Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

This means that as a disgruntled employee I can simply visit Iran, log in my company Github account and boom!

I have now taken revenge on my whole company with minimal effort.



Or just use a vpn that has servers in Iran? I think there are a few, hidemyass is one also I think, services designed to test access from different countries.


Great idea! Maybe GitHub does some additional checks for determining if somebody is in Iran? Or they have a special way to know if a VPN is used?

I think that some VPN services offer a "random server" access, so you are essentially playing Russian roulette if you just happen to log in via an Iranian server.


Only if you're okay with the legal consequences of sabotaging the company. They absolutely can sue you for it, and you might even face criminal prosecution for such a thing.


There is also another scenario.

I steal with social engineering (or phishing or other method) the GitHub credentials of an employee from a company I wish to harm.

And then I simply log in GitHub(or use a VPN to appear in Iran) with those stolen credentials.

Sounds like a very easy DOS method.


On what basis they are going to sue him? he visited a specific country and than boom. how in the hell are going to prove that he did it in purpose.?


Exactly. Somebody who wanted to do this could simply book a flight where Iran in an intermediate destination.

And then they would say "I had 30 minutes of waiting time in transit and I just wanted to add a comment on my Pull Request".


On the basis of this comment thread :)




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: