Toyota suffered a data breach by accidentally exposing a secret key on GitHub
blog.gitguardian.com
Toyota suffered a data breach by accidentally exposing a secret key on GitHub
1–10 of 272 posts
Re: Toyota suffered a data breach by accidentally exposing a secret key on GitHub
#2Re: Toyota suffered a data breach by accidentally exposing a secret key on GitHub
#3Re: Toyota suffered a data breach by accidentally exposing a secret key on GitHub
#4The access model on platforms like GitHub is flawed, a single account can be used for both professional and personal projects/repositories, leading to “fat finger” errors like this one here...
You cannot access org's repos without VPN
if you create a new repo by mistake outside your org, then uhh..., it's crazy?
it's like sending email with credentials to people outside your org
Re: Toyota suffered a data breach by accidentally exposing a secret key on GitHub
#5"Production keys in source control" is right up there with "mistaken routing table entry" and "fat-fingered DNS config" on the list of critical company-breaking mistakes that you'd think would be easy to avoid, but aren't.
Re: Toyota suffered a data breach by accidentally exposing a secret key on GitHub
#6Could an attacker have remote-unlocked and remote-started the entire Toyota fleet with this access?
Re: Toyota suffered a data breach by accidentally exposing a secret key on GitHub
#7The access model on platforms like GitHub is flawed, a single account can be used for both professional and personal projects/repositories, leading to “fat finger” errors like this one here...
Re: Toyota suffered a data breach by accidentally exposing a secret key on GitHub
#8Re: Toyota suffered a data breach by accidentally exposing a secret key on GitHub
#9The access model on platforms like GitHub is flawed, a single account can be used for both professional and personal projects/repositories, leading to “fat finger” errors like this one here...
Note: the invite input box actually autocompletes ALL github usernames.
Re: Toyota suffered a data breach by accidentally exposing a secret key on GitHub
#10> T-Connect enables features like remote starting, in-car Wi-Fi, digital key access, Could an attacker have remote-unlocked and remote-started the entire Toyota fleet with this access?