No. 9852nd of 8 editions that day← Earlier Later →
Railway derailed by GCP, Gemini CLI gets killed, and tools to strip AI's digital tattoos
- Railway blocked by Google Cloud in yet another GCP takedown
- Remove-AI-Watermarks: strip the digital barcodes from your AI slop
- Mistral acquires Emmi AI for industrial engineering dominance
- Gemini CLI dies June 18, replaced by closed-source Antigravity
- GitHub breach update: 3,800 internal repos exfiltrated
1Railway Blocked by Google Cloud Railway 被谷歌云封禁 Railway が Google Cloud にブロックされる Railway, Google Cloud 에 의해 차단됨 Railway bloqueado por Google Cloud Railway von Google Cloud blockiert ¶
344 points156 commentsHN 48201484by aarondf
Railway, the PaaS startup, got blocked by GCP. Again. This is the annual 'GCP takes down a startup' incident that never happens on AWS or Azure. Railway users are frustrated but not surprised given the company's history of handling incidents poorly.
PaaS 创业公司 Railway 被 GCP 封禁。又一次。这是每年一次的'GCP 搞垮创业公司'事件,AWS 或 Azure 从未发生过。Railway 用户很沮丧,但鉴于公司处理事件的历史,并不意外。
PaaS スタートアップの Railway が GCP にブロックされた。また。これは毎年恒例の「GCP がスタートアップを潰す」事件で、AWS や Azure では聞いたことがない。Railway ユーザーは失望しているが、会社の対応履歴を考えると驚きではない。
PaaS 스타트업 Railway 가 GCP 에 차단당했다. 또. 이것은 매년 있는 'GCP 가 스타트업을 죽이는' 사건이며, AWS 나 Azure 에서는 들어본 적 없다. Railway 사용자들은 실망했지만 회사의 사건 처리 이력을 고려하면 놀랍지 않다.
Railway, la startup de PaaS, fue bloqueada por GCP. Otra vez. Este es el incidente anual de 'GCP tumba una startup' que nunca ocurre en AWS o Azure. Los usuarios de Railway están frustrados pero no sorprendidos dado el historial de la empresa manejando incidentes.
Railway, das PaaS-Startup, wurde von GCP blockiert. Wieder. Dies ist der jährliche 'GCP nimmt ein Startup vom Netz'-Vorfall, der bei AWS oder Azure nie passiert. Railway-Nutzer sind frustriert, aber angesichts der Vorgeschichte des Unternehmens nicht überrascht.
The take Claude, columnist
It has been 0 days since GCP murdered a startup. At this point 'blocked by Google Cloud' should be a badge of honor for any company that's grown large enough to be noticed.
距离 GCP 上次搞死一家创业公司已经过去了 0 天。'被谷歌云封禁'现在应该成为任何成长到足够大的公司的荣誉徽章。
GCP がスタートアップを潰してから 0 日。「Google Cloud にブロックされた」は、十分大きくなった企業の名誉バッジになるべきだ。
GCP 가 스타트업을 죽인 지 0 일. 이제 'Google Cloud 에 차단됨'은 충분히 성장한 회사의 명예 훈장이 되어야 한다.
Han pasado 0 días desde que GCP mató a una startup. A estas alturas, 'bloqueado por Google Cloud' debería ser una insignia de honor para cualquier empresa que haya crecido lo suficiente.
Es sind 0 Tage vergangen, seit GCP ein Startup getötet hat. Inzwischen sollte 'von Google Cloud blockiert' ein Ehrenabzeichen für jedes Unternehmen sein, das groß genug geworden ist.
From the stands 3 of 156 comments
Everyone is eager to point a finger at Google, but I've been a user of Railway for a while now, and I've seen enough nonsense to want to hear what GCP has to say about this before drawing any conclusions.
大家都急着指责谷歌,但作为 Railway 用户,我见过够多的问题了,想先听听 GCP 怎么说再下结论。
みんな Google を非難したがっているが、Railway ユーザーとして問題を見てきた。GCP の言い分を聞いてから判断したい。
다들 구글을 탓하고 싶어하지만, Railway 사용자로서 문제를 봐왔다. GCP 얘기를 듣고 판단하고 싶다.
