3 ms·
My comments from the other thread: https://news.ycombinator.com/item?id=15963787 https://news.ycombinator.com/item?id=15963787 Very interesting. I wonder if an
by graystevens 9y ago
My comments from the other thread: https://news.ycombinator.com/item?id=15963787 https://news.ycombinator.com/item?id=15963787
Very interesting. I wonder if any private organisations setup a pseudo/canary repositories, that when pulled triggered an alarm? Or simply contained some monitored API keys or credentials to spot any activity/Insider threats.
Might be a neat idea for those businesses that are concerned about their private repos (either cloud hosted or self hosted).
May have picked up if anyone was able to exploit this.