4 ms·
Its not the time from discovery to rotating the key thats OPs issue. What was the time from key being public until discovery? Thats the issue. And also, while t
by Msurrow 4y ago
Its not the time from discovery to rotating the key thats OPs issue. What was the time from key being public until discovery? Thats the issue. And also, while the key was public, did anyone access it?
- remus 4y agoAgreed. I don't think that was the point the comment I replied to was making though? Maybe I misread it.
- UseStrict 4y agoMaybe I'm missing something, but since all GitHub events can be watched through the API, I don't think it particularly matters how long it was public. Anecdotal but I once accidentally pushed an AWS key (thankfully heavily locked down and not a root account) for all of 30 seconds and it was compromised anyways.
- Msurrow 4y agoI agree. Even if its only public for one sec it should be considered compromised. However, everything is a risk management question, so knowing the amount of time it was exposed is helpful for other orgs to determine their response to this incident. Same if there was an accesslog.