news.volyx.in

Ask HN: Developer abused “sign in with GitHub”?

860 points by 2Gkashmiri · 1368 days ago · 480 comments on HN

Article summary

A user's GitHub account was suspended after they used the 'sign in with GitHub' feature on a website called nopecha.com, which automatically starred hundreds of repositories without their knowledge or consent. The user claims they did not engage in any abusive behavior and that the website's actions were unauthorized. The user is questioning why GitHub allowed the developer to use the 'sign in with GitHub' feature to create a situation that could be considered abusive. The user is seeking to understand why they were banned instead of the developer being held responsible.

Main themes

  • GitHub permission system
  • OAuth2 authorization
  • single sign-on security
  • user responsibility
  • developer abuse
  • GitHub accountability

What commenters say

  • The user is responsible for vetting who they give permissions to and should have read the permissions more carefully before granting access.
  • GitHub's permission system is flawed and allows developers to request too many permissions, making it difficult for users to make informed decisions.
  • The 'sign in with GitHub' feature can be misleading and may not always be a standard single sign-on flow, but rather an OAuth2 authorization code flow that grants more access than expected.
  • GitHub should have banned the developer instead of the user, as the user did not engage in any abusive behavior and was tricked into granting access.
  • The incident highlights the dangers of 'sign in with' buttons and the potential for abuse, and users should be more cautious when using these features.
  • GitHub's response to the incident was excessive and unfair, and the company should have taken a more nuanced approach to addressing the issue.
  • The user's lack of attention to the permissions granted is not entirely their fault, as the permissions can be confusing and misleading, and GitHub should take steps to improve the user experience and prevent similar incidents in the future.