Live data from Hacker News

Home Depot GitHub token exposed for a year, granted access to internal systems

techcrunch.com

151–160 of 169 posts

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#151

What's the biggest damage someone could have done with that info?

As an example, there is a hacking group tracked as "Atlas Lion" that has been persistently targeting large retailers' internal systems to steal gift cards that they resell on gray markets for a profit.

I don't believe exploiting GitHub repos for initial access is part of their playbook, but there have been plenty of examples in recent years of attackers gaining access to internal infrastructure via secrets exposed in GitHub (whether in code or Actions workflows). Just this year, attackers got into Salesloft's GitHub, pivoted to their AWS environment, and stole OAuth tokens that gave them access to hundreds of Salesforce customers.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#152

Earlier quoted context omitted.

Stock price is an extremely narrow view of the total consequences of lax cybersecurity but that aside, the notion that security doesn’t matter because those companies got hacked is ridiculous. The reason there isn’t an Equifax every minute is because an enormous amount of effort and talent goes into ensuring that’s the case. If your attitude is we should vibe code our way past the need for security, you aren’t respon…

I feel as if security is a much bigger concern than it ever was. The main issue seems to be, that our artifacts are now so insanely complex, that there’s too many holes, and modern hackers are quite different from the old skiddies. In some ways, it’s possible that AI could be a huge boon for security, but I’m worried, because its training data is brogrammer crap.

Security has become a big talking point, and industry vultures have zeroed in on that and will happily sell dubious solutions that claim to improve security. There is unbelievable money sloshing around in those circles, even now during the supposed tech downturn ("security" seems to be immune to this).

Actual security on the other hand has decreased. I think one of the worst things to happen to the industry is "zero trust", meaning now any exposed token or lapse in security is exploitable by the whole world instead of having to go through a first layer of VPN (no matter how weak it is, it's better than not having it).

> quite different from the old skiddies

Disagreed - if you look at the worst breaches ("Lapsus$", Equifax, etc), it was always down to something stupid - social engineering the vendor that conned them into handing them the keys to the kingdom, a known vulnerable version in a Java web framework, yet another NPM package being compromised and that they immediately updated to since the expensive, enterprise-grade Dependabot knockoff told them to, and so on.

I'm sure APTs and actual hacking exists in the right circles, but it's not the majority of breaches. You don't need APT to breach most companies.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#153

Earlier quoted context omitted.

Security simply doesn’t seem like it matters much based on the mild consequences.

Try working at a company of any remote public significance and see if your view changes.

There's a lot of performative "security" in such companies. You need to employ the right people (you need a "CISO", ideally someone who's never actually used a terminal in their life), you need to pay money for the right vendors, adopt the right buzzwords and so on. The amounts of money being spent on performative security are insane, all done by people who can't even "hack" a base64-"encrypted" password.

All while there's no budget for those that actually develop and operate the software (so you get insecure software), those that nevertheless do their best are slowed down by all the security theater, and customer service is outsourced to third-world boiler rooms so exploiting vulnerabilities doesn't even matter when a $100 bribe will get you in.

It's "the emperor has no clothes" all the way down: because any root-cause analysis of a breach (including by regulators) will also be done by those without clothes, it "works" as far as the market and share price is concerned.

Source: been inside those "companies of public significance" or interacted with them as part of my work.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#154

Any suggestions for secrets management to distribute API keys/DB secrets/etc.? For a self-hosted use case. Currently, manually SSH into VPs and updating env files but not sure if its best practice.

If it's a single application exposed to the internet that is using those tokens then an env file is perfectly fine. If the application gets breached the secrets will be in memory anyway (as the app needs them to do its work), so they will get exposed no matter how they were sourced.

If your vendors support IP-based restrictions (few do, thanks to "zero trust" and other bullshit), a very strong defense would be to enable that and restrict use of those secrets to your server's IP, so that the tokens become useless to anyone else even if leaked.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#155

Any suggestions for secrets management to distribute API keys/DB secrets/etc.? For a self-hosted use case. Currently, manually SSH into VPs and updating env files but not sure if its best practice.

SOPS reduces the surface area you need to cover. You can use Age as a backend and then you only need a long lived private key on the server. https://github.com/getsops/sops

The bad guys will steal that private key and decrypt the encrypted secrets the same way they can steal the unencrypted secrets directly.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#156

Any suggestions for secrets management to distribute API keys/DB secrets/etc.? For a self-hosted use case. Currently, manually SSH into VPs and updating env files but not sure if its best practice.

