Hacker News new | ask | show | jobs
by iuri1 1718 days ago
Since the main leaked files are from github, I'm assuming they got it from one of the many reported github auth flaws which don't get fixed and allows access to private repositories. Or more unlikely, via someone getting sloppy with their laptop.

Now I wonder if the commit history has database dumps or sensitive information, which is a common practice, or if any twitch servers have been accessed through a breach or privileged information found in some of their source code.

2 comments

I'm pretty sure a company of Twitch's size uses on-premise GitHub.
Yup, and AWS Code*
Which Github auth issues are you referring to?