2 ms·
> I’d like to see these many occurrences. Some high-profile cases where credentials were leaked on public GitHub: Uber in 2014 and 2021 [1, 2] and Twitch in 20
by SnowflakeOnIce 3y ago
> I’d like to see these many occurrences.
Some high-profile cases where credentials were leaked on public GitHub: Uber in 2014 and 2021 [1, 2] and Twitch in 2021.
> Search is still possible using google and other methods
Yes, you can search with Google or other sources. But the thing is, pretty much only GitHub has easy access to all the code present there, readily available to search within minutes of pushing.
You could try mirroring GitHub yourself, but you'd need enormous disk space and bandwidth, and would quickly hit rate limits. You also wouldn't be able to do fast full regex search like you can with GitHub's search, as you don't have their search infrastructure.
Hackers are aware of this and do make use of GitHub's search to identify possible leaked credentials. I recently experimented with uploading a dummy AWS credential pair to a public Git repo, and saw that numerous IPs started trying those credentials less than 5 minutes after I pushed.
> any theoretical gains from forcing login are dangerous to count on as vulnerable projects are still vulnerable
Indeed, requiring login is not going to _solve_ the problem. But it could lessen the impact of leaked credentials at large scale, by making it more difficult for automated systems to harvest them.
Perhaps more significantly, requiring login could give better audit trails in incidence response situations, as the logs would indicate which accounts were searching for secrets.
> I think the solution to projects with hard coded credentials are to make the credentials easier to find and exploit so they fixed more quickly after being created
Yes, this can help! There are several other companies that specialize in secret detection. I've also written Nosey Parker, a fast regex-based detection tool that has higher-precision rules than similar tools [4]. GitHub also has its own offering in Advanced Security to address this problem.
[1] https://www.reuters.com/article/uk-uber-tech-lyft-hacking-exclusive/exclusive-in-lawsuit-over-hacking-uber-probes-ip-address-assigned-to-lyft-exec-sources-idUKKCN0S20D020151008/ https://www.reuters.com/article/uk-uber-tech-lyft-hacking-ex...
[2] https://www.securonix.com/blog/securonix-threat-research-uber-hack-software-code-repository-vcs-leaked-credential-usage-detection/ https://www.securonix.com/blog/securonix-threat-research-ube...
[3] https://news.ycombinator.com/item?id=28770590 https://news.ycombinator.com/item?id=28770590
[4] https://github.com/praetorian-inc/noseyparker https://github.com/praetorian-inc/noseyparker