3 ms·
I can understand how AWS can react quickly using the secrets scanning service but how do malicious actors do it without having access to that service?
by pmx 4y ago
I can understand how AWS can react quickly using the secrets scanning service but how do malicious actors do it without having access to that service?
- Gordonjcp 4y agoLuck, I guess? Maybe they have a bot watching some "latest thing on github" API, that scans everything coming in for credentials.
- blibble 4y agothere's a public firehose feed of everything on github https://api.github.com/events https://api.github.com/events (not sure why really)
- andy_ppp 4y agoIt says in the docs this API is delayed 5 minutes though. So no idea how they did things this quickly unless you can add a webhook to every repository somehow as it is created? It's probably just polling and luck to be honest.
- chpatrick 4y agoMaybe the 5 minutes delay is so partners like AWS get a chance to scan first. https://docs.github.com/en/code-security/secret-scanning/about-secret-scanning#about-secret-scanning-alerts-for-partners https://docs.github.com/en/code-security/secret-scanning/abo...