TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Zapier says someone broke into its code repositories and may have customer data

56 点作者 OmarShehata2 个月前

4 条评论

pm902 个月前
This is the most mealy mouthed disclosure ever. Shame on them.<p>How can an employees 2FA misconfiguration lead to someone else accessing these repos? 2FA setups are supposed to prevent this sort of thing. If I had to guess it was someone on the “devops&#x2F;sre&#x2F;infra” team that usually has god mode access that were setting up some integration and disabled 2FA for testing or something for a test account … but it would have had to be disabled for a while for the attacker to get access.<p>What kind of customer data were they storing in their repository? Were they storing raw webhook data&#x2F;API responses in github gists or something (wouldn’t put it past them).<p>As a sidenote, Ive worked with folks from zapier and Im not impressed with their engineering. Their integrations are super fucking brittle, its like it was designed by toddlers. I would not depend on them for any kind of business critical functionality.
评论 #43220470 未加载
评论 #43229295 未加载
评论 #43219855 未加载
mvdtnz2 个月前
Why is there customer data in code repositories?<p>&gt; The customer data had been “inadvertently copied to the repositories for debugging purposes,” according to an email obtained by The Verge.<p>What on earth? How is this possible?<p>&gt; we audited the contents of the repositories, and we found that in isolated instances, certain customer information had been inadvertently copied to the repositories for debugging purposes.<p>&quot;instances&quot;. Plural.
Kye2 个月前
I never used it because I could never figure out the pricing. Fortuitous.
评论 #43219476 未加载
评论 #43219567 未加载
linwangg2 个月前
Zapier’s breach shows that even big SaaS companies can accidentally expose customer data in code repos. If they got hit due to a 2FA misconfiguration, how many other companies are at similar risk without knowing?
评论 #43221425 未加载