Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They don't say what the timeframe for this issue is. Have passwords been logged for the last 6 months? Last 3 years? Was this a bug found and fixed last year, and only now are they reporting it?


The article does say:

> that they were exposed for “several months.”


Same as Github it seems.

I wonder what library was used, and which other companies use it which hasn't told their users. That'd let us know who isn't as transparent...


We must assume the worst.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: