FYI: Data from deleted GitHub repos may not actually be deleted
ID: 245a8c64-768d-5ca9-b92b-d2a3dbbf14dc
STIX ID: report--245a8c64-768d-5ca9-b92b-d2a3dbbf14dc
Feed Name: The Register (Security)
Truffle Security demonstrated that GitHub's fork and dangling-commit behavior (called Cross Fork Object Reference, CFOR) can expose deleted or private repository data — including API keys and private keys — via forks or partial commit-hash enumeration; researchers recovered dozens of valid keys from deleted forks. GitHub says this is documented, intended behavior, while Truffle Security recommends platform changes (isolate fork object pools and provide true permanent deletion) to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
