Stop Secrets Creep Across Developer Platforms
These articles are AI-generated summaries. Please check the original sources for full details.
Dark Reading Confidential: Stop Secrets Creep Across Developer Platforms
Dark Reading Confidential Episode 13 highlighted the increasing exposure of sensitive enterprise information by developers; 23 million secrets were found in public spaces last year alone. The podcast featured experts discussing the causes and potential solutions to this growing problem.
The ideal model assumes developers follow security best practices, but reality shows credentials, API keys, and other sensitive data are increasingly found in code repositories, CI/CD pipelines, and collaboration tools like Slack and JIRA. This widespread exposure creates significant risk, with potential for data breaches, financial loss, and reputational damage—attacks are happening through these tools more often than previously thought.
Key Insights
- 23 million secrets exposed: GitGuardian reported finding 23 million secrets in public spaces in the past year (2024).
- Convenience vs. Security: Developers often prioritize speed and convenience, leading to shortcuts that expose secrets.
- Temporal for Secret Management: Temporal is used by companies like Stripe and Coinbase for managing stateful workflows, offering a more secure alternative to traditional methods for handling sensitive data.
Continue reading
Next article
Cracks in the Foundation are Showing as More Developers Use AI
Related Content
Why Secrets in JavaScript Bundles are Still Being Missed
Scanning 5M apps uncovered 42K exposed secrets in JavaScript bundles, highlighting shortcomings in current SAST and DAST practices.
Challenging Google Play Security: A Technical Proposal for Manifest-Level Verification
Developer Indigotime proposes replacing Google's identity verification with technical declarations of public keys and hardcoded web addresses to stop data interception.
Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors
AI-driven attacks leaked 23.77 million secrets in 2024, highlighting critical gaps in traditional security frameworks like NIST, ISO, and CIS.