25 ms·
GitHub already has a program to scan for keys, since publishing Discord tokens by mistake used to get the token immediately revoked and a DM from the system acc
by PokestarFan 9mo ago
GitHub already has a program to scan for keys, since publishing Discord tokens by mistake used to get the token immediately revoked and a DM from the system account saying why
- rao-v 9mo agoYeah I'd hope they were doing this, atleast in repos! Thought the mechanism was a little unclear in your specific example - did Github revoke Discord tokens?
- 3eb7988a1663 9mo agoI thought there were many first and third party services looking for this kind of thing (AWS, Github, GWS, crypto, etc tokens). Seems weird that a F500 company repo was not receiving the regular, let alone extra deep scanning which could have trivially found these. There was a recent post from someone who made the realization that most of these scanning services only investigate the main branch. Extra gold in them hills if you also consider development branches.