Hacker News new | ask | show | jobs
by galuggus 1275 days ago
Isn't this information already public?
1 comments

Which information?

Your wechat tokens, no that should never be public, hence why this feature exist?

That github reports that you leaked your wechat tokens, it was announced just recently, hence the post.

That github is giving wechat your secrets, not that is not what this is about although the article title would make you think that.

GitHub is indeed giving WeChat our information, but only when it looks just like WeChat secrets, and only once it's already publicly leaked (any leaked via private repo instead goes to the repo admin).

So technically the answer to GP is 'yes'.

I dont think you can claim an API key is your information. It is quite by definition information created by WeChat and Github is sharing only that with them a few minutes before it shares it with bad actors.
It's not necessarily created by WeChat. It just needs to follow the same pattern as a key generated by WeChat (thus all the .* regex jokes here). It could very well be anyone's information, but information about to be public anyway (making "yes" the answer to the question "Isn't this information already public?").