GitLeaks – Search engine for exposed secrets on GitHub
gitleaks.com
gitleaks.com
Instead of informing the owners of repositories by creating an issue, you create a search engine to expose them, and then ask to be paid for usage of this index? The only reason someone would want those secrets is to abuse them. This is basically the only use case for the data. Why do this?
This is coming from "fallible.co" whose homepage says "Prevented 40 million+ users personal data leaks". So you are in the business of making sure people's information does not get leaked, and at the same time expose people's secrets?
Also, notifying via a GitHub issue is, in my opinion, a terrible idea. GitHub has no concept of a security issue viewable only to the repo maintainers, so filing a public issue might make things worse (by calling public attention to it). A paid search engine without any notification is probably worse, but maybe they are emailing the repo's committers? They may even be embargoing the search results for a period of time.
Ideally this scanner would be a feature of a Github or a Bitbucket or a Gitlab, etc, itself. They could've decided to contact them to add this as a feature, or decided to contact repository owners, but instead they decided to sell the data publicly. Real shame.
Yes, more people will burned by making these data more easily available to the public - but as a result of those people being burned, security for the community as a whole will be improved over time.
An example of this is what happened with Facebook. Prior to 2013, most users logged in to Facebook without using HTTPS. A Firefox-based tool was released that sniffed for Facebook traffic over WiFi and snagged the other users' cookie to allow for easy session hijacking (Firesheep). Shortly after Firesheep started getting press coverage Facebook enabled HTTPS-by-default[1].
I think it's perfectly valid to argue whether or not the short-term harm caused by this sort of thing is justified by the longer-term benefit, but I don't think it's quite fair to say that the only reason to offer it is to enable abuse.
[1]: https://www.facebook.com/notes/facebook-engineering/secure-b...
https://github.com/dxa4481/truffleHog - "Searches through git repositories for high entropy strings, digging deep into commit history"
https://github.com/ezekg/git-hound - "Hound is a Git plugin that helps prevent sensitive data from being committed into a repository by sniffing potential commits against PCRE regular expressions"
https://github.com/michenriksen/gitrob - "The tool will iterate over all public organization and member repositories and match filenames against a range of patterns for files that typically contain sensitive or dangerous information"
https://github.com/awslabs/git-secrets - "Prevents you from committing passwords and other sensitive information to a git repository"
We are removing the search functionality and account upgrades right now until we can come up with a better solution to inform people about secret leaks. For now, you can simply use the existing Check my GitHub button to scan your public repos.
It would be more helpful though if such a search engine could auto create an issue on github when exposed secrets come up in a search result.
This is different than what people label as 'echo chamber'. In there you'd have either 100% love or hate.
Having mixed responses verging toward hate, says you screwed up and the general public doesn't approve of it.
If anything what they're doing might help shine a light on how big of an issue this actually is and provide a helpful corpus of data to train algorithms on to detect this better.
The issue at this point is far too big to be able to go around and notify everyone about this. There's also plenty of repositories that are abandoned or maintainers that are MIA so you'll never be able to properly resolve all of it.
However, account for the fact that not all HN readers are from US. In other countries what they did is in some case against the law (promoting/enabling criminal behaviour and activities/etc).
Most have come to the middle and settled on a "responsible disclosure" paradigm, where researchers notify the maintainers and work with them to set a reasonable timeline for the correction of the issue. The issue is publicly disclosed somewhere between 30-90 days after the private disclosure to maintainers; this gives them time to correct the issue and push out updates, and it also incentivizes them to fix the issue instead of sitting on it forever and allowing it to be exploited as a zero-day.
It would've been good to see this paradigm applied here; the search could've sent a message to the repository owner with a note that the result would become public in 60 days, and to ensure all keys had been rotated and that secrets were no longer stored in git after that point.
In any case, none of these people are operating from a morally dubious perspective. I would suggest you refrain from impugning their motives. Virtually everyone in the security community has the end goal of promoting secure software. Aggressive full disclosure advocates believe that their methods will work most effectively not only at getting issues that exist fixed ASAP, but also at ensuring companies adopt strong and safe practices moving forward, since there won't be second chances.
It also seems as though the only use of this site is to capitalise on other people's mistakes? It looks like you're just handing over leaked data to people who will definitely abuse it, which seems to go against your core business of preventing data leaks?
- Shakespeare or something
You could've taken the moral high ground and created a reverse-search such as HaveIBeenPwned[0], whereby you check repos you own.
I hope this gets taken down because the potential for abuse is ripe.
$ whois gitleaks.com | grep Creation
Creation Date: 06-feb-2017
That's an example of using this tech for good.
I am glad to see the search was taken down. There's nothing wrong with the search, but a better use of it would be to educate and inform. I'd be curious to see which kinds of developers are the most likely to leak sensitive data.
I know it's publicly available info but since the original creator of the information didn't directly give it to you, do you still have the usual immunity given to service providers?
Also, just because something is on $PUBLIC_URL doesn't mean the copyright would allow you redistribute it. I'm sure a lot of these projects have either a private license, or more likely, no license at all.
I'm running Chrome, Win 7 on a mildly large display, nothing particularly out of the ordinary.