I found 39 Algolia admin keys exposed across open source documentation sites
1–10 of 62 posts
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#2Re: I found 39 Algolia admin keys exposed across open source documentation sites
#3Re: I found 39 Algolia admin keys exposed across open source documentation sites
#4Great write up. Reminder that if you commit these to a Github Gist and the provider partners with GitHub for secrets scanning, they’ll rapidly be invalidated.
"If the secrets issuer partners with X-corp for secret scanning so that secrets get invalidated when you X them, then when you X them the secrets will be invalidated".
The above is a true statement for all X.
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#5Re: I found 39 Algolia admin keys exposed across open source documentation sites
#6Great write up. Reminder that if you commit these to a Github Gist and the provider partners with GitHub for secrets scanning, they’ll rapidly be invalidated.
That's just a tautology. "If the secrets issuer partners with X-corp for secret scanning so that secrets get invalidated when you X them, then when you X them the secrets will be invalidated". The above is a true statement for all X.
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#7Great write up. Reminder that if you commit these to a Github Gist and the provider partners with GitHub for secrets scanning, they’ll rapidly be invalidated.
That's just a tautology. "If the secrets issuer partners with X-corp for secret scanning so that secrets get invalidated when you X them, then when you X them the secrets will be invalidated". The above is a true statement for all X.
Unfortunately, it doesn't look like Algolia has implemented this
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#8Re: I found 39 Algolia admin keys exposed across open source documentation sites
#9I'm not a newspaper editor, but I think if this was an article for one, they'd also say the graphs are unnecessary. It smells of "I need some visual stuff to make this text interesting"...
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#10Great write up. Reminder that if you commit these to a Github Gist and the provider partners with GitHub for secrets scanning, they’ll rapidly be invalidated.
That's just a tautology. "If the secrets issuer partners with X-corp for secret scanning so that secrets get invalidated when you X them, then when you X them the secrets will be invalidated". The above is a true statement for all X.
In formal logic, that statement is true whether X is GitHub, or Lockheed-Martin, Safeway, or the local hardware store.
In English, the statement serves to inform (or remind) you that GitHub has a secret scanning program that many providers actually do partner with.