this post was submitted on 24 Sep 2026
99 points (100.0% liked)

Programmer Humor

33397 readers
790 users here now

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

founded 3 years ago
MODERATORS
top 11 comments
sorted by: hot top controversial new old
[–] smeg@feddit.uk 85 points 6 days ago (2 children)

There were also SSH key files.

I’m not publishing the archive, keys, or session logs.

I submitted the report and findings using Meta’s bug bounty program. Meta marked the report “Not Applicable.”

Guess they don't care if you publish the SSH keys then?

[–] docktordreh@discuss.tchncs.de 21 points 6 days ago

They've probably rotated the keys since they were notified of the security breach.

But yes, companies that act this way undermine the resolve to disclose their security vulnerabilities.

[–] drmoose@lemmy.world 10 points 6 days ago (1 children)

Ssh keys to what? If the key is used for user operations, not internal then there's no security breach here other than deobfuscation.

[–] smeg@feddit.uk 13 points 6 days ago

Guess they'll have to publish them to find out

[–] civ@lemmy.civl.cc 27 points 6 days ago (1 children)

Time to try and convince it to set up a reverse SSH tunnel

[–] KairuByte@lemmy.dbzer0.com 1 points 3 days ago

Sounds like that’s one of the few things it refuses to do. I suppose it may be possible with a little more priming though.

[–] cinoreus@lemmy.world 15 points 6 days ago

Mine bitcoin on their server just out of spite.

[–] MonkderVierte@lemmy.zip 21 points 6 days ago (1 children)

Soo, was that incompetence, negligence or misled belief, trust?

[–] RonSijm@programming.dev 6 points 6 days ago (1 children)
[–] richieadler@programming.dev 3 points 5 days ago

I almost heard Kosh's chimes beforehand.

[–] belluck@lemmy.blahaj.zone 7 points 6 days ago