3 ms·
This does not cover the only scenario which I was hoping it would. I accidentally pushed my api key/password to github and I want to "undo" that push and compl
by johnnymonster 11y ago
This does not cover the only scenario which I was hoping it would. I accidentally pushed my api key/password to github and I want to "undo" that push and completely remove the history locally and on an origin? This is so obscure across many different outlets. And go ahead, flame me for pushing my password/api key to github, but all of you know you have done this at least once in your life!
- deleted 11y ago[deleted]
- akerl_ 11y agohttps://help.github.com/articles/remove-sensitive-data/ https://help.github.com/articles/remove-sensitive-data/ That said, as the article points out, you need to consider them compromised once they've been pushed and rotate the creds.
- pimlottc 11y agoTo add to this, this is not just good paranoid practice. Don't just think you're safe because you fixed it 5 minutes later and probably no one noticed. There are sites that monitor the global github commit feed looking for things like AWS credentials and SSH keys. If it's been pushed to a public github repo for even a moment, it's been grabbed.
- scott_karana 11y agoEven slightly more obscure things, like the config file for Sublime SFTP (`sftp-config.json`) have been personally observed as a target of crawling.
- seanp2k2 11y agoIt's still useful to know how to use e.g. BFG for e.g. Situations where you push a password to private git / GH :)
- hrez 11y agoIf it is a public repo it's compromised, period. Change keys/passwords ASAP regardless of what you do with the repo.
- guiambros 11y agoIf you pushed something (publicly) to GitHub, there's no undo: you HAVE TO change your keys now. Your keys were immediately ingested and compromised a few seconds after you pushed, and likely even before you realized what you've done. To paraphrase from my own comment last month [1]: "Some time ago I published my blog to GitHub, with my MailGun API key in the config file (stupid mistake, I know). In less than 12 hours, spammers had harvested the key AND sent a few thousand emails with my account, using my entire monthly limit. Thankfully I was using the free MailGun account, which is limited to only 10,000 emails/month, so there was no material damage. And MailGun's tech support was awesome and immediately blocked the account and notified me, reseting the account after I had changed the keys." If you're wondering how they were able to harvest GitHub commits so quickly, just read the article linked in that thread [2]. Basically you have bots drinking from GitHub's events firehose and the GHTorrent project. Every commit is monitored and harvested for passwords on the fly. [1] https://news.ycombinator.com/item?id=8818035 https://news.ycombinator.com/item?id=8818035 [2] http://jordan-wright.com/blog/2014/12/30/why-deleting-sensitive-information-from-github-doesnt-save-you/ http://jordan-wright.com/blog/2014/12/30/why-deleting-sensit...
- seanp2k2 11y agoNice, so now we need to make honeypots which post to GitHub tons of things that look like real secrets but with broken credentials, monitor logins for those things, and start a blacklist of compromised / malicious systems (which would be the things trying with those logins).
- Zardoz84 11y agoThis last week, I accidentally pushed a github apikey (my dot files repo). Github send me an mail saying that they disabled these api key, on less that 1 minute. So, I created a new api key, and I changed my fish config file to read the api key from an private file.