Saying that no 'secrets' were leaked is effectively burying the lede.
Saying that no 'secrets' were leaked is effectively burying the lede.
The payout data likely wasn’t ripped from a DB but rather dashboards which customer service or partnerships likely had access to. Tier1 or Tier2 support kinda stuff.
This smells like a stolen backup or maybe network access and http scanning, finding the internal GitHub and maybe a support admin cred that allowed dashboard view.
I would classify that as access to production systems.
The leak includes source code of multiple active websites and applications that are operated under the umbrella of Twitch/Amazon.
Why would an intern have access to this data?
If you're saying that Twitch runs their developer environment in a lousy manner (and you have proof of this), then please go ahead.
But to imply that an intern/average developer would be given access to all this branching information is ignorant.
Maybe the super secure siloed world doesn't really exist outside of military/government organizations.
monorepos are a thing at several companies (e.g. Google).
The other access rights that come from staff access is either incedential or miss /debt in architecture.
"Hey, pick through everything I say with a fine-toothed comb and treat it as the official company stance!"
I suspect that's a lot more controlled these days, but it wasn't very uncommon for signified staff to be trolling along with everyone else.