I’d use the native secrets of your VM platform or something like 1password with an functional API.

Yes if you get the hypervisor to provide the secrets this in theory means the secrets will be safe at rest... but if the VM gets breached (which is the scenario we're assuming here, as his VM is the one handling untrusted traffic from the internet), the secrets still get out.

One option is to use separate "proxy" VMs that proxy traffic to the external services and applies the secret. The main application VM uses those proxy VMs to talk to the external services. This means a compromise of the application VM will not be able to exfiltrate any secrets - it will merely be able to make use of them (by talking to the proxy VMs) while the attacker still has access. Post-breach remediation becomes easier as not only do you not need to rotate the secret (as it wasn't stolen, merely misused) but your proxy VM can provide a tamper-proof audit log to tell which malicious activity has happened, if any.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#158
post #90

Earlier quoted context omitted.

It varies a lot by store. I’ve been to HDs where they’re all useless, and others where there’s a good number of knowledgeable DIYers working there. I think a lot of people just expect too much from a big box store employee making $17/hr… You go to HD because you have an easy job and you’re as cheap as their MBAs. If you need help, go to a supply house or an Ace Hardware or something.

Fully this. Every Ace or Do It Best I've been to in Washington has had at least one Rugged Grandpa ™ on staff who could have given me a PhD-level essay on whatever I asked them about; at Home Depot I'm lucky if the folks there have any idea what an impact-rated bit is or why I specifically need one and NO please stop trying to sell me this other crap if you're sold out of the impact bits, they are NOT the same! (It g…

> It gets worse the further from the power tools section you get, I find. I had to explain the difference between a three-prong and four-prong 240V plug once at HD and promptly told my friend to stop asking the staff for "help" finding things.

The best feature of Home Depot is order pickup. No need to explain to someone that some appliances use both 120V for control power and 240V power for the motor or heating element; or that you’re installing a receptacle to backfeed a 120/240V panel with a 120/240V generator and therefore you need a 4-wire NEMA 14 series receptacle with a neutral conductor, you just buy one and pick it up from a locker. It’s made buying things from Home Depot tolerable for me, I’m used to buying material from supply houses where the folks are knowledgeable, I know that’s not the case at HD so I don’t even bother asking.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#159
post #123

Last week I accidentally exposed my OpenAI, Anthropic, and Gemini keys. They somehow ended up in Claude Code logs(!) Within seconds I got an email from Anthropic and they have already disabled my keys. Neither OpenAI nor Google alerted me in anyway. I was able to login to OpenAI and delete all the keys quickly. Took me a good 10-15 minutes to _just_ _find_ where Gemini/AI Studio/Vortex projects keys _might_ be! I had…

>Took me a good 10-15 minutes to _just_ _find_ where Gemini/AI Studio/Vortex projects keys _might_ be

I feel like all this granular key management across everything, dev, life, I might be more insecure but god damn I don't feel like I know what is going on.

Re: Home Depot GitHub token exposed for a year, granted access to internal systems

#160
post #144
post #133

Earlier quoted context omitted.

I disagree. Traditional underwater human habitats are overengineered and expensive. By using plywood in conjunction with other off-the-shelf parts and materials, we can change this equation to deliver more value while dramatically reducing costs. If, due to unforeseen circumstances the habitat occupant can no longer sustain life, they're automatically entombed inside a makeshift plywood coffin—no costly recovery oper…

Could we involve robotics, LLMs and maybe some camera based vision models to this process? Surely with AI we could make building those very fast. Especially with humanoid robots...

After the initial trial of humanoid robots resulted in too many fatalities owing to falls, it was decided to instead acquire industrial 6-DoF robotic armatures and place them atop treaded, omnidirectional-pivot cargo transport systems intended for warehouse use.

The LiDAR option on the armature was eschewed due to cost in favor of an in-house, camera-based vision model that has thus far reduced the number of safety incidents that later result in amputation (knock on plywood) while increasing manufacturing output.

Pressure vessel construction still remains a point of concern on account of recent trends which indicate a rise in errant armature misfires when gripping tools that facilitate the application of nails and staples to the plywood superstructure.

Post reply on HN