Hacker News new | ask | show | jobs
by flylib 3135 days ago
I mean they don't say how they accessed the GitHub repo or whether there was a vulnerability in Github itself that allowed access
1 comments

I assume it was password reuse from one of their engineers or something similar. If you could compromise GitHub itself there would probably be higher value targets (source code for upcoming AAA games, Coinbase, government organizations, etc.)
> If you could compromise GitHub itself there would probably be higher value targets (source code for upcoming AAA games

I'm intrigued. Why would that be a higher-value target?

AAA games have budgets in the millions. Threatening full release would likely net you much more than a few hundred thousands, and without requiring any secondary attack.
Are many (any?) AAA studios using private Github repos for development?
I mean 100k is a lot of money and there is no saying they didn't hit those guys also