2 ms·
12K hardcoded API keys and passwords found in public LLM training data
- deleted 2y ago[deleted]
- st3fan 2y agoI find it disingenuous to call this out as "public LLM training data". It was found in common crawl (which is a great source for all kinds of publicly crawled data) but the REAL problem here of course is poor credential management by the actual websites. Maybe instead of trying to shift the blame to LLM training data, talk more about the poor state of good security practices in general? I mean yes you can probably find these back with a discussion with an LLM but you know what is even simpler? Just download the raw data from Common Crawl and run a credential matcher on it ...
- toomuchtodo 2y agoCommon Crawl could implement what GitHub does; when a secret is detected, report it to the issuer and invalidate it. This encourages improved credentials management, as your (or your application’s) access will be revoked as soon as it’s detected and shipped for invalidation. If someone from Common Crawl sees this and is interested, I would be willing to discuss a directed donation to the 501c3 to implement this functionality (as it appears there is a lot of leverage to be had wrt global security posture with such an implementation). https://docs.github.com/en/code-security/secret-scanning/introduction/about-secret-scanning https://docs.github.com/en/code-security/secret-scanning/int... https://docs.github.com/en/code-security/secret-scanning/secret-scanning-partnership-program/secret-scanning-partner-program https://docs.github.com/en/code-security/secret-scanning/sec...