Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mcdwayne
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
mcdwayne
1y ago
This was on public GitHub, which anyone can scan for anything. Their API is a firehose you can consume: https://api.github.com/events GitGuardian's public report on secrets sprawl talks about their methodology of scann
2.
▲
by
mcdwayne
3y ago
Basically, rotate as soon as you can* and start looking through your AWS logs and setting to see if any services you don't recognize have been spun up. Is you think you have been attacked or see stuff you did not spin up, contact AWS s
3.
▲
by
mcdwayne
4y ago
When will devs stop hardcoding passwords? smh.
4.
▲
AstraZeneca patients data exposed for over a year due to password snafu
(techcrunch.com)
48 points
by
mcdwayne
4y ago
|
6 comments
5.
▲
by
mcdwayne
4y ago
Another take: https://blog.gitguardian.com/dropbox-breach-hack-github-circ...
6.
▲
by
mcdwayne
4y ago
FYI - GitGuardian is free for individuals and teams smaller than 25
7.
▲
by
mcdwayne
4y ago
Yikes. It is sad to hear stories like that, where security is not a concern until panic sets in. :( Yet another reason we need to adopt standards like security.txt and make it easy to report these things as it is to tell robots to ignore
8.
▲
by
mcdwayne
4y ago
Toyota is claiming no, not with this leak. It was a partial repo that was exposed. The data they accessed with the key got customer ID numbers and emails only.