Live AWS keys in 75 throwaway repos, each made public for one of five windows from 60 seconds to 12 hours, every use logged. The keys were tripwires; the real question was who notices a private repo going public, and what they do once they’re in.

The most useful finding is the dull one: re-hiding the repo does nothing. One busy harvester kept re-validating the captured keys for a day after the repos went private again. Only rotating the key stops it.

This came out of building a monitor for exactly these repo-setting changes.

  • peternovakdev@programming.devOP
    link
    fedilink
    arrow-up
    4
    ·
    5 days ago

    Fair to call out. This did come out of me building a product in the space, and I’d rather disclose that than bury it. The method and numbers are real, happy to get into either.

    • squaresinger@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      5 days ago

      Yeah, the article was a good read, nothing wrong with that. But I think it’s important to make it clear what the intent is.