Live data from Hacker News

Show HN: GitMonKey – monitor your repos and commits for exposed private keys

gitmonkey.io

11–20 of 50 posts

Re: Show HN: GitMonKey – monitor your repos and commits for exposed private keys

#11
Before I allow this read access to all of my code, what kind of checks should I run through on GitMonKey as an organisation/product?

Edit: when I try to go back to the homepage from the "Install GitHub Integration" page, I'm redirected back. Probably just paranoia.. but still. I want to learn more about the people behind this before clicking this button.

Edit 2: no Twitter, no incorporated entity, no names of the people behind this, nothing to reassure. No account management screen I can see, no way to revoke GitMonkey's access. Is this just a massively dodgy idea?

Re: Show HN: GitMonKey – monitor your repos and commits for exposed private keys

#12
post #11

Before I allow this read access to all of my code, what kind of checks should I run through on GitMonKey as an organisation/product? Edit: when I try to go back to the homepage from the "Install GitHub Integration" page, I'm redirected back. Probably just paranoia.. but still. I want to learn more about the people behind this before clicking this button. Edit 2: no Twitter, no incorporated entity, no names of the peo…

It's a product of Tikal Lab, which is a unit in http://tikalk.com

Re: Show HN: GitMonKey – monitor your repos and commits for exposed private keys

#13
Sounds like a scam to me:

- No imprint or any other kind of information who is behind this service on their website

- Testimonials which talk about leaked credentials and not about how GitMonkey saved them

- Not even a privacy policy stating what they do with your source code

Re: Show HN: GitMonKey – monitor your repos and commits for exposed private keys

#14
post #6
post #3

Earlier quoted context omitted.

Agreed. Or software you can just run internally. Not a fan of just opening up read access to my code to a new startup.

Yeah, what if gitmonkey accidentally reveal a secret key? Now somebody has a curated list of everyone's git's secret keys - even the ones in private repos!

If GitMonkey has your key on record - it means we're not the only ones having it. You should revoke it immediately. So even if our db is breached, it should only contain a list of useless revoked keys.

Re: Show HN: GitMonKey – monitor your repos and commits for exposed private keys

#15
post #11

Before I allow this read access to all of my code, what kind of checks should I run through on GitMonKey as an organisation/product? Edit: when I try to go back to the homepage from the "Install GitHub Integration" page, I'm redirected back. Probably just paranoia.. but still. I want to learn more about the people behind this before clicking this button. Edit 2: no Twitter, no incorporated entity, no names of the peo…

It's a product of Tikal Lab, which is a unit in http://tikalk.com

Forgive me if I don't take your word for it!

Re: Show HN: GitMonKey – monitor your repos and commits for exposed private keys

#16
post #13

Sounds like a scam to me: - No imprint or any other kind of information who is behind this service on their website - Testimonials which talk about leaked credentials and not about how GitMonkey saved them - Not even a privacy policy stating what they do with your source code

It's a product of Tikal Lab, which is a unit in http://tikalk.com

We will add a privacy policy, didn't even notice we don't have one, it's just launching...

Re: Show HN: GitMonKey – monitor your repos and commits for exposed private keys

#18
post #13

Sounds like a scam to me: - No imprint or any other kind of information who is behind this service on their website - Testimonials which talk about leaked credentials and not about how GitMonkey saved them - Not even a privacy policy stating what they do with your source code

It's a product of Tikal Lab, which is a unit in http://tikalk.com We will add a privacy policy, didn't even notice we don't have one, it's just launching...

I would say that if you've forgotten to consider this side of things, it's a big stretch to ask people to trust your app to read all of their source code, which even has the intent to find secrets. What else have you forgotten?

Re: Show HN: GitMonKey – monitor your repos and commits for exposed private keys

#19
post #15

Earlier quoted context omitted.

It's a product of Tikal Lab, which is a unit in http://tikalk.com

Forgive me if I don't take your word for it!

that said I will try to fix everything you mention and make it more comfortable for new ppl to join, thx for the feedback!

Re: Show HN: GitMonKey – monitor your repos and commits for exposed private keys

#20
post #9

Weirdly AWS and GitHub seems to have something similar. I know a couple of folks (not me!) who've uploaded AWS credentials to OSS projects on GitHub and been contacted by AWS about it, after AWS has revoked the credentials.

For AWS it makes sense, because typically AWS discounts the customer the damage made by stolen credentials.

For example, if a dozen EC2 instances are launched with credentials poached from Github to mine bitcoins, I know AWS used to remove the rogue extra charge from the customer bill, as a token of gratitude (to avoid losing the customer by a sense of defenselessness).

Post reply on HN