you are viewing a single comment's thread
view the rest of the comments
[–] 94 points 4 months ago* (13 children)

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures. Valadon said he reached out because the owner in this case wasn’t responding and the information exposed was highly sensitive.

But wait

Valadon said the exposed CISA credentials represent a textbook example of poor security hygiene, noting that the commit logs in the offending GitHub account show that the CISA administrator disabled the default setting in GitHub that blocks users from publishing SSH keys or other secrets in public code repositories.

“Passwords stored in plain text in a csv, backups in git, explicit commands to disable GitHub secrets detection feature,” Valadon wrote in an email. “I honestly believed that it was all fake before analyzing the content deeper. This is indeed the worst leak that I’ve witnessed in my career. It is obviously an individual’s mistake, but I believe that it might reveal internal practices.”

One of the exposed files, titled “importantAWStokens,” included the administrative credentials to three Amazon AWS GovCloud servers.

This is shameful incompetence. Just head-rolling abysmal incompetence. These are the people they hired, for all you 1337 hax0rz currently looking.

  • source
  • hideshow 13 child comments
  • [–] 12 points 4 months ago (2 children)

    Outside of the sheer incompetence of this administration, is there ANY chance this was done intentionally as a honeypot or something along those lines?

    The fact that the commits were explicit along with bypassing all the checks could read as someone trying to see who knocks on the door.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 9 points 4 months ago (6 children)

    ELIT please.

    Explain like im Trump in case you didn't get the T bit. Sorry.

  • source
  • parent
  • hideshow 6 child comments
  • [+] -7 points 4 months ago* (last edited 4 months ago) (3 children)

    Woke computer nerds fucked us

    Edit: just to reassure the more anxious amongst us, I mean ‘woke’ in the maga sense of anything-i-don’t-like-is-woke. Not actually woke.

    Actually woke computer nerds observe proper security protocols ffs.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 3 points 4 months ago

    Beautiful, woke computer nerds, and they're gonna replace nuclear. My uncle, he was a nuclear woke, and he said, he said you know what, computers are the future, they're gonna replace nuclear. He dosen't have the socks for it, and the electronic wokes, they have these socks that just make the computer work for them, ok, the computer works for them. The computers will work for the nuclear.

  • source
  • parent
  • [–] 6 points 4 months ago

    “Mistake”. Yeah, no. That’s someone thinking policies aren’t meant for them and blindly taking the easiest path. Sounds just like those 1337 hax0rs they gave the keys to

    In a sane world this should get clearances revoked so they never again deal with any private data

  • source
  • parent