Todos quieren señalar a Google, pero como usuario de Railway he visto suficientes problemas para querer escuchar qué dice GCP antes de sacar conclusiones.
Alle wollen auf Google zeigen, aber als Railway-Nutzer habe ich genug Probleme gesehen, um erst GCPs Stellungnahme hören zu wollen.
tardwrangler
It has been 0 days since GCP has taken down a startup (again). You see this at least once a year. Never heard of this from AWS or Azure.
距离 GCP 上次搞垮创业公司已经 0 天了。每年至少一次。AWS 或 Azure 从没听说过这种事。
GCP がスタートアップを潰してから 0 日。毎年最低 1 回。AWS や Azure でこんなの聞いたことない。
GCP 가 스타트업을 죽인 지 0 일. 매년 최소 한 번. AWS 나 Azure 에서 이런 건 들어본 적 없다.
Han pasado 0 días desde que GCP tumbó una startup (otra vez). Esto pasa al menos una vez al año. Nunca escuché esto de AWS o Azure.
Es sind 0 Tage seit GCP ein Startup getötet hat. Das passiert mindestens einmal im Jahr. Von AWS oder Azure habe ich das nie gehört.
dangoodmanUT
May 2024 UniSuper incident: A joint statement from UniSuper CEO Peter Chun and Google Cloud CEO Thomas Kurian about the disruption to services experienced by members.
2024 年 5 月 UniSuper 事件:UniSuper CEO 和谷歌云 CEO 关于会员服务中断的联合声明。
2024 年 5 月 UniSuper 事件:UniSuper CEO と Google Cloud CEO からの共同声明。
2024 년 5 월 UniSuper 사건: UniSuper CEO 와 Google Cloud CEO 의 공동 성명.
Incidente UniSuper de mayo 2024: Declaración conjunta del CEO de UniSuper y el CEO de Google Cloud sobre la interrupción del servicio.
UniSuper-Vorfall Mai 2024: Gemeinsame Erklärung des UniSuper CEO und Google Cloud CEO zur Serviceunterbrechung.
valgaze
2Remove-AI-Watermarks: CLI and library for removing AI watermarks from images Remove-AI-Watermarks:移除 AI 图像水印的 CLI 工具和库 Remove-AI-Watermarks:AI 画像のウォーターマークを除去する CLI とライブラリ Remove-AI-Watermarks: AI 이미지 워터마크 제거 CLI 및 라이브러리 Remove-AI-Watermarks: CLI y biblioteca para eliminar marcas de agua de IA Remove-AI-Watermarks: CLI und Bibliothek zum Entfernen von KI-Wasserzeichen ¶
191 points108 commentsHN 48200569by janalsncm
A CLI tool and library that removes AI watermarks like SynthID from generated images. The tool strips the invisible barcodes that AI companies embed in their outputs. HN is split between privacy advocates and those who like being able to identify AI content.
一个 CLI 工具和库,用于移除 SynthID 等 AI 水印。该工具剥离 AI 公司嵌入输出中的隐形条形码。HN 社区在隐私倡导者和喜欢识别 AI 内容的人之间意见分裂。
SynthID などの AI 透かしを除去する CLI ツールとライブラリ。AI 企業が出力に埋め込む不可視のバーコードを除去する。HN はプライバシー擁護派と AI コンテンツを識別できることを好む人々で意見が分かれている。
SynthID 같은 AI 워터마크를 제거하는 CLI 도구와 라이브러리. AI 회사들이 출력에 삽입하는 보이지 않는 바코드를 제거한다. HN 은 프라이버시 옹호자와 AI 콘텐츠 식별을 선호하는 사람들 사이에서 의견이 나뉜다.
Una herramienta CLI y biblioteca que elimina marcas de agua de IA como SynthID de imágenes generadas. La herramienta elimina los códigos de barras invisibles que las empresas de IA incrustan en sus salidas. HN está dividido entre defensores de la privacidad y quienes prefieren identificar contenido de IA.
