Any suggestions for secrets management to distribute API keys/DB secrets/etc.? For a self-hosted use case. Currently, manually SSH into VPs and updating env files but not sure if its best practice.
Home Depot GitHub token exposed for a year, granted access to internal systems
131–140 of 169 posts
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#132Last week I accidentally exposed my OpenAI, Anthropic, and Gemini keys. They somehow ended up in Claude Code logs(!) Within seconds I got an email from Anthropic and they have already disabled my keys. Neither OpenAI nor Google alerted me in anyway. I was able to login to OpenAI and delete all the keys quickly. Took me a good 10-15 minutes to _just_ _find_ where Gemini/AI Studio/Vortex projects keys _might_ be! I had…
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#133Earlier quoted context omitted.
Pretty good actually. With the salt, lack of oxygen and pressure it can last quite a long time.
Presumably you'd want human habitable atmosphere on the inside of the sphere, which would radically change the equation against the use of wood unfortunately.
By using plywood in conjunction with other off-the-shelf parts and materials, we can change this equation to deliver more value while dramatically reducing costs.
If, due to unforeseen circumstances the habitat occupant can no longer sustain life, they're automatically entombed inside a makeshift plywood coffin—no costly recovery operations required. Logitech wireless game controller sold separately.
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#134Last week I accidentally exposed my OpenAI, Anthropic, and Gemini keys. They somehow ended up in Claude Code logs(!) Within seconds I got an email from Anthropic and they have already disabled my keys. Neither OpenAI nor Google alerted me in anyway. I was able to login to OpenAI and delete all the keys quickly. Took me a good 10-15 minutes to _just_ _find_ where Gemini/AI Studio/Vortex projects keys _might_ be! I had…
> With a lot of vibe coding happening I shudder to think of the implications. Consider all the security disasters we already get from brogramming, and multiply that, times 100.
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#135Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#136Given the absolute state of their website on mobile it's hardly surprising. It's faster to find an employee and ask them where an item is at instead of waiting for the search to finish, see that it the "current store" now points to a random location somewhere in a different state, pick the correct store and re-do the search
I feel like the home depot website is fine. It's a lot better than most other shops, I've had a good experience finding the aisle and location of items, and it's generally accurate with the amount in stock at each location. If you didn't enable precise location or have bad cell signal then that is hardly the fault of the website.
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#137Last week I accidentally exposed my OpenAI, Anthropic, and Gemini keys. They somehow ended up in Claude Code logs(!) Within seconds I got an email from Anthropic and they have already disabled my keys. Neither OpenAI nor Google alerted me in anyway. I was able to login to OpenAI and delete all the keys quickly. Took me a good 10-15 minutes to _just_ _find_ where Gemini/AI Studio/Vortex projects keys _might_ be! I had…
How did they get leak them? Just someone getting into your personal Claude Code logs? I'm surprised that if it was just that Google would even be aware they're leaked.
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#138I’m surprised that GitHub, OpenAI etc. doesn’t have automation to scan the usual surfaces for hashes of their access tokens. It seems like a cheap and simple thing to offer your customers a little extra safety. Anybody interested in starting a platform agnostic service to do this?
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#139Any suggestions for secrets management to distribute API keys/DB secrets/etc.? For a self-hosted use case. Currently, manually SSH into VPs and updating env files but not sure if its best practice.
Re: Home Depot GitHub token exposed for a year, granted access to internal systems
#140>When reached by TechCrunch on December 5, Home Depot spokesperson George Lane acknowledged receipt of our email but did not respond to follow-up emails asking for comment. The exposed token is no longer online, and the researcher said the token’s access was revoked soon after our outreach. > >We also asked Lane if Home Depot has the technical means, such as logs, to determine if anyone else used the token during the…
As it could be service or real legal stuff, it tends to get read by someone literate and able to take action.
Had to do that with a bank that refused to talk to me (I hit some kind of identify verification quagmire), but they quickly got someone able to call me and close it on the spot.