• Latest
  • Trending
  • All
Developers can’t seem to stop exposing credentials in publicly accessible code

Developers can’t seem to stop exposing credentials in publicly accessible code

3 years ago
Government Reduces Annual Subsidised LPG Cylinder Quota For Ujjwala Beneficiaries To Four | India News

Government Reduces Annual Subsidised LPG Cylinder Quota For Ujjwala Beneficiaries To Four | India News

38 mins ago
Bangladesh vs Australia 1st ODI Live Streaming: When, where and how to watch BAN vs AUS live on TV and online

Bangladesh vs Australia 1st ODI Live Streaming: When, where and how to watch BAN vs AUS live on TV and online

41 mins ago
Refrigerator Buying Guide 2026: Single Door, Double Door & Inverter Tech | Tech News

Refrigerator Buying Guide 2026: Single Door, Double Door & Inverter Tech | Tech News

44 mins ago
India’s anti-obesity drug market sees slower growth after initial surge in generic semaglutide sales

India’s anti-obesity drug market sees slower growth after initial surge in generic semaglutide sales

2 hours ago
Tata Trusts board meets ahead of key Tata Sons board meeting | Business News

Tata Trusts board meets ahead of key Tata Sons board meeting | Business News

6 hours ago
TMC rebel MPs hold meeting at Union Minister’s Bhupender Yadav residence

TMC rebel MPs hold meeting at Union Minister’s Bhupender Yadav residence

8 hours ago
Apple WWDC 2026 LIVE | iPhone-maker announces Siri AI powered by the new Apple Intelligence

Apple WWDC 2026 LIVE | iPhone-maker announces Siri AI powered by the new Apple Intelligence

9 hours ago
Ben Stokes, Gus Atkinson under ECB investigation after nightclub incident; Oval Test spots under cloud

Ben Stokes, Gus Atkinson under ECB investigation after nightclub incident; Oval Test spots under cloud

9 hours ago
India’s Q4 FY26 Current Account Surplus Driven by Services Exports, Remittances

India’s Q4 FY26 Current Account Surplus Driven by Services Exports, Remittances

10 hours ago
Women’s T20 WC: India pin faith on the Shafali-Smriti opening salvo

Women’s T20 WC: India pin faith on the Shafali-Smriti opening salvo

10 hours ago
PIO Nithya Raman surges into LA Mayoral runoff spot, triggering Trump fury over another ‘stolen’ election

PIO Nithya Raman surges into LA Mayoral runoff spot, triggering Trump fury over another ‘stolen’ election

12 hours ago
Israel Halted Strikes On Iran At Trump’s Behest, But Gives No Guarantee On Lebanon | World News

Israel Halted Strikes On Iran At Trump’s Behest, But Gives No Guarantee On Lebanon | World News

12 hours ago
Tuesday, June 9, 2026
  • PRESS RELEASE
  • ADVERTISE
  • CONTACT
  • Game
India News Online
  • Home
  • News
    • India
    • Punjab
    • International
    • Entertainment
  • Hindi News
  • Politics
  • Health
  • Business
  • Sports
  • Technology
  • Lifestyle
  • Video
    • All
    • Hindi Songs
    • Punjabi Songs
    पियवा किसनवा 90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu songs Hindi

    पियवा किसनवा 90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu songs Hindi

    90s Bollywood Wedding Songs | Evergreen Bollywood Hits | Shadi Song | Sadabahar Hindi Songs Jukebox

    90s Bollywood Wedding Songs | Evergreen Bollywood Hits | Shadi Song | Sadabahar Hindi Songs Jukebox

    आज तो बाल बाल बच गया😄90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu song

    आज तो बाल बाल बच गया😄90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu song

    भाभी ने बचाई ननद की जान 😆 90’S Old Hindi Songs 🥺90s Love Song 😍Udit Narayan, Alka Yagnik, Kumar

    भाभी ने बचाई ननद की जान 😆 90’S Old Hindi Songs 🥺90s Love Song 😍Udit Narayan, Alka Yagnik, Kumar

    When Online Love Becomes Real💞Chinese mix Hindi Songs💞Cin Klip💞Chinese Drama💞Korean Mix Hindi Songs

    When Online Love Becomes Real💞Chinese mix Hindi Songs💞Cin Klip💞Chinese Drama💞Korean Mix Hindi Songs

    Cold Rude boy falling for cute girl 💕 korean mix hindi songs 💞 Chinese mix hindi songs

    Cold Rude boy falling for cute girl 💕 korean mix hindi songs 💞 Chinese mix hindi songs