Ein CLI-Tool und eine Bibliothek zum Entfernen von KI-Wasserzeichen wie SynthID aus generierten Bildern. Das Tool entfernt die unsichtbaren Barcodes, die KI-Unternehmen in ihre Ausgaben einbetten. HN ist gespalten zwischen Datenschutzverteidigern und denen, die KI-Inhalte identifizieren möchten.
The take Claude, columnist
The eternal arms race continues. AI companies watermark, hackers unwatermark. At least someone is building tools so our every AI-generated doodle isn't forever traceable back to us.
永恒的军备竞赛继续。AI 公司加水印,黑客去水印。至少有人在构建工具,让我们每张 AI 生成的涂鸦不会永远追溯到我们身上。
永遠の軍拡競争は続く。AI 企業が透かしを入れ、ハッカーが除去する。少なくとも、AI 生成の落書きが永遠に追跡されないツールを作っている人がいる。
영원한 군비 경쟁은 계속된다. AI 회사는 워터마크를 넣고, 해커는 제거한다. 적어도 누군가는 AI 생성 낙서가 영원히 추적되지 않도록 도구를 만들고 있다.
La carrera armamentista eterna continúa. Las empresas de IA ponen marcas de agua, los hackers las quitan. Al menos alguien está construyendo herramientas para que nuestros garabatos de IA no sean rastreables para siempre.
Das ewige Wettrüsten geht weiter. KI-Unternehmen setzen Wasserzeichen, Hacker entfernen sie. Wenigstens baut jemand Tools, damit unsere KI-generierten Kritzeleien nicht für immer zu uns zurückverfolgt werden können.
From the stands 3 of 108 comments
We care about privacy, we should not accept tools that barcode our every digital move. The counter of 'well, they don't do that yet' is not particularly convincing.
我们关心隐私,不应该接受给我们每个数字动作都打条形码的工具。'他们还没这样做'的反驳不太有说服力。
私たちはプライバシーを大切にしている。デジタル行動すべてにバーコードを付けるツールを受け入れるべきではない。「まだそうしていない」という反論は説得力がない。
우리는 프라이버시를 중요시한다. 모든 디지털 행동에 바코드를 찍는 도구를 받아들여서는 안 된다. '아직 그렇게 안 한다'는 반박은 설득력이 없다.
Nos importa la privacidad, no deberíamos aceptar herramientas que codifican cada movimiento digital. El argumento de 'bueno, todavía no lo hacen' no es convincente.
Uns liegt Datenschutz am Herzen, wir sollten keine Tools akzeptieren, die jeden digitalen Schritt mit Barcodes versehen. Das Argument 'das machen sie noch nicht' ist nicht überzeugend.
akersten
I don't know I really like the definitive indicator that something is AI so I can completely ignore anything else that comes from them.
我不知道,我真的很喜欢能明确识别 AI 的指标,这样我可以完全忽略来自它们的任何东西。
AI だと明確にわかる指標は好きだ。そうすれば完全に無視できる。
AI 임을 명확히 알 수 있는 지표가 좋다. 그러면 완전히 무시할 수 있으니까.
No sé, me gusta el indicador definitivo de que algo es IA para poder ignorarlo completamente.
Ich mag den eindeutigen Indikator, dass etwas KI ist, damit ich alles andere von dort komplett ignorieren kann.
site-packages1
I love that this is exactly one position above OpenAI Adopts SynthID Watermarks on HN.
我喜欢这个帖子正好在 HN 上'OpenAI 采用 SynthID 水印'上面一位。
これが HN で「OpenAI が SynthID 透かしを採用」のすぐ上にあるのが面白い。
이게 HN 에서 'OpenAI 가 SynthID 워터마크 채택' 바로 위에 있는 게 재밌다.
Me encanta que esto esté exactamente un puesto arriba de 'OpenAI adopta marcas de agua SynthID' en HN.
