Live data from Hacker News

CISA Admin Leaked AWS GovCloud Keys on GitHub

krebsonsecurity.com

181–190 of 205 posts

Re: CISA Admin Leaked AWS GovCloud Keys on GitHub

#182

GitHub has automatic secret scanning on all public repositories which notifies AWS if access keys are pushed. I would have expected these tokens to be immediately revoked by AWS. Is there something different about GovCloud access keys so they weren't detected?

I would expect this to work in accordance with Github uptime.... so take it for what its worth

Re: CISA Admin Leaked AWS GovCloud Keys on GitHub

#183
post #26

Earlier quoted context omitted.

One the one hand the CISA is being gutted, and on the other hand there is an ever increase of rhetoric about cybersecurity, national interests, critical infrastructure..

[flagged]

Gutting doesn't magically solve incompetence. It's a anti-solultion that people peddle because it requires literally zero thought or nuance.

If an organization has systemic incompetence and you gut them, then they're still incompetent but now they're also pressured and therefore more likely to make mistakes. So, you're just in a worse position.

Re: CISA Admin Leaked AWS GovCloud Keys on GitHub

#184

Earlier quoted context omitted.

[flagged]

Complaining about gross negligence, after all the competence has been gutted out, strikes me as misdirected frustration.

Oh, thats interesting ,. this is one of those things where two people can hear opposite things from the exact same information.

Re: CISA Admin Leaked AWS GovCloud Keys on GitHub

#185

Earlier quoted context omitted.

[flagged]

Gutting doesn't magically solve incompetence. It's a anti-solultion that people peddle because it requires literally zero thought or nuance. If an organization has systemic incompetence and you gut them, then they're still incompetent but now they're also pressured and therefore more likely to make mistakes. So, you're just in a worse position.

[dead]

Re: CISA Admin Leaked AWS GovCloud Keys on GitHub

#186

They also uploaded sensitive docs in chatgpt [1] [1] https://www.politico.com/news/2026/01/27/cisa-madhu-gottumuk...

I feel like this piece is framed incorrectly.

Imagine joining an organization with 3k employees in 2025 and not having access to an LLM.

It’s well known that the federal govt over-classifies many documents. This former CISA head alleged dumped “for official use” documents. Obviously, he should have pushed for the chatgpt enterprise account (or equivalent) but we dont know what bureaucratic obstacles he was up against.

Re: CISA Admin Leaked AWS GovCloud Keys on GitHub

#187
post #26

Earlier quoted context omitted.

One the one hand the CISA is being gutted, and on the other hand there is an ever increase of rhetoric about cybersecurity, national interests, critical infrastructure..

[flagged]

What if they purged all of the competent people and installed party loyalists? That seems to be a recurring theme with this administration. These are guys who unapologetically admire the efficiency of the Nazi party, not realizing that the pervasive incompetence and most levels of the government were one of the driving factors in their ultimate defeat.

Re: CISA Admin Leaked AWS GovCloud Keys on GitHub

#189
post #26

Earlier quoted context omitted.

One the one hand the CISA is being gutted, and on the other hand there is an ever increase of rhetoric about cybersecurity, national interests, critical infrastructure..

[flagged]

Gutting organizations _leads to_ these kinds of problems.

Re: CISA Admin Leaked AWS GovCloud Keys on GitHub

#190
post #7

Earlier quoted context omitted.

Agreed. Static long lived credentials are real problems. Kudos for AWS and the other hyperscalers for building the tooling to move away from them. And providing some gentle and not-so-gentle nudges away from it too. But not everyone is where they need to be. For instance, railway doesn't let you access AWS resources via roles/OIDC. I filed a ticket[0] but haven't seen movement. 0: https://station.railway.com/feedback…

Heh, you mean the railway that was part of the whole "my production db got deleted in 9 seconds" story? That company sounds a lot like one that doesn't focus on the right things.

Yeah... the railway that has just had a multi-hour outage because they looked like a spam account to Google Cloud!
Post reply on HN