5 ms·
Is there a reason github can’t just have a setting to prevent you from pushing secrets in the first place? Is it really that processing heavy?
by wallscratch 5y ago
Is there a reason github can’t just have a setting to prevent you from pushing secrets in the first place? Is it really that processing heavy?
- nomoreplease 5y agoI assume they could. Meanwhile, I’ve used the git-secrets tool
- psanford 5y agoYou might have strings that match one of their secrets regex's that are not an actual secret. It would be extremely annoying if they blocked you from pushing a commit in that case.
- Aissen 5y agoBut they have the secrets, can't they check that it's the actual secret ?
- atatatat 5y agoFrom the security side, thaaat sounds like a can of worms.
- psanford 5y agoGithub doesn't check if the secrets are real or not. Any string that matches one of the regexs gets shared with the appropriate API provider. The provider checks to see if the its a valid credential or not and revokes the key if necessary.
- cnorthwood 5y agoIt's more to avoid false positives. I've had bug bounty hunters flag secrets in my projects before looking for a bounty, but in actuality it was some random string in a variable named AWS_ACCESS_KEY etc that we used in a unit test (which mocked out the SDK but still expected the config values to exist at init)
- Aissen 5y agoI'm wondering if this couldn't be used as a way to confirm or search for secrets: push huge files with many "secrets", if it's rejected, then you know it has a valid one, then rince and repeat with a binary search to find the one.