Wow, yeah. I'd love to know what the source of that is all about, personally. I mean, my initial thought was "oh, it's a younger crowd here, they haven't shot themselves in the foot enough to be able to empathize with the situation", but age doesn't matter ... experience does. It's a simple fact that if you're writing software, it doesn't matter how good you are, over time "the house always wins." And this is a crowd that has
plenty of experience.
Thousands of comments from other stories and stories themselves are rife with "how I deleted our entire production database with this one cool trick" stories -- things that are orders of magnitude worse on the "blunder scale". And it's not that these are "stories of humility", i.e. the author is writing because they want to tell you how dumb they are. They're, minimally, warning tales (because you will make a mistake this bad at some point). Sometimes they're stories meant to make the author feel better for having made the ridiculous blunder (I can relate to that). :)
Usually those stories are not filled with a bunch of comments along the lines of "You really should have known better given the work you do". No kidding?!
> Just bc someone has a Github account doesn't mean they're some sort of super hacker
Well stated. I'd add "just because they're some sort of super hacker doesn't mean they're any less likely to to make the same mistake/be tricked into doing something like this" ... including if the permissions were more clear. It's the old "Mechanic's Car" (which hasn't had its oil changed in 15,000 miles).
The party deserving of harsh penalties is the product implementing Github's API, alone, in my opinion. Here's my thinking: change the scenario, slightly. Imagine I use "login with Github" in a tool that's distributed by a trusted third-party, that spells out exactly how they use those permissions in a clear manner at login and then uses them exactly as they state. Several years down the road, the company is sucked up by someone "not as trustworthy". It's possible they dropped an e-mail about an update to their application Terms & Conditions and buried deep within there is something about consenting to allow them to "star their repositories". Even if they sent a one-sentence e-mail in bright red letters saying they were going to do it, in all likelihood, GMail didn't put it in my Priority Inbox, so I missed it. :)
The "typical exposure a user (including a super hacker) has to 'consent dialogs'" on a PC are the kind that ask for permission "to sign me in and see minimal profile information". On a phone, the things they're asking for are things that "if I give them permission to, I'm not usually allowing them to harm an internet community in a general sense" like "star farming" would. I think seeing these dialogs as frequently as we do might work against paying more attention to them ... regardless of the fact that we know the kind of damage and we'd probably assign more blame to ourselves than is warranted.
All of that said, there's probably more to the story. Unless something stated is fabricated, I can't think of a detail that could be added to the story that would make me feel a permanent ban is justified. I can think of reasons I would be sympathetic to Github initially banning the account (due to AI/automation) and then unbanning the account after "a human being saw that this was something close enough to phishing" that the account should be restored.