5 ms·
I guess that's one way to get attention to your business. Instead of informing the owners of repositories by creating an issue, you create a search engine to e
by flipp3r 10y ago
I guess that's one way to get attention to your business.
Instead of informing the owners of repositories by creating an issue, you create a search engine to expose them, and then ask to be paid for usage of this index? The only reason someone would want those secrets is to abuse them. This is basically the only use case for the data. Why do this?
This is coming from "fallible.co" whose homepage says "Prevented 40 million+ users personal data leaks". So you are in the business of making sure people's information does not get leaked, and at the same time expose people's secrets?
- deleted 10y ago[deleted]
- kiallmacinnes 10y agoThere are non-abusive uses of this kind of data, e.g. security researchers, or IT departments outsourcing credential leak scanning, etc.. Also, notifying via a GitHub issue is, in my opinion, a terrible idea. GitHub has no concept of a security issue viewable only to the repo maintainers, so filing a public issue might make things worse (by calling public attention to it). A paid search engine without any notification is probably worse, but maybe they are emailing the repo's committers? They may even be embargoing the search results for a period of time.
- flipp3r 10y agoTheir FAQ indicates they update the index every two months, but no information on what they do with the data in the meantime. Ideally this scanner would be a feature of a Github or a Bitbucket or a Gitlab, etc, itself. They could've decided to contact them to add this as a feature, or decided to contact repository owners, but instead they decided to sell the data publicly. Real shame.
- kiallmacinnes 10y agoI do remember reading something about GitHub preventing some keys from being pushed (AWS secrets etc?) But it's a vague memory from a long time ago!
- johncolanduoni 10y agoIf posting individual issues in each project, likely to be seen first by contributors is a bad idea, how is creating a paid search engine likely to be used by people who specifically want to find secrets and not likely to be used/seen by contributors a good thing?
- kiallmacinnes 10y agoI didn't say it was a good thing (or a bad thing), only that there are legitimate use cases and that the suggested notification method would be, in my opinion, terrible security practice...
- LyndsySimon 10y agoI strongly disagree with this reasoning. Yes, more people will burned by making these data more easily available to the public - but as a result of those people being burned, security for the community as a whole will be improved over time. An example of this is what happened with Facebook. Prior to 2013, most users logged in to Facebook without using HTTPS. A Firefox-based tool was released that sniffed for Facebook traffic over WiFi and snagged the other users' cookie to allow for easy session hijacking (Firesheep). Shortly after Firesheep started getting press coverage Facebook enabled HTTPS-by-default[1]. I think it's perfectly valid to argue whether or not the short-term harm caused by this sort of thing is justified by the longer-term benefit, but I don't think it's quite fair to say that the only reason to offer it is to enable abuse. [1]: https://www.facebook.com/notes/facebook-engineering/secure-browsing-by-default/10151590414803920 https://www.facebook.com/notes/facebook-engineering/secure-b...
- zensavona 10y agoWhy not just write a quick script to send them all an automated message/ticket a week before this is live and then run it on archived data? You can do both at the same time.
- himot 10y agoLol wrong way of marketing own business. Purely nonsense :/ Everyone knows there are secrets on Github.