Comment by keyle
Comment by keyle 7 hours ago
Press Win+R, CTRL+V <enter>
From captcha to gotcha.I could see junior developers falling for this. Hey it's Github, it's legit right? We get security notifications every second months about some lib everyone uses etc.
"Oh look, captcha by running code, how neat!"
I don't think webpages should be able to fill your copy/paste buffer from a click without a content preview. They made it requiring a user action, such as clicking, thinking that would solve the problem but it's still too weak. That's problem number 1.People need to stop actioning any links from emails and/or believing that any content in an email has legitimacy. It doesn't. That's problem number 2.
Problem number 3, Windows still let you root a machine by 1 line in powershell? What the @$$%&%&#$?
Github might need to stop people putting links in issues without being checked by automated services that can validate the content as remotely legitimate. They're sending this stuff to people's email, don't tell me they're not aware this could be used for fishing! That's cyber security 101, in 2015.
Finally, Github, in being unable to act on the above, may need to better strip what they email to people, and essentially behave more like banks "you have a new issue in this repository..." and that's that. You then go there, there is no message, ok great. That would have taken care of this issue...
It seems Github needs to graduate a bit here.
"I could see junior developers falling for this" - I can see all sorts fucking up, not just juniors. It is the way of things.
"I don't think that...". I think that you have to train your troops effectively in what is harmfull.
"Windows" - yes. I have been asked by at least two of my employees to get them away from Windows. I'll do my best. Its been a long running project but I will succeed.