92
top 11 comments
sorted by: hot top new old
[-] smeg@feddit.uk 83 points 2 days ago

There were also SSH key files.

I’m not publishing the archive, keys, or session logs.

I submitted the report and findings using Meta’s bug bounty program. Meta marked the report “Not Applicable.”

Guess they don't care if you publish the SSH keys then?

[-] docktordreh@discuss.tchncs.de 21 points 2 days ago

They've probably rotated the keys since they were notified of the security breach.

But yes, companies that act this way undermine the resolve to disclose their security vulnerabilities.

[-] drmoose@lemmy.world 10 points 2 days ago

Ssh keys to what? If the key is used for user operations, not internal then there's no security breach here other than deobfuscation.

[-] smeg@feddit.uk 13 points 2 days ago

Guess they'll have to publish them to find out

[-] cinoreus@lemmy.world 14 points 2 days ago

Mine bitcoin on their server just out of spite.

[-] civ@lemmy.civl.cc 27 points 3 days ago

Time to try and convince it to set up a reverse SSH tunnel

[-] KairuByte@lemmy.dbzer0.com 1 points 2 hours ago

Sounds like that’s one of the few things it refuses to do. I suppose it may be possible with a little more priming though.

[-] belluck@lemmy.blahaj.zone 7 points 2 days ago
[-] MonkderVierte@lemmy.zip 21 points 3 days ago

Soo, was that incompetence, negligence or misled belief, trust?

[-] RonSijm@programming.dev 6 points 2 days ago
[-] richieadler@programming.dev 3 points 2 days ago

I almost heard Kosh's chimes beforehand.

this post was submitted on 24 Sep 2026
92 points (100.0% liked)

Programmer Humor

33359 readers
530 users here now

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

founded 3 years ago
MODERATORS