Hacker News new | past | comments | ask | show | jobs | submit | joshdotsmith's comments login

Yes, a forum of people interested in software development might care that most new repositories created on the most popular website for sharing open source code will end up spoofed and sharing malware?


As I wrote in this issue, I am exhausted. Microsoft has plenty of money to handle issues like this and chooses not to do so. I have spent hours now reaching out to GitHub in vain, tracking down people affected, and trying to figure out how to get someone to give one single flying fuck.

So what the hell. Let’s make the CISO’s slideshow intro to GitHub popular.


Thanks, I just find it wild that Microsoft appears wholly uninterested in policing what seems like a huge legal liability to their business. I’ll start reaching out to as many journalists as I can with what I’ve got. They seem a little overwhelmed from the two I’ve already reached out to.

Edited to add: I’ve also been hoping that I could avoid giving the attackers too much of a heads up, but at this point the risk is higher that nothing gets done about it at all.


SEEKING WORK | REMOTE | Baltimore, MD, US

Product-focused full stack developer with 14 years of experience. Hired on "Seeking freelancer" before – happy to provide the reference!

Work with early stage startups, often seed or pre-Series A. Recent experience in enterprise on various teams at Credit Karma.

Recent work: https://keyhero.io - designed / built everything

--

Skills:

- Ruby / Rails, Elixir / Phoenix, Node.js

- React, Next.js, some Vue + Elm

- React Native / Expo, Swift

- CSS, HTML, Tailwind

- Design, UI, UX, Figma

- Postgres, MySQL, Redis

- AWS, DO, Fly.io, Render

- TDD / BDD

- SaaS + consumer metrics and conversion rate optimization

--

Email: josh@coderly.com

GitHub: https://github.com/joshsmith


Thank you for sharing this! Shared it with my wife over breakfast.


I'm also curious about this. We were accepted into Stripe Atlas but too late – we ended up forming our company while on the waiting list and couldn't partake.


Watsi only funds its operations via tips. 100% of your non-tip donations go to funding treatments.


If your non-profit needs any help with any of the software side (that can be made open source) let me know and I'd be happy to see how I can help.


Looks fantastic. Do you have plans to support additional languages?

This would be particularly useful in open source.


I don't think he understood the question. "For 30" sounds like he meant "$30 per hour" and not "on net 30 terms."


Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: