Home Depot GitHub token exposed for a year, granted access to internal systems
121–130 of 169 posts
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#122Earlier quoted context omitted.
Right, so you can't opt-out of it.
I went to Wi-Fi settings, "Edit" in top right, scroll to bottom "Managed" section, and was able to turn off "Auto-Join" for the "t-mobile" managed network just fine. I did this many months ago, I think because I was infuriated at the idea of auto-connecting to a Wi-Fi network I did not opt in to, but regardless, the checkbox has remained off through a few OS updates since (on 26.1 now with a T-Mo prepaid eSIM).
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#123Took me a good 10-15 minutes to _just_ _find_ where Gemini/AI Studio/Vortex projects keys _might_ be! I had to "import project" before I could find where the key is. Google knew key was exposed but the key seemed to be still active with a "!" next to it!
With a lot of vibe coding happening, key hygiene becomes crucial on both issuer and user ends.
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#124What's the biggest damage someone could have done with that info?
- Depending on whether they use GH for deployments they can also introduce features to production that can help them
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#125Given the absolute state of their website on mobile it's hardly surprising. It's faster to find an employee and ask them where an item is at instead of waiting for the search to finish, see that it the "current store" now points to a random location somewhere in a different state, pick the correct store and re-do the search
If you go to the home depot page for torque wrenches and click the filter for drive size, you get this list: 1/2 in 1/4 in 1 in 3/8 in 3/4 in Specialty Here is the same list in decimal to make the insanity plainly obvious: 0.5 0.25 1 0.375 0.75 What sadistic lunatic made that sort order?! It's not based on size and it's not alphabetic.
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#126Last week I accidentally exposed my OpenAI, Anthropic, and Gemini keys. They somehow ended up in Claude Code logs(!) Within seconds I got an email from Anthropic and they have already disabled my keys. Neither OpenAI nor Google alerted me in anyway. I was able to login to OpenAI and delete all the keys quickly. Took me a good 10-15 minutes to _just_ _find_ where Gemini/AI Studio/Vortex projects keys _might_ be! I had…
I shudder to think of the implications.
Consider all the security disasters we already get from brogramming, and multiply that, times 100.
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#127Earlier quoted context omitted.
They probably don't have any repeaters. All those metal shelves are going to interfere with the signal. I have the same experience.
Their in-store WiFi is a repeater more or less. It's one of those bullshit forced auto-join networks that you can't opt out of (at least on iOS). Because that's not a massive vector for phishing or anything.
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#128Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#129Earlier quoted context omitted.
I don't know how well lumber holds up to the bottom of the ocean
Pretty good actually. With the salt, lack of oxygen and pressure it can last quite a long time.
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#130For a self-hosted use case.
Currently, manually SSH into VPs and updating env files but not sure if its best practice.