Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Fair point. But even if it had warned me that the site would be allowed to star repos, I would consider that such a low-risk innocent thing that I would likely just ignore it. Until reading this post I would have never considered how that could be abused.


Well, github does need some more fine-grained permissions.

Another stupid thing I found is about GH organization access.

If org didn't had Third-part application access policy set to restricted, THERE WAS NO OPTION TO NOT GIVE PERMISSIONS TO A TOKEN.

As in I HAD to give permission for repos for org I was in if I wanted to give app permissions for my personal repos.

Only after enabling that option in org I was given an option to not proliferate permissions to org I'm in. I happened to have admin access so I just enabled that option but if someone didn't it would be real easy for some user to give too much permissions on accident...

It really feels like those permissions should be at per-repo level. App should never need to have access to all of them, even if it asks for all there should be option to give limited access


See, my first question would be "WHY?!".

Every unnecessary permission is suspicious until proven not to be, and will at the very least be used in ways that I would not, if not even actively to my detriment.

Your android flashlight demanding to read your contacts is trying to scam you ( and worse, your contacts through your negligence), not just ask for some harmless permission you needn't care about.


Hence why the Google Play store reviews app permissions requests, just like Google OAuth app registration does, and just like GitHub could do...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: