Live data from Hacker News

CISA Admin Leaked AWS GovCloud Keys on GitHub

krebsonsecurity.com

201–205 of 205 posts

Re: CISA Admin Leaked AWS GovCloud Keys on GitHub

#201
post #28

I think one thing that people are sleeping on is passing a ton of secrets to OpenAI and Anthropic or your OpenRouter by having a .env or secrets on disk in your repo, but not checked in Your LLM will happily read the entire file, ship it off to be training data for future versions of ChatGPT, and not raise any flags, because let's be fair it was on ok thing to check if all the env vars were set, or it you had set up…

I no longer keep my dotenv files in plaintext. I use `sops` to keep an encrypted env around and you can use tools like direnv to make them available to your shell while you're working. Obviously the LLM could print any of these secrets, but it's less likely. Additionally I find that at least claude seems to avoid reading the dotenv. And lastly, don't make any local secrets that important. Limited scope, dev accounts,…

I've used `sops` "manually" before and I'm interested. What is your workflow? I'm assuming you set certain directories to have access to the sops key you're storing somewhere else to be able to encrypt/decrypt files?

Re: CISA Admin Leaked AWS GovCloud Keys on GitHub

#202

Earlier quoted context omitted.

Gutting doesn't magically solve incompetence. It's a anti-solultion that people peddle because it requires literally zero thought or nuance. If an organization has systemic incompetence and you gut them, then they're still incompetent but now they're also pressured and therefore more likely to make mistakes. So, you're just in a worse position.

On the contrary you can argue that gutting should lead to lower number of mistakes/incompetence. There can't be any mistakes if no work is being done.

There's a big mistake in this logic: is work really not getting done?

Because a lot of work has to be done regardless of if you have the money or time to do it. Most government work is actually not optional, there are literal laws saying it has to be done.

And that's what we, very predictably, saw with DOGE.

Like, think about it. You fire say 50% of people. What happens to the other 50%? They twiddle their thumbs?

You've worked a job before, right? And you've had coworkers fired or laid off before, right? Okay, what happens to their work?

Does it disappear into the abyss or do you then take it on? Because in all my experience, I take it on. Come on now.

Re: CISA Admin Leaked AWS GovCloud Keys on GitHub

#203

Earlier quoted context omitted.

> When negligence is so bad that it looks like sabotage from a hostile agent It doesn't though. There's no actual evidence for anything beyond negligence. The "sabotage" angle is just speculation in the vain hope that surely people this stupid don't work for the US government.

We doesn't need a signed affidavit on GitHub to trigger an investigation. This already crossed the line of reasonable suspicion. The investigation is where evidence gets collected. Who knows what other improper behavior these people have engaged in and what other secrets they have leaked, intentionally or by side effect.

By all means, investigate. But it shouldn't be a criminal investigation without sufficient evidence.

Re: CISA Admin Leaked AWS GovCloud Keys on GitHub

#204

Earlier quoted context omitted.

good thing we know DOGE has been trying to exfil all US Gov data like all gov employees, or all SSNs under a previous administration I'd assume CISA was doing a dirty dangle, but given how corrupt and incompetent this administration is, to include firing lots of CISA, this may just be a legit fuckup.

When negligence is so bad that it looks like sabotage from a hostile agent, then criminal investigations are needed to learn more about the people who did it, the others who enabled it, and deter similar future acts. DOGE did a lot of bad things, but it didn't force anyone to commit credentials to a repo, disable scanners to get away with it, and then make the repo public.

DOGE was the culture of let's do things fast!!

I can imagine CISA reducing personal and subcontracting work to some cheap company to save money

Re: CISA Admin Leaked AWS GovCloud Keys on GitHub

#205

Earlier quoted context omitted.

Complaining about gross negligence, after all the competence has been gutted out, strikes me as misdirected frustration.

Oh, thats interesting ,. this is one of those things where two people can hear opposite things from the exact same information.

Without naming names, there's an old, old joke about a certain political party's philosophy: "Government is incompetent and ineffective! Elect us and we'll prove it!"
Post reply on HN