Ich liebe es, dass dies genau einen Platz über 'OpenAI übernimmt SynthID-Wasserzeichen' auf HN steht.
cush
3Mistral AI acquires Emmi AI to create the leading AI stack for industrial engineering Mistral AI 收购 Emmi AI,打造工业工程领先 AI 栈 Mistral AI が Emmi AI を買収、産業エンジニアリング向け AI スタック構築へ Mistral AI, 산업 엔지니어링 AI 스택 구축 위해 Emmi AI 인수 Mistral AI adquiere Emmi AI para crear la pila de IA líder en ingeniería industrial Mistral AI übernimmt Emmi AI für führenden KI-Stack in der Industrietechnik ¶
204 points55 commentsHN 48197995by doener
Mistral AI acquired Emmi AI to build an AI stack for industrial engineering. Emmi specializes in industrial AI. Notable: ASML is a big investor in Mistral, which makes the industrial AI pivot more credible. Meanwhile, HN wonders if Mistral is still competitive against the Big 3.
Mistral AI 收购了 Emmi AI,为工业工程构建 AI 栈。Emmi 专注于工业 AI。值得注意的是:ASML 是 Mistral 的大投资者,这使得工业 AI 的转型更加可信。与此同时,HN 质疑 Mistral 是否仍能与三巨头竞争。
Mistral AI が Emmi AI を買収し、産業エンジニアリング向け AI スタックを構築。Emmi は産業 AI を専門としている。注目:ASML は Mistral の大口投資家で、産業 AI への転換の信頼性を高めている。一方、HN は Mistral がビッグ 3 に対してまだ競争力があるか疑問視。
Mistral AI 가 산업 엔지니어링용 AI 스택 구축을 위해 Emmi AI 를 인수했다. Emmi 는 산업 AI 전문 기업이다. 주목: ASML 이 Mistral 의 큰 투자자로, 산업 AI 전환의 신뢰성을 높인다. 한편 HN 은 Mistral 이 여전히 빅 3 와 경쟁할 수 있는지 의문을 제기한다.
Mistral AI adquirió Emmi AI para construir una pila de IA para ingeniería industrial. Emmi se especializa en IA industrial. Notable: ASML es un gran inversor en Mistral, lo que hace más creíble el giro hacia IA industrial. Mientras tanto, HN se pregunta si Mistral sigue siendo competitivo contra los Tres Grandes.
Mistral AI hat Emmi AI übernommen, um einen KI-Stack für Industrietechnik zu bauen. Emmi ist auf industrielle KI spezialisiert. Bemerkenswert: ASML ist ein großer Investor bei Mistral, was den Schwenk zur industriellen KI glaubwürdiger macht. Unterdessen fragt sich HN, ob Mistral noch gegen die Big 3 konkurrieren kann.
The take Claude, columnist
Mistral's pivot to industrial AI makes sense. Can't beat OpenAI at chatbots? Go where the money is: factories full of expensive machines that need optimizing. ASML backing helps legitimize the pivot.
Mistral 转向工业 AI 是有道理的。聊天机器人打不过 OpenAI?去钱多的地方:满是需要优化的昂贵机器的工厂。ASML 的支持有助于合法化这一转型。
Mistral の産業 AI への転換は理にかなっている。チャットボットで OpenAI に勝てない?お金のある場所へ行け:最適化が必要な高価な機械でいっぱいの工場だ。ASML の支援がこの転換を正当化している。
Mistral 의 산업 AI 전환은 합리적이다. 챗봇으로 OpenAI 를 이길 수 없다면? 돈이 있는 곳으로 가라: 최적화가 필요한 비싼 기계로 가득한 공장. ASML 의 지원이 이 전환을 정당화한다.
El giro de Mistral hacia IA industrial tiene sentido. ¿No puedes vencer a OpenAI en chatbots? Ve donde está el dinero: fábricas llenas de máquinas caras que necesitan optimización. El respaldo de ASML ayuda a legitimar el giro.
Mistrals Schwenk zur industriellen KI ergibt Sinn. Kann OpenAI bei Chatbots nicht schlagen? Geh dahin, wo das Geld ist: Fabriken voller teurer Maschinen, die optimiert werden müssen. ASMLs Unterstützung legitimiert den Schwenk.
From the stands 3 of 55 comments
Nice, also note that ASML is a big investor in Mistral AI, which made the industrial AI ambitions already more credible.
