6 ms·
As a CI company, their ‘customer data’ is source code!
by stuartd 4y ago
As a CI company, their ‘customer data’ is source code!
- heartbreak 4y agoThe story, and the CircleCI post, say the customer data was environment variables and other configuration data. Not source code.
- throwaway892238 4y agoCircleCI has listed literally every kind of credential used by its users as vulnerable. This includes deploy keys that are used to download source code. Anyone who has access to customer data, and a deploy key, can just check out the source code, instantly. The extent to which CircleCI has gone to eliminate all threats is... scary. They've gotten GitHub to invalidate any GitHub access tokens used by a CircleCI customer. They've gotten AWS to e-mail AWS customers if one of their access keys was stored in CircleCI. It's a complete and total compromise of literally every customer secret in CircleCI. I expect this will be the biggest hack of 2023... and it's still January. So, yeah, I'm pretty sure customer source code is up for grabs.
- taspeotis 4y agoWhat do you store in GitHub repos... > Review GitHub audit log files for unexpected commands such as ... repo.download_zip https://circleci.com/blog/jan-4-2023-incident-report/ https://circleci.com/blog/jan-4-2023-incident-report/
- charcircuit 4y agoThe article is referring to how the attacker could use the stolen github tokens to download someone's source code. The source code isn't coming from CircleCI