Hacker News new | ask | show | jobs
by maryjpenny 1509 days ago
Heroku you say? Could it be related to this?

https://github.blog/2022-04-15-security-alert-stolen-oauth-u...

“The applications maintained by these integrators were used by GitHub users, including GitHub itself.”

1 comments

Very unlikely to be honest, especially that there's no private* data present in Git.io.

* Technically the links are not publicly listed, which might jeopardise some obnsscure but technically-available repository, but it doesn't store private data.

Historical DNS TXT shows that git.io was (and probably still is) hosted on Heroku.

From the original post: “due to the security of the links redirected with the current git.io infrastructure”

What does “security of the links” even mean? Disclosure? Tampering?

Adversaries submitting nasty stuff and have it behind the git brand.