3 ms·
> The repositories include a large amount of intellectual property… connection strings, cloud access keys, blueprints, design documents, [single sign-on] passwo
by cryptos 3y ago
> The repositories include a large amount of intellectual property… connection strings, cloud access keys, blueprints, design documents, [single sign-on] passwords, API Keys [...]
That doesn't really sound like security best-practices would be applied. Why don't they use a credential store?
- jamesrr39 3y agoJust guessing as an outsider, but... it's a big, conservative car company trying to do software development. Reasons could include: - Too much red tape/risk assessments/effort/time required to set up a credential store - Devs working there may not know/understand the importance of it, and may not be up-to-date with modern software development practices. - Assumption that Github repo will always be private, correctly configured, never leaked. - Assumption that employee computers with code checked out will always be full disk encrypted and source code never read by a malicious program/transmitted somewhere else. If you work in a company that makes software for a living, it's worth bearing in mind you are probably nearer the forefront of modern best practices and there are many companies in other industries that do some software as part of, but not the main part of the product, and these do not necessarily focus on software development and therefore may be "as hot" with best practices, to put it mildly.
- mass_and_energy 3y agoI mean, I think it's fair to say that given they're developing their "Drive Pilot" level 2 SAE software, at least some of this code involves life-or-death systems. For that reason alone I'd expect a higher level of security awareness, so seeing how unhygienic their repos are from a sec perspective is a bit unsettling.
- kdmccormick 3y agoAgreed it is unsettling. For what it's worth, there's some peace of mind in that this software is probably tested much more thoroughly than the average piece of Web software or whatever. Version control / security best practices / clean code may be too abstract for these old companies, but testing isn't. You'd hope.
- 8organicbits 3y agoI do freelance security consulting. There's a cultural element to security that, when missing, leads to obvious problems like this. I'm struggling to think of an engagement where I didn't find improperly stored plaintext credentials somewhere. Credential stores are a constant recommendation.
- AlwaysNewb23 3y agoIt seems like they made a lot of assumptions that something like this wouldn't happen. They assumed employees would never leak secret information, and that their GitHub repos would never be exposed. They could've used https://doppler.com https://doppler.com or AWS Secrets Manager (https://aws.amazon.com/secrets-manager/ https://aws.amazon.com/secrets-manager/) and never had this problem. It's a little too easy to get comfortable thinking things work well the way they are. This should be a warning to other companies to seriously evaluate how they're storing and managing application secrets and credentials.