We're only one sentence in and I'm already very, very nervous about the author's hubris.
We're only one sentence in and I'm already very, very nervous about the author's hubris.
> What could be done to prevent this?
> Always test new version control GUIs before using them in the wild. There could be a bug that could expose your data.
> Encrypt access keys in config files instead of just leaving them exposed in the config file.
> Better yet, move access keys to a seperate config file, and exclude this from Git deploys with a .gitignore.
The fact this supposedly security experienced and conscious developer thought it was okay to have any kind of access credentials stored in a git repository is glaring.
You should consider all data in any repository public for security reasons. Publishing to github publicly made it quite obvious - but he could have been just as screwed over by people he gave access to the private repositories and people who have broken into github and can directly access the repositories.
Sure the numbers on both those groups are lower than the numbers of people apparently scanning public github for access keys - but the severity of the risk of keeping access keys and other secrets in your revision control are the same.
http://docs.aws.amazon.com/AWSSdkDocsNET/latest/V3/Developer...
How do decrypt them when you app re-launches? How do you decrypt them automatically on every instance?
2. He pushed code to a new repository without verifying the security configuration of the created repository (granted the tool made it easy to do this but you should create a repo, verify it, then push code).
3. He used his master AWS account key/secret in the code which gave global access to everything.
4. He didn't use IAM credentials with a restrictive policy set to just access the resources required.
No, clearly not security concious.
I'm a solution architect in the financial services industry and have been for 16 years. Never do I assume I know what the hell I'm doing.
Also putting keys in (even a private) cloud-hosted repos is at least a step under what I'd describe as "very security conscious" for someone who self describes as working in the financial industry.