Andrzej Dyjak Profile picture
Moved from hacking to securing. Now into Threat Modeling, DevSecOps and Secure by Design.
Hubert Krawczyk Profile picture 1 subscribed
Nov 5, 2020 8 tweets 5 min read
Couple of days ago I conducted a small experiment WRT secrets commited to public git repositories. My plan was simple: (1) Generate a secret, (2) commit it to the public repository, and (3) see what happens. Thread time! 👉

1/8
BTW. For the secret I've chosen AWS key generated with @ThinkstCanary by @haroonmeer et al.

Anyhow, my experiment for @github and @gitlab went as follows...

2/8