7 ms·
Good on them. GitHub secrets cause a lot of problems. They will always create a better idiot but this idiot trap is long past due. I also can’t wait until peop
by flatiron 4y ago
Good on them. GitHub secrets cause a lot of problems. They will always create a better idiot but this idiot trap is long past due.
I also can’t wait until people base64 their creds to get past this. Explaining to some that base64 isn’t encryption tends to be hard so I imagine people will feel safe just base64 and checking it in.
- CSSer 4y agoOr md5. I wouldn’t be surprised to see that from some in PHP land.
- tkanarsky 4y agoHah, provide the hash and have the backend crack it whenever it needs to call the api.
- eloff 4y agoYou're not going to crack a hash for an API key. Not even with MD5. Long random strings are the worst case scenario for trying to reverse a hash.
- CSSer 4y agoI forget the exact details, but if I recall correctly you can crack md5 with a for loop in PHP because you can just iterate through the full character set. Maybe it would take awhile but having seen it in action for shorter examples I doubt that’s going to stop someone sufficiently motivated. Then again, at that point I guess they’d just opt for a tool like hashcat.
- mwint 4y agoThe full character set for an AWS key is super ridiculously huge, like heat death of the universe huge.
- CSSer 4y agoHm, could you provide one as an example? I’m kidding. That’s fair. I was just thinking of ASCII. How many services live up to AWS’ standards?
- eloff 4y agoAWS keys are ascii (hex encoded iirc), but they have so much entropy you could never guess it to reverse the hash.
- jamesfinlayson 4y agoOne I can see now is 40 characters of... not sure - I see uppercase, lowercase, digits and special characters. Maybe it's printable ASCII?
- bombcar 4y agoYour access keys consist of an access key ID (for example, AKIAIOSFODNN7EXAMPLE) and a secret access key (for example, wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY).
- selcuka 4y agoYou can find a collision, but you can't (unless you are very lucky) reverse the hash. The bits are not there.
- CSSer 4y agoOf course not. I’m referring to brute force. The idea that you can’t reverse a hash seemed so obvious to me that I didn’t feel it necessary to disclaim. You can increment characters in php like numbers[0]. It has some funny quirks. It doesn’t loop back around right away. If you write a for loop for that and pass it into the builtin for md5, you can just go until your hashes match. Of course this would take a long time for big hashes and there are other tools that can do this better if you’re motivated anyway. But hey, you can make a fun hash cracker in a few lines if you’re feeling it. My whole point was just that MD5 is fairly weak. Lots of people don’t or at least didn’t use to consider this because it was also (too) convenient. [0]: https://stackoverflow.com/a/3567245 https://stackoverflow.com/a/3567245
- selcuka 4y ago> I’m referring to brute force. The idea that you can’t reverse a hash seemed so obvious to me that I didn’t feel it necessary to disclaim. You are confusing hashing with encryption. There is no general way to reverse a hash, be it brute force or an algorithmic method. There are an infinite number of strings that will generate the same MD5 hash. My point is, your for loop may eventually find a string, but it won't be the original AWS secret, so it won't work.
- Godel_unicode 4y agoWith md5 hashes, the actual password isn’t there whereas base64 encoding is merely another way of representing the same bits. Yes md5 is weak, but it’s Fort Knox compared to base64.
- CSSer 4y agoI’m very much aware of the differences in format and effort. The idea was only tangentially related :/ Also, at the risk of being pedantic, yes, some semblance of the password is definitely there. Someone can happily go off and try to brute force it.
- Godel_unicode 4y agoAs long as we’re being pedantic, no they can’t (well, I guess they can try with no hope of succeeding?). You can find a sequence of bytes which will have the same md5, but you have no way of knowing that it’s the same string of bytes which someone else used to arrive at that md5. As I alluded to in my post, that information is gone.
- depereo 4y agoBase64: if this format wasn't secure why are kubernetes 'secrets' stored in it huh? ;)
- banana_giraffe 4y agobase64 is far too much work. A new dev turned '"AKIAIOSFODNN7EXAMPLE"' into '"AK" + "IAIOSFODNN7EXAMPLE"' to make the security alert go away. Thankfully, the alert was sent to enough people it was caught by someone else, and the key was destroyed before someone outside could have fun with it.
- mbildner 4y agoI remember reading in jshint’s docs that they purposely did not chase this kind of lint since at that point the user is clearly fighting the library.
- reilly3000 4y agoGiven the fact that nobody really does that, I think it was a creative and low risk hack. 1. If you are worried about the people who have access to your codebase abusing a secret, you have a serious people problem that needs to be solved immediately and unambiguously. A motivated internal attacker can do almost anything. Organizations live or die on trust. One doesn’t need to scour for keys break in when they have a badge (or their mate’s) and they built the lock. 2. If you are concerned the secret will be discovered by a generic threat, it won’t, not with this string concatenation. It’s so rare. Should this become a common practice this would be over, retroactively even. We all saw this unfold with with m y e m a I l at y dot com obscurity, until the fine folks who worked on ScrapeBox turned up the right regex to start scraping those too. 3. Nothing else. You are right and responded right. Don’t put keys in code kids. Nobody likes having to erase history in their codebase, especially because of a careless mistake or a deliberate workaround. I’m just saying… of all the dumb shortcuts that can break stuff, this one is one the mostly harmless end of the spectrum.
- woutr_be 4y agoI legitimately recently had to argue with a PM and his developers, that a base64 encoded user ID isn’t considered security best practices for API authentication. Even when I showed them how I can produce the “secret” myself, they kept arguing that I was wrong.
- bryanrasmussen 4y agoOk I've been around for a long time and I don't think I would have met anyone who would have argued that since around 2009, although I guess I can remember secrets and keys going into repos as late as 2018 at places I've seen.
- woutr_be 4y agoIn fairness, the PM was the kind of guy who has no technical experience, but was arrogant enough to pretend like he did, and most of the devs were pretty junior. It was the first time for me having to even argue about this.