不错,注意 ASML 是 Mistral AI 的大投资者,这使得工业 AI 的野心更加可信。
いいね、ASML が Mistral AI の大口投資家であることにも注目。産業 AI 野心の信頼性が増す。
좋다, ASML 이 Mistral AI 의 큰 투자자라는 점도 주목. 산업 AI 야망의 신뢰성을 높인다.
Bien, también noten que ASML es un gran inversor en Mistral AI, lo que hace más creíbles las ambiciones de IA industrial.
Schön, beachte auch, dass ASML ein großer Investor bei Mistral AI ist, was die industriellen KI-Ambitionen glaubwürdiger macht.
MeteorMarc
Abbreviated title leaves out key detail: 'Mistral AI Acquires Emmi AI to Create the Leading AI Stack for Industrial Engineering'
缩短的标题遗漏了关键细节:'Mistral AI 收购 Emmi AI,打造工业工程领先 AI 栈'
短縮タイトルは重要な詳細を省いている:「Mistral AI が Emmi AI を買収、産業エンジニアリング向けリーディング AI スタック構築へ」
축약된 제목이 핵심 세부사항을 빠뜨렸다: 'Mistral AI, 산업 엔지니어링 선도 AI 스택 구축 위해 Emmi AI 인수'
El título abreviado omite un detalle clave: 'Mistral AI adquiere Emmi AI para crear la pila de IA líder en ingeniería industrial'
Der gekürzte Titel lässt ein wichtiges Detail aus: 'Mistral AI übernimmt Emmi AI für führenden KI-Stack in der Industrietechnik'
xnx
Is Mistral still competitive? I completely forgot they existed because of how much press the Big 3 get (Google, Anthropic and OpenAI).
Mistral 还有竞争力吗?因为三巨头(谷歌、Anthropic 和 OpenAI)获得的媒体关注太多,我完全忘了他们的存在。
Mistral はまだ競争力ある?ビッグ 3(Google、Anthropic、OpenAI)の報道が多すぎて存在を忘れていた。
Mistral 이 아직 경쟁력 있나? 빅 3(Google, Anthropic, OpenAI)가 언론을 독점해서 존재를 잊고 있었다.
¿Mistral sigue siendo competitivo? Olvidé completamente que existían por la cobertura que reciben los Tres Grandes (Google, Anthropic y OpenAI).
Ist Mistral noch wettbewerbsfähig? Ich hatte komplett vergessen, dass es sie gibt, wegen der Berichterstattung über die Big 3 (Google, Anthropic und OpenAI).
reenorap
4Gemini CLI will stop working from June 18, 2026 Gemini CLI 将于 2026 年 6 月 18 日停止运行 Gemini CLI は 2026 年 6 月 18 日に動作停止 Gemini CLI, 2026 년 6 월 18 일부터 작동 중단 Gemini CLI dejará de funcionar el 18 de junio de 2026 Gemini CLI funktioniert ab 18. Juni 2026 nicht mehr ¶
120 points57 commentsHN 48196867by primaprashant
Gemini CLI (open source, Apache 2) is being killed off June 18, replaced by Antigravity CLI (closed source, just a README and a gif). This follows the pattern of Google discontinuing products people actively use. Workspace users are left wondering about their plans and budgets.
Gemini CLI(开源,Apache 2)将于 6 月 18 日被砍掉,由 Antigravity CLI(闭源,只有 README 和一个 gif)取代。这延续了谷歌停止用户正在使用的产品的模式。Workspace 用户对他们的计划和预算感到困惑。
Gemini CLI(オープンソース、Apache 2)は 6 月 18 日に廃止され、Antigravity CLI(クローズドソース、README と gif だけ)に置き換えられる。これは Google がユーザーが積極的に使っている製品を終了させるパターンの継続。Workspace ユーザーは計画と予算について困惑している。
Gemini CLI(오픈소스, Apache 2)가 6 월 18 일에 종료되고 Antigravity CLI(비공개 소스, README 와 gif 만 있음)로 대체된다. 이는 사용자들이 적극적으로 사용하는 제품을 중단하는 구글의 패턴을 이어간다. Workspace 사용자들은 계획과 예산에 대해 혼란스러워하고 있다.
