Standards describe existing behaviour of value that benefits from a single interface. For that, the behaviour has to be first demonstrated. That's how the envelope is pushed. You make an implementation, then you show how that solves something worthwhile, and then if there are multiple implementations that could benefit from a single interface, you do that.
Ideally you’d have an endpoint that returns a set of patterns to check for and a way to submit a set of tokens for checking, along with some kind of context. It would probably be something like what GitHub requires[1].
Unfortunately that has somewhat limited value when GitHub can do most of the legwork for you, and as the de-facto place to publish code the majority of “accidental secrets exposed in code” are leaked there.
1. https://docs.github.com/en/code-security/secret-scanning/sec...
These specific expressions may contain non-public information about the structure of the tokens.
But imagine we live in a world where companies are OK with exposing this information publicly and investing time in keeping the expressions up to date.
Now what? How do you report it to services whilst stopping abuse? Like, if the code isn’t public then all this is an endpoint to let anyone to disable another users (or companies) key without any explanation or recourse.
Pushing to GitHub is actually quite an elegant solution to these issues I think, even if I do think it is a bit too centralized.
I wouldn’t like to wake up to an email that says “your key has been disabled because someone anonymously reported is as leaked, sorry if this has broken your entire system”.
What do you do with this, outside of obviously quarantining and/or disabling the key? How was it leaked? What’s the context?
1. Are not malicious
2. Have access to a key
3. Are unable or unwilling to commit it to GitHub
It would be great if this stuff was public and available without a central authority. But after working on it for a while it seems like a fairly good compromise.
There are three issues with the use of GitHub here:
1. Not everybody knows that AWS will invalidate tokens committed into a public GitHub repository.
2. There is a window (67 seconds according to OP) in which the compromised token is public but working. For the “small intersection of people”, you could bring it down to 0.
3. GitHub protects GitHub keys, and apparently AWS keys, but does it protect Azure keys? Or GCP keys?
A few cycles ago [4] sudhirj pointed out that you could just use an actual URL as your secret key and have that be the URL you visit to revoke it, and I think that is genius.
[1] https://news.ycombinator.com/item?id=34009442
[2] https://news.ycombinator.com/item?id=31335081