4 ms·
> I still think the exfiltration threat is the worst. Any secret injected into the environment of any tested codebase is vulnerable -- especially if your logs a
by cm3 10y ago
> I still think the exfiltration threat is the worst. Any secret injected into the environment of any tested codebase is vulnerable -- especially if your logs are public.
Fair point, though instead of worrying about that, I think the real solution is to have test-only keys and also make sure logs can be shared without fear of leaking data.
- jacques_chester 10y agoWe (buildpacks team) get some of the way by ensuring that all secrets in our logs are redacted -- we actually wrote a rough-and-ready tool (concourse-filter[0]) for this purpose. It works on a whitelist principle. Any environment variable emitted to stdout or stderr is redacted unless it appears on a whitelist[1]. You're right that in the longer run, providing per-test keys will be the safest option. It's on our radar as part of the overall "3 Rs" effort[2]. [0] https://github.com/pivotal-cf-experimental/concourse-filter https://github.com/pivotal-cf-experimental/concourse-filter [1] https://github.com/cloudfoundry/buildpacks-ci/blob/1c345c30e1f9bcabf7d56cfe78ab70d0104cd0c4/build/filter.sh https://github.com/cloudfoundry/buildpacks-ci/blob/1c345c30e... [2] https://medium.com/built-to-adapt/the-three-r-s-of-enterprise-security-rotate-repave-and-repair-f64f6d6ba29d#.tefbtzegc https://medium.com/built-to-adapt/the-three-r-s-of-enterpris...
- cm3 10y agoRight. Unfortunately, Rotate and Repave are not common practice, just like periodically restoring backups isn't.
- jacques_chester 10y agoWe're working on it. One day I expect it'll be considered normal.