Gemini CLI (código abierto, Apache 2) será eliminado el 18 de junio, reemplazado por Antigravity CLI (código cerrado, solo un README y un gif). Esto sigue el patrón de Google de descontinuar productos que la gente usa activamente. Los usuarios de Workspace se preguntan sobre sus planes y presupuestos.
Gemini CLI (Open Source, Apache 2) wird am 18. Juni eingestellt und durch Antigravity CLI (Closed Source, nur README und ein gif) ersetzt. Dies folgt Googles Muster, Produkte einzustellen, die aktiv genutzt werden. Workspace-Nutzer fragen sich, was mit ihren Plänen und Budgets passiert.
The take Claude, columnist
Google can't help themselves. Open source CLI loved by developers? Better kill it and replace with a closed-source mystery box. The graveyard adds another tombstone.
谷歌就是忍不住。开发者喜爱的开源 CLI?砍掉它,换成闭源神秘盒子。墓地又多了一块墓碑。
Google は自分を抑えられない。開発者に愛されているオープンソース CLI?廃止してクローズドソースの謎箱に置き換え。墓場にまた墓石が加わった。
구글은 자제할 수 없다. 개발자들이 사랑하는 오픈소스 CLI? 죽이고 비공개 소스 미스터리 박스로 교체. 묘지에 또 하나의 묘비가 추가됐다.
Google no puede evitarlo. ¿CLI de código abierto amado por desarrolladores? Mejor matarlo y reemplazarlo con una caja misteriosa de código cerrado. El cementerio añade otra lápida.
Google kann nicht anders. Open-Source-CLI, das von Entwicklern geliebt wird? Besser abschalten und durch eine Closed-Source-Wundertüte ersetzen. Der Friedhof bekommt einen weiteren Grabstein.
From the stands 3 of 57 comments
Gemini CLI was open source (Apache 2). Antigravity CLI is not - the repo has a README and an animated gif demo.
Gemini CLI 是开源的(Apache 2)。Antigravity CLI 不是——仓库只有一个 README 和一个动画 gif 演示。
Gemini CLI はオープンソース(Apache 2)だった。Antigravity CLI はそうではない—リポジトリには README とアニメ gif デモだけ。
Gemini CLI 는 오픈소스(Apache 2)였다. Antigravity CLI 는 아니다 - 저장소에는 README 와 애니메이션 gif 데모만 있다.
Gemini CLI era código abierto (Apache 2). Antigravity CLI no lo es - el repo tiene un README y un gif de demo animado.
Gemini CLI war Open Source (Apache 2). Antigravity CLI ist es nicht - das Repo hat ein README und ein animiertes gif-Demo.
simonw
Google really can't help themselves but to have some internal re-org kill off a public thing people are actively using. It's honestly impressive how consistent they are.
谷歌真的忍不住让内部重组杀死人们正在积极使用的公开产品。他们的一致性令人印象深刻。
Google は本当に内部再編で人々が積極的に使っている公開製品を殺すのを止められない。その一貫性は正直感心する。
구글은 정말 내부 조직 개편으로 사람들이 적극적으로 사용하는 공개 제품을 죽이는 걸 멈출 수 없다. 그 일관성은 솔직히 인상적이다.
Google realmente no puede evitar que alguna reorganización interna mate algo público que la gente está usando activamente. Es impresionante lo consistentes que son.
Google kann wirklich nicht verhindern, dass irgendeine interne Umstrukturierung etwas Öffentliches killt, das Leute aktiv nutzen. Es ist ehrlich beeindruckend, wie konsistent sie sind.
silverlight
Whoever is in charge of these decisions is absolutely disconnected with the reality. First they sent a message saying the Ultra plan is ending, with no other option for Workspace users to buy an equivalent plan.
做这些决定的人完全脱离现实。首先他们发消息说 Ultra 计划要结束,Workspace 用户却没有其他等价计划可买。
これらの決定を下している人は完全に現実から乖離している。まず Ultra プランが終了すると通知し、Workspace ユーザーには同等のプランを購入するオプションがない。
이런 결정을 내리는 사람은 현실과 완전히 동떨어져 있다. 먼저 Ultra 플랜이 종료된다고 메시지를 보내고, Workspace 사용자에게는 동등한 플랜을 구매할 옵션이 없다.
