Exposing Secrets In Code @marknca
Exposing Secrets In Code  @marknca
Uploaded April 2019 | Updated September 2026, 2 weeks ago
A recent study by NCSU found that there are way more API keys and tokens uploaded to GitHub than previously thought. In fact, there's almost a near constant stream of secrets being exposed...why?!?

It boils down to operational security. Automated build pipelines and access to cloud services that amplify what your team is capable of. Moving faster without some smart guardrails can lead to these issues.

The good news? A cybersecurity view of the same tool sets that are exposing this lack of opsec can help address it. Automated checks for secrets, tools specifically designed to handle secrets, and education around these issues can help reduce the likelihood of recurrence or prevent it from happening in the first place.

References;
- the research page from NCSU (PDF), ndss-symposium.org/wp-content/uploads/2019/02/ndss2019_04B-3_Meli_paper.pdf
- recent MongoDB issues via Brian Krebs, krebsonsecurity.com/tag/mongodb

// MWM Y2 no. 022
Exposing Secrets In CodeUsers Experience Is CriticalLazio & BlackMatter Bring Ransomware Into the Spotlight…Again #shortsFacebooks F8 & Information ManagementDelivering Information With ContextFacebooks 10 Year ChallengeRansomware Attack On Kaseya Still Very Real For Victims #shortsOptimize Your ToolsCheck Out SEC308-S At AWS re:Invent 2018Signals And The Data ExplosionNew Ransomware Resources For Defenders #shortsRoad to AWS re:Invent 2019 // Introduction to AWS Lambda
marknca |

Exposing Secrets In Code

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER