this post was submitted on 01 Feb 2024
126 points (97.7% liked)

Technology

59414 readers
2618 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Comment

I hope nobody loses their shirt over this.

Summary

  • Sensitive data exposed: Internal code, infrastructure diagrams, passwords, and other technical information were publicly accessible on GitHub for months.
  • Source unclear: Unclear if an outside hacker or Binance employee accidentally uploaded the data.
  • Potential risk: Information could be used by attackers to compromise Binance systems, though Binance claims "negligible risk".
  • Data details: Included code related to passwords and multi-factor authentication, diagrams of internal infrastructure, and apparent production system passwords.
  • Binance response: Initially downplayed the leak, later acknowledged data was theirs but downplayed risk.
  • Current status: Data removed from GitHub via copyright takedown request.
  • Unclear if any malicious actors accessed the data.
top 6 comments
sorted by: hot top controversial new old
[–] Rooki@lemmy.world 25 points 9 months ago

Wow, just wow.....

[–] notannpc@lemmy.world 14 points 9 months ago* (last edited 9 months ago)

I look forward to the future article “billions stolen from crypto exchange binance”

[–] shortwavesurfer@lemmy.zip 8 points 9 months ago

Again, centralized exchanges are like public toilets. Get in, do your business, and get the fuck out. This is a good argument against KYC as well, since if they don't have data, they can't leak data.

[–] Petter1@lemm.ee 6 points 9 months ago (1 children)

Was the github repo archived?

[–] SinningStromgald@lemmy.world 16 points 9 months ago

It was on the open net. I am sure it is somewhere.

[–] TWeaK@lemm.ee 3 points 9 months ago