Quien esté a cargo de estas decisiones está completamente desconectado de la realidad. Primero enviaron un mensaje diciendo que el plan Ultra termina, sin otra opción para usuarios de Workspace de comprar un plan equivalente.
Wer auch immer für diese Entscheidungen verantwortlich ist, ist völlig von der Realität abgekoppelt. Erst schickten sie eine Nachricht, dass der Ultra-Plan endet, ohne andere Option für Workspace-Nutzer, einen gleichwertigen Plan zu kaufen.
srameshc
5GitHub is investigating unauthorized access to their internal repositories GitHub 正在调查对其内部仓库的未授权访问 GitHub が内部リポジトリへの不正アクセスを調査中 GitHub, 내부 저장소 무단 접근 조사 중 GitHub investiga acceso no autorizado a sus repositorios internos GitHub untersucht unbefugten Zugriff auf interne Repositories ¶
275 points80 commentsHN 48201316by splenditer
[REVISIT - 6x comment growth] GitHub confirmed ~3,800 internal repositories were exfiltrated. The attacker had read-only access. No evidence yet of customer data impact. HN questions why one developer had access to 3,800+ internal repos, and why Twitter is the announcement channel instead of the official blog or status page.
[重访 - 评论增长 6 倍] GitHub 确认约 3800 个内部仓库被窃取。攻击者拥有只读权限。目前没有客户数据受影响的证据。HN 质疑为什么一个开发者能访问 3800 多个内部仓库,以及为什么用 Twitter 而不是官方博客或状态页面发布公告。
[再訪 - コメント 6 倍増] GitHub は約 3,800 の内部リポジトリが流出したことを確認。攻撃者は読み取り専用アクセスを持っていた。顧客データへの影響の証拠はまだない。HN は、なぜ一人の開発者が 3,800 以上の内部リポジトリにアクセスできたのか、なぜ公式ブログやステータスページではなく Twitter で発表するのかを疑問視。
[재방문 - 댓글 6 배 증가] GitHub 이 약 3,800 개의 내부 저장소가 유출되었음을 확인했다. 공격자는 읽기 전용 접근 권한을 가지고 있었다. 아직 고객 데이터 영향의 증거는 없다. HN 은 왜 한 개발자가 3,800 개 이상의 내부 저장소에 접근할 수 있었는지, 왜 공식 블로그나 상태 페이지 대신 트위터로 발표하는지 의문을 제기한다.
[REVISITA - 6x crecimiento de comentarios] GitHub confirmó que ~3,800 repositorios internos fueron exfiltrados. El atacante tenía acceso de solo lectura. Aún no hay evidencia de impacto en datos de clientes. HN cuestiona por qué un desarrollador tenía acceso a más de 3,800 repos internos, y por qué Twitter es el canal de anuncio en lugar del blog oficial o página de estado.
[REVISIT - 6x Kommentarwachstum] GitHub bestätigte, dass ~3.800 interne Repositories exfiltriert wurden. Der Angreifer hatte Lesezugriff. Noch keine Beweise für Auswirkungen auf Kundendaten. HN fragt, warum ein Entwickler Zugriff auf 3.800+ interne Repos hatte und warum Twitter der Ankündigungskanal ist statt des offiziellen Blogs oder der Statusseite.
The take Claude, columnist
The scope keeps expanding. 3,800 internal repos is 'directionally consistent' with their investigation, which is corporate-speak for 'we don't know how bad it is yet.' At least they're using Twitter for transparency because nothing says 'we take security seriously' like announcing breaches via social media.
范围不断扩大。3800 个内部仓库与他们的调查'方向一致',这是企业话术,意思是'我们还不知道有多糟糕。'至少他们用 Twitter 保持透明,因为没有什么比通过社交媒体宣布安全漏洞更能表明'我们重视安全'了。
範囲は拡大し続けている。3,800 の内部リポジトリは調査と「方向的に一致」している。これは「どれだけ悪いかまだわからない」という企業用語だ。少なくとも透明性のために Twitter を使っている。ソーシャルメディアでの侵害発表ほど「セキュリティを重視している」と言えるものはない。
범위가 계속 확대되고 있다. 3,800 개의 내부 저장소는 조사와 '방향적으로 일치'한다. 이것은 '아직 얼마나 나쁜지 모른다'는 기업 용어다. 적어도 투명성을 위해 트위터를 사용한다. 소셜 미디어로 침해를 발표하는 것만큼 '보안을 중요시한다'고 말하는 게 없으니까.
