6 ms·
Wow. Really crazy. I know it was not right to revoke the key, he touched into their system. He probably broke someone’s production. But it was also absolutely
by avg_dev 4y ago
Wow. Really crazy. I know it was not right to revoke the key, he touched into their system. He probably broke someone’s production.
But it was also absolutely the right thing to do. A god mode key floating around for over a year unrevoked, with real human beings’s medical data on the other side… I am glad the post author revoked the key. It is probably too little too late but they did close that door and maybe saved someone some pain: not the negligent development team, but a real patient and human being, perhaps many of them.
- fragmede 4y agoThe lesson here is that there are things worse than downtime. Yeah the site being down is bad but hey, what's worse? Leaking PII all over the place.
- orf 4y agoI tried to highlight this in the post, but the key is a personal user one tied to an email, and the worst that I expect would happen would be that some training scripts break. If this was a production key or something that seemed like it would cause financial harm/downtime, I would have never deleted it.
- OJFord 4y agoHonestly, with this level of competence I wouldn't be surprised if the same admin user credentials were used in application/lambda processor/whatever there is. Not at all saying you shouldn't have done it though!
- 0xbadcafebee 4y agoEven worse: PHI.
- lmm 4y agoSadly, if you measure "worse" in selfish financial terms, the site being down is probably worse for you.
- stefan_ 4y agoPretty sure GitHub runs a system that will automatically revoke every (AWS and other) key to ever become part of a repository.
- whoknew1122 4y agoNot in my experience dealing with customers who had AWS email them saying 'Hey, we found one of your keys on GitHub'.
- philsnow 4y agoI’ve worked on a team where Github was the one who reached out about a leaked AWS secret key, not AWS. They apparently usually do this a few minutes before the key makes it into their search index. It’s not much but it’s better than nothing.
- OJFord 4y agoThat evidently didn't happen here. I do remember reading about that too though, maybe it missed it because it was JSON data not a variable definition or something? https://docs.github.com/en/code-security/secret-scanning/secret-scanning-patterns#supported-secrets-for-partner-patterns https://docs.github.com/en/code-security/secret-scanning/sec... I can't find anywhere that specifies the actual pattern though.
- zhfliz 4y agoit wasn't stored on GitHub. there's a json file on GitHub referencing the download of the source archive, stored on pypi infra. in the tgz you can download from pypi you can find python code containing the secret. https://github.com/orf/pypi-data/blob/main/release_data/i/h/ihip.json https://github.com/orf/pypi-data/blob/main/release_data/i/h/...
- rodgerd 4y agoThey have the tools to do that. You might be horrified by how many shitty developers want all the good guardrails GHE provides switched off, and how many managers will support them because they're a "superstar who gets things done".
- kevin_thibedeau 4y agoIt wasn't right to issue a fraudulent takedown either.
- sbf501 4y agoGitHub always freaks out at me when I include text that even looks like a PEM cert. Too bad they can't scan for AWS key / secret variables too.
- jandrese 4y agoWhat are the chances someone goes and gets a new key and then immediately checks it into git on top of the old key?
- AlfeG 4y agoIs it possible to create another god keys with this key? Will other keys expire also?