Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Neither Heroku nor GitHub are addressing the key part of this - if Heroku's Dashboard apps were compromised, and thus access was given to connected GitHub repos for download - were the secrets in the Heroku config vars for the app also visible? That is the nightmare scenario for the affected app's owners.


Heroku/SalesForce updated their status on https://status.heroku.com/incidents/2413:

"Salesforce continues to investigate this incident in coordination with GitHub and our retained third-party breach vendor. Once we identify how the threat actor gained access to customers' OAuth tokens, we will immediately take appropriate actions."

Sounds like they simply don't know yet how the actor got access and what else was exposed.


Looks like it's addressed in an update to https://status.heroku.com/incidents/2413

The compromised tokens could provide the threat actor access to customer GitHub repos, but not customer Heroku accounts

While the situation can get worse, this token alone may not be enough...


The token isn’t nearly as concerning as what it implies: this stolen token would have been stored in heroku’s DB. However it got out likely has broader implications.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: