PharmaLedger-IMI / acdc-components

UC4 Anti-Counterfeiting Data Collaboration
MIT License
3 stars 4 forks source link

Take down request related to email addresses #8

Closed joaoluis-pdm closed 3 years ago

joaoluis-pdm commented 3 years ago
De: ...
Enviado: 26 de maio de 2021 20:48
Para: João Paulo Luís
Cc: IT_SECURITY_CYBER_FUSION_CENTER_IR_TIER2 
Assunto: Merck Contact Information on Your GitHub Page

CAUTION: External E-mail

Proprietary

Greetings,

My name is  ... from Merk’s Cyber Incident Response Team, and we were alert to merck information being listed on GitHub page you are listed as owning. After investigating, the below line was discovered that publicly exposing a Merck employees email (and possible hashed password) and we are kindly requesting you remove this line as Merck does not wish for its employees email to be shared widely on public accessible web pages.

GitHub Link:

...

Thank you for your time and assistance on this matter.

Sincerely,

...
joaoluis-pdm commented 3 years ago
10h20
João Luís (PDM) Hi! If anyone is using the acdc-worskpace from github, please save your modified files somwhere, and start again with a fresh repo clone.There was a security incident, in which an acdc.sql file contained an email addresses.
That file was removed, and the history was purged.
The whole repo history was re-written, and a github support ticket was opened (github says they have already deleted the cache on their side).It is important that, no one with push access, does a merge with a tainted old repo. (The deleted file, and its history, can be accidentaly restored).Best regards,João Luís
11h56
João Luís (PDM) @Bruno Patrao and @Andoni Santos, please acknowledge that you've read the message above. Thank you!
Novo
12h19
Andoni Santos Hi. I have read the message above, and will clone a fresh workspace
Enviado: 28 de maio de 2021 10:14
...

so I guess the removal is done within our possibilities.
...