Docker Hub被黑了,190K账号泄露,GitHub tokens被撤销,已禁用构建

原文如下:
Docker Hub Hacked – 190k accounts, GitHub tokens revoked, builds disabled
558 points by lugg 5 hours ago | hide | past | web | favorite | 109 comments
Received this email a few minutes ago:
"On Thursday, April 25th, 2019, we discovered unauthorized access to a single Hub database storing a subset of non-financial user data. Upon discovery, we acted quickly to intervene and secure the site.

We want to update you on what we’ve learned from our ongoing investigation, including which Hub accounts are impacted, and what actions users should take.

Here is what we’ve learned:

During a brief period of unauthorized access to a Docker Hub database, sensitive data from approximately 190,000 accounts may have been exposed (less than 5% of Hub users). Data includes usernames and hashed passwords for a small percentage of these users, as well as Github and Bitbucket tokens for Docker autobuilds.

Actions to Take:

  • We are asking users to change their password on Docker Hub and any other accounts that shared this password.

  • For users with autobuilds that may have been impacted, we have revoked GitHub tokens and access keys, and ask that you reconnect to your repositories and check security logs to see if any unexpected actions have taken place.

  • You may view security actions on your GitHub or BitBucket accounts to see if any unexpected access has occurred over the past 24 hours -see https://help.github.com/en/articles/reviewing-your-security-log and https://bitbucket.org/blog/new-audit-logs-give-you-the-who-what-when-and-where

  • This may affect your ongoing builds from our Automated build service. You may need to unlink and then relink your Github and Bitbucket source provider as described in https://docs.docker.com/docker-hub/builds/link-source/

We are enhancing our overall security processes and reviewing our policies. Additional monitoring tools are now in place.

Our investigation is still ongoing, and we will share more information as it becomes available.

Thank you,

Kent Lamb Director of Docker Support [email protected]"

译文如下:
Docker Hub Hacked - 190k帐户,GitHub令牌被撤销,构建被禁用
558点的Lugg填入 4小时前 | 隐藏 | 过去 | 网络 | 喜欢 | 109评论
几分钟前收到此电子邮件:
“在2019年4月25日星期四,我们发现未经授权访问存储一部分非财务用户数据的单个Hub数据库。一旦发现,我们就会迅速采取干预措施并保护网站。

我们希望向您介绍我们从正在进行的调查中了解到的内容,包括哪些Hub帐户受到影响,以及用户应采取的操作。

这是我们学到的:

在未经授权访问Docker Hub数据库的短暂时间内,可能已暴露大约190,000个帐户的敏感数据(少于5%的Hub用户)。数据包括一小部分用户的用户名和散列密码,以及Docker autobuild的Github和Bitbucket令牌。

采取的行动:

  • 我们要求用户在Docker Hub和共享此密码的任何其他帐户上更改密码。

  • 对于具有可能受影响的autobuild的用户,我们已撤销GitHub令牌和访问密钥,并要求您重新连接到您的存储库并检查安全日志以查看是否发生了任何意外操作。

  • 您可以在GitHub或BitBucket帐户上查看安全操作,以查看过去24小时内是否发生任何意外访问 - 请访问https://help.github.com/en/articles/reviewing-your-security-log和https ://bitbucket.org/blog/new-audit-logs-give-you-the-who-what-when-and-where

  • 这可能会影响我们的Automated构建服务的持续构建。您可能需要取消链接,然后重新链接您的Github和Bitbucket源提供程序,如https://docs.docker.com/docker-hub/builds/link-source/中所述

我们正在加强整体安全流程并审核我们的政策。现在有了额外的监测工具。

我们的调查仍在进行中,我们将在可用时分享更多信息。

谢谢,

Kent Lamb Docker支持总监[email protected]

链接如下:
https://news.ycombinator.com/item?id=19763413

你可能感兴趣的:(道听途说,GitHub,隐私泄露,Docker,Hub)