. Not only can Chinese ppl not sign up without providing a phone number, just to get a SIM card they now take your government ID, a picture of your face and a fingerprint! Xi is making absolutely sure that every single internet user is IDed and has their conversations tracked on apps like Wechat. Whatsapp, Signal &amp; co are banned.<p>These &quot;leaked&quot; secrets GitHub forwards might be dissidents getting access without being tracked. It might not be a WeChat secret at all who knows? They&#x27;re not a trustworthy partner, nothing should be shared with this company.<p>And to the folks saying it&#x27;s public information and they already have it: That makes no sense, then they don&#x27;t need GitHubs help. Obviously GitHub is supporting their scanning efforts here.
评论 #34067335 未加载
评论 #34067075 未加载
评论 #34068530 未加载
评论 #34067391 未加载
评论 #34067091 未加载
评论 #34070316 未加载
评论 #34067156 未加载
评论 #34067777 未加载
andrewaylett超过 2 年前
This is part of <a href="https:&#x2F;&#x2F;docs.github.com&#x2F;en&#x2F;developers&#x2F;overview&#x2F;secret-scanning-partner-program" rel="nofollow">https:&#x2F;&#x2F;docs.github.com&#x2F;en&#x2F;developers&#x2F;overview&#x2F;secret-scanni...</a><p>It lets WeChat revoke tokens that GitHub finds in public repositories.
评论 #34067073 未加载
255超过 2 年前
Optics of this article could be improved.<p>However, this is already a well established and useful thing. When you publish your AWS (for example) secrets to your public repo, it will scan it and stop it leaking before damage can be done. This is just the same for another service.
评论 #34067121 未加载
redleader55超过 2 年前
It would be nice of Github if they could publish a transparency repo with all the partners and all the regex along with this initiative. I see a lot of people in this thread worried that &quot;China gets their data&quot; and this transparency repo could alleviate some of that.
评论 #34064832 未加载
评论 #34064724 未加载
评论 #34065261 未加载
评论 #34067138 未加载
评论 #34066077 未加载
nomercy400超过 2 年前
Wait, what?<p>So any string (which Github deems an access token) is forwarded to Tencent?<p>Or will Tencent share all their current access tokens with github?
评论 #34064417 未加载
评论 #34067774 未加载
luc_超过 2 年前
They had to have titled it like this on purpose. I almost spat out my tea.
gbtw超过 2 年前
What does a wechat token look like, as in can i scan my repo to see if i do not leak anything unwanted to wechat?<p>That said, could one also generate tokens and essentially DDOS the wechat org by having them inform their customers unnecessarily?
galuggus超过 2 年前
Isn&#x27;t this information already public?
评论 #34065930 未加载
nintendo1889超过 2 年前
They should scan for Bitcoin seeds too.
评论 #34066354 未加载
olksdhdkdbdj超过 2 年前
1. If their regex matches my company token, will it be send to them? 2. Can Wechat update the token regex to collect tokens from competitor company? 3. Can Tencent collect information about applications that use wechat?
Traubenfuchs超过 2 年前
Why is everyone upset? This is a good thing.<p>Where are you seeing a privacy or security risk?
评论 #34065250 未加载
评论 #34065124 未加载
评论 #34065221 未加载
whoevercares超过 2 年前
It’s absolutely shocking to observe how hostile HN is to Chinese affairs. While in real life many must have collaborated A LOT with Chinese engineers &amp; managers. Are you worry about bias bleeding into real life? I’m indeed worried as a Chinese immigrant working in tech
评论 #34067334 未加载
评论 #34066804 未加载
评论 #34073839 未加载
munhitsu超过 2 年前
Just make sure your secret doesn’t look like a WeChat secret
okokwhatever超过 2 年前
Is this a joke? I&#x27;m not laughing.
评论 #34064074 未加载
lopkeny12ko超过 2 年前
Just a reminder that Git is a decentralized protocol and Github is merely a (poor) implementation of it. Microsoft-Github have been increasingly introducing antifeatures, just one of which is sending repository contents to China automatically.<p>For the last few years I&#x27;ve been running Git off my own servers with a cgit [0] frontend, and couldn&#x27;t be happier.<p>[0] <a href="https:&#x2F;&#x2F;git.zx2c4.com&#x2F;cgit&#x2F;about&#x2F;" rel="nofollow">https:&#x2F;&#x2F;git.zx2c4.com&#x2F;cgit&#x2F;about&#x2F;</a>
评论 #34066190 未加载
评论 #34066323 未加载