Posted by mooreds 14 hours ago
People like Nadella must think that developers are the weakest link: Extreme tolerance for Rube Goldberg machines, no spine, no sense of self-protection.
I'll cancel my paid GitHub account though.
First of all, any subdomain system domain is already a bit phishy because you need to somehow parse whether github.io is officially part of github.com and not say something like git-hub.xyz by a phisher or whatever new TLD there. These things are used by sysadmin/project pairs that can't budget 1$/month for a domain name, so it's 100% a security/price tradeoff.
Second of all, the actual domain host is publishing as one of these untrusted users on their alternate subdomain, so it could be a phisher using a subdomain of the official alternate domain with malicious material
Thirdly, even if it is all legit, it is still a problem, because it weakens security posture, it trains users to ignore domain names.
I understand if it appears subtle, but I wish that we lived in a world where whoever is responsible for this gets put on a PIP
https://github.github.com/gh-aw/
served as GitHub Pages from https://github.com/github/gh-aw