Live data from Hacker News

Show HN: GitMonKey – monitor your repos and commits for exposed private keys

gitmonkey.io

21–30 of 50 posts

Re: Show HN: GitMonKey – monitor your repos and commits for exposed private keys

#21
post #6

Earlier quoted context omitted.

Yeah, what if gitmonkey accidentally reveal a secret key? Now somebody has a curated list of everyone's git's secret keys - even the ones in private repos!

If GitMonkey has your key on record - it means we're not the only ones having it. You should revoke it immediately. So even if our db is breached, it should only contain a list of useless revoked keys.

> should

Re: Show HN: GitMonKey – monitor your repos and commits for exposed private keys

#25
post #23

Why should I trust you guys? I also recognize standard templates from miles away. EDIT: found the template http://demo.templateocean.com/premium/template/landx/layout-...

Hilarious. No customization at all!

Except that they disabled the scrolljacking, which is a nice touch at least.

Re: Show HN: GitMonKey – monitor your repos and commits for exposed private keys

#26

Why does it need to auth using Google? Can it not just use GitHub like the second getting started button suggests?

Because we need your email and dont want to take it from GitHub because we may span to gitlab, bitbucket etc

Re: Show HN: GitMonKey – monitor your repos and commits for exposed private keys

#27
post #21

Earlier quoted context omitted.

If GitMonkey has your key on record - it means we're not the only ones having it. You should revoke it immediately. So even if our db is breached, it should only contain a list of useless revoked keys.

> should

I am also really scared by the suggestion that they might 'take a leap' and check if it's valid... Then they have a list of keys and whether they work or not

Re: Show HN: GitMonKey – monitor your repos and commits for exposed private keys

#28

Why does it need to auth using Google? Can it not just use GitHub like the second getting started button suggests?

Because we need your email and dont want to take it from GitHub because we may span to gitlab, bitbucket etc

Hmm could you not just take it from GitHub though. If you chose to span others they could also provide an email or you could link accounts together.
Post reply on HN