Monday, January 12, 2015

DevOoops: Spoofing GitHub Users

The user information that gets loaded with a commit is locally controlled metadata.

What this means is that you can submit a commit as any user you please. Examples:





It even adds the GitHub icon automagically :-)

This was also discussed here:
https://news.ycombinator.com/item?id=7792026

No comments:

Post a Comment