Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
🦠Toxic Flange (Gurjeet)🔬⚱️🌚
🦠Toxic Flange (Gurjeet)🔬⚱️🌚
@Toxic_Flange@infosec.exchange  ·  activity timestamp 2 weeks ago

hey experienced #devsecops and #infosec people, what’s a good tool to scan got repos regularly for secrets and report on them? what about prevention? thinking a special hit hook pre commit but those can be bypassed. what tools are there for that regardless?

  • Copy link
  • Flag this post
  • Block
Cat 🐈🥗 (D.Burch) :paw:⁠:paw:
Cat 🐈🥗 (D.Burch) :paw:⁠:paw:
@catsalad@infosec.exchange  ·  activity timestamp 2 weeks ago

@Toxic_Flange A nice DDoS tool to take down git or lax management that allows for the devs to play Factorio at work will prevent this!

  • Copy link
  • Flag this comment
  • Block
🦠Toxic Flange (Gurjeet)🔬⚱️🌚
🦠Toxic Flange (Gurjeet)🔬⚱️🌚
@Toxic_Flange@infosec.exchange  ·  activity timestamp 2 weeks ago

@catsalad 😂 With Bitbucket cloud, we just let it do it to itself..

  • Copy link
  • Flag this comment
  • Block
Cat 🐈🥗 (D.Burch) :paw:⁠:paw:
Cat 🐈🥗 (D.Burch) :paw:⁠:paw:
@catsalad@infosec.exchange  ·  activity timestamp 2 weeks ago

@Toxic_Flange No mistakey if always breaky!

  • Copy link
  • Flag this comment
  • Block
Pseudo Nym
Pseudo Nym
@pseudonym@mastodon.online  ·  activity timestamp 2 weeks ago

@Toxic_Flange @risottobias

This is a policy issue.

Ultimately, it isn't the dev's choice (and I say this as a former dev who went into security).

Appeal to their professionalism.

If they truly can't figure out a way to refactor code to remove hard coded creds from the source, you may need better developers.

Correct handling of secrets is hard, but doable. There are existing patterns for this.

Abstraction is your friend. Run time short session creds, vaults, AWS Secrets Manager, etc...

  • Copy link
  • Flag this comment
  • Block
🦠Toxic Flange (Gurjeet)🔬⚱️🌚
🦠Toxic Flange (Gurjeet)🔬⚱️🌚
@Toxic_Flange@infosec.exchange  ·  activity timestamp 2 weeks ago

@risottobias Getting our large team of devs to all install the tools for prehooks is like herding cats. It would eventually get done, but could also potentially be bypassed as many devs believe its the only way to get their app to work (so many hard-coded secrets after I looked at all the repos..)

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.34 no JS en
Automatic federation enabled
Log in
Instance logo
  • Explore
  • About
  • Members
  • Code of Conduct