Hacker News new | ask | show | jobs
by wlll 1490 days ago
I'd still love to get a response to the comment I made on my submission (https://news.ycombinator.com/item?id=31450100)

> I'd love to hear from someone at GitHub (anonymously or not) what they've done to be satisfied with action Heroku have taken that would allow the integration to be turned back on. My confidence in Heroku to give me accurate information on this is low.

As far as I can tell from Heroku's communications they:

- Have no idea how the attacker gained access

- Have no idea if the attacker still has access

If they do know these things then I've not seen them say so.

1 comments

It's nitpick, but I'll note that it follows that you wouldn't know if the attacker has access if you don't know how they gained it.
They could use the access again without revealing how they got it. Double nitpick!