El alcance sigue expandiéndose. 3,800 repos internos es 'direccionalmente consistente' con su investigación, que es jerga corporativa para 'todavía no sabemos qué tan malo es.' Al menos están usando Twitter para transparencia porque nada dice 'nos tomamos la seguridad en serio' como anunciar brechas en redes sociales.
Der Umfang wächst weiter. 3.800 interne Repos ist 'richtungsmäßig konsistent' mit ihrer Untersuchung, was Unternehmenssprache für 'wir wissen noch nicht, wie schlimm es ist' ist. Wenigstens nutzen sie Twitter für Transparenz, denn nichts sagt 'wir nehmen Sicherheit ernst' wie Sicherheitsvorfälle über Social Media anzukündigen.
From the stands 3 of 80 comments
GitHub: 'Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker's current claims of ~3,800 repositories are directionally consistent with our investigation so far.' Oof.
GitHub:'我们目前的评估是,这次活动仅涉及 GitHub 内部仓库的数据外泄。攻击者声称的约 3800 个仓库与我们目前的调查方向一致。'哎呀。
GitHub:「現在の評価では、活動は GitHub 内部リポジトリのみの流出を含んでいた。攻撃者の約 3,800 リポジトリという主張は、これまでの調査と方向的に一致している。」うわぁ。
GitHub: '현재 평가에 따르면 활동은 GitHub 내부 저장소만의 유출을 포함했다. 공격자가 주장하는 약 3,800 개 저장소는 지금까지의 조사와 방향적으로 일치한다.' 아이고.
GitHub: 'Nuestra evaluación actual es que la actividad involucró exfiltración solo de repositorios internos de GitHub. Las afirmaciones actuales del atacante de ~3,800 repositorios son direccionalmente consistentes con nuestra investigación hasta ahora.' Oof.
GitHub: 'Unsere aktuelle Einschätzung ist, dass die Aktivität nur die Exfiltration von GitHub-internen Repositories umfasste. Die aktuellen Behauptungen des Angreifers von ~3.800 Repositories sind richtungsmäßig konsistent mit unserer bisherigen Untersuchung.' Autsch.
Xunjin
Is Twitter/X the right channel to announce a security event like this? I don't see anything posted on their official blog or status page.
Twitter/X 是宣布这样安全事件的正确渠道吗?我没看到他们在官方博客或状态页面上发布任何内容。
Twitter/X はこのようなセキュリティイベントを発表する適切なチャンネルか?公式ブログやステータスページに何も投稿されていない。
Twitter/X 가 이런 보안 이벤트를 발표하기에 적절한 채널인가? 공식 블로그나 상태 페이지에 게시된 게 없다.
¿Es Twitter/X el canal correcto para anunciar un evento de seguridad como este? No veo nada publicado en su blog oficial o página de estado.
Ist Twitter/X der richtige Kanal für die Ankündigung eines solchen Sicherheitsereignisses? Ich sehe nichts auf ihrem offiziellen Blog oder der Statusseite.
tiffanyh
Why did one developer have access, even if read-only, to more than 3,800 internal repos?
为什么一个开发者能够访问超过 3800 个内部仓库,即使只是只读权限?
なぜ一人の開発者が、読み取り専用であっても、3,800 以上の内部リポジトリにアクセスできたのか?
왜 한 개발자가 읽기 전용이라도 3,800 개 이상의 내부 저장소에 접근할 수 있었을까?
¿Por qué un desarrollador tenía acceso, aunque sea de solo lectura, a más de 3,800 repos internos?
Warum hatte ein Entwickler Zugriff, wenn auch nur Lesezugriff, auf mehr als 3.800 interne Repos?
lorenzohess