Hacker News new | ask | show | jobs
by crote 23 days ago
That's the thing: according to the post he offered it, but the offer wasn't accepted. They stayed on Github, and it was the Github repos which were compromised. They did entertain his desire to let him host a read-only mirror - but that's hardly critical, and having complete strangers mirroring Linux ISOs or package repos has been a thing for ages.

The post makes zero mention of him ever joining or being part of the core infra ops team. So where did the admin access come from?

1 comments

I don't know if this is the case here, but I have witnessed several instances in the open source community where someone offer to help with a boring/fastidious task and some temporary admin privileges are granted to them in order to make it easier.

But then, temporary become permanent because either the task never complete or because people just forgot. It's always when the problems start to appear that the temporary privileges are finally revoked.

In my case the problems were mostly due to incompetence, but sometimes a malicious action happens...