4 ms·
I accidentally published[1] my AWS secret key last year because I pushed an old project from college. At the time, I was very new to using source control and ha
by dguo 8y ago
I accidentally published[1] my AWS secret key last year because I pushed an old project from college. At the time, I was very new to using source control and had little idea how to distinguish between what should and shouldn't be committed. I hope colleges and code boot camps go over that sort of info nowadays. The usefulness to effort to learn ratio seems exceptionally high.
[1]: https://www.dannyguo.com/blog/i-published-my-aws-secret-key-to-github/ https://www.dannyguo.com/blog/i-published-my-aws-secret-key-...
- Liveanimalcams 8y agoWhen I attended Hack Reactor they did tell us not to push them. However since they didn't teach us git (they expected us to know it) many still pushed them up. You would know because they'd get an email from some random company/person letting them know that they found their secret keys and that they should enroll/buy their services if they don't know what they're doing. Luckily no one from my class got hosed, but others in the past had.
- aiddun 8y agoMy sophomore year of high school, I was trying to writing a Discord (chat platform) bot for a server I shared with friends and unknowingly included the private key in a public repo I hoped to show them. A specifically written crawler for Discord keys found the key and starting spamming the server with images of very very undesirable things from the far corners of the internet at a rate of hundreds per second. Needless to say I learned my lesson the hard way.
- HNLurker2 8y agoCouldn't we use Google's bigquery to search for private keys?
- sbmthakur 8y agoThanks for sharing! How do people write such crawlers? Do they specifically point them at Github repos?
- yorwba 8y agoThe paper discussed in the article describes writing such a crawler. They simply use the GitHub search API.