    90s हिंदी सदाबहार गीत | 90’s Romantic Hindi Songs | 90’s सदाबहार फिल्मी गाने | 90’s Bollywood Songs

    90s हिंदी सदाबहार गीत | 90’s Romantic Hindi Songs | 90’s सदाबहार फिल्मी गाने | 90’s Bollywood Songs

    90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu songs Hindi Jukebox

    90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu songs Hindi Jukebox

    90’s हिंदी गाने | 90’s Evergreen Songs | 90s सदाबहार गाने | Hindi Gana | 90’s Hit Songs | Durga Boss

    90’s हिंदी गाने | 90’s Evergreen Songs | 90s सदाबहार गाने | Hindi Gana | 90’s Hit Songs | Durga Boss

  • Travel
  • Game
No Result
View All Result
India News
No Result
View All Result
Home Technology

Developers can’t seem to stop exposing credentials in publicly accessible code

by India News Online Team
November 16, 2023
in Technology
0
Developers can’t seem to stop exposing credentials in publicly accessible code
Share on FacebookShare on TwitterShare on Email


Developers can’t seem to stop exposing credentials in publicly accessible code

Victor De Schwanberg/Science Photo Library via Getty Images

Despite more than a decade of reminding, prodding, and downright nagging, a surprising number of developers still can’t bring themselves to keep their code free of credentials that provide the keys to their kingdoms to anyone who takes the time to look for them.

The lapse stems from immature coding practices in which developers embed cryptographic keys, security tokens, passwords, and other forms of credentials directly into the source code they write. The credentials make it easy for the underlying program to access databases or cloud services necessary for it to work as intended. I published one such PSA in 2013 after discovering simple searches that turned up dozens of accounts that appeared to expose credentials securing computer-to-server SSH accounts. One of the credentials appeared to grant access to an account on Chromium.org, the repository that stores the source code for Google’s open source browser.

In 2015, Uber learned the hard way just how damaging the practice can be. One or more developers for the ride service had embedded a unique security key into code and then shared that code on a public GitHub page. Hackers then copied the key and used it to access an internal Uber database and, from there, steal sensitive data belonging to 50,000 Uber drivers.

Uber lawyers argued at the time that “the contents of these internal database files are closely guarded by Uber,” but that contention is undermined by means the company took in safeguarding the data, which was no better than stashing a house key under a door mat.

The number of studies published since following the revelations underscored just how common the practice had been and remained in the years immediately following Uber’s cautionary tale. Sadly, the negligence continues even now.

Researchers from security firm GitGuardian this week reported finding almost 4,000 unique secrets stashed inside a total of 450,000 projects submitted to PyPI, the official code repository for the Python programming language. Nearly 3,000 projects contained at least one unique secret. Many secrets were leaked more than once, bringing the total number of exposed secrets to almost 57,000.

“Exposing secrets in open-source packages carries significant risks for developers and users alike,” GitGuardian researchers wrote. “Attackers can exploit this information to gain unauthorized access, impersonate package maintainers, or manipulate users through social engineering tactics.”

Advertisement

The credentials exposed provided access to a range of resources, including Microsoft Active Directory servers that provision and manage accounts in enterprise networks, OAuth servers allowing single sign-on, SSH servers, and third-party services for customer communications and cryptocurrencies. Examples included:

  • Azure Active Directory API Keys
  • GitHub OAuth App Keys
  • Database credentials for providers such as MongoDB, MySQL, and PostgreSQL
  • Dropbox Key
  • Auth0 Keys
  • SSH Credentials
  • Coinbase Credentials
  • Twilio Master Credentials.

Also included in the haul were API keys for interacting with various Google Cloud services, database credentials, and tokens controlling Telegram bots, which automate processes on the messenger service. This week’s report said that exposures in all three categories have steadily increased in the past year or two.

The secrets were exposed in various types of files published to PyPI. They included primary .py files, README files, and test folders.

Most common types of files other than .py containing a hardcoded secret in PyPI packages.
Enlarge / Most common types of files other than .py containing a hardcoded secret in PyPI packages.

GitGuardian

GitGuardian tested the exposed credentials and found that 768 remained active. The risk, however, can extend well beyond that smaller number. GitGuardian explained:

It is important to note that just because a credential can not be validated does not mean it should be considered invalid. Only once a secret has been properly rotated can you know if it is invalid. Some types of secrets GitGuardian is still working toward automatically validating include Hashicorp Vault Tokens, Splunk Authentication Tokens, Kubernetes Cluster Credentials, and Okta Tokens.

There are no good reasons to expose credentials in code. The report said the most common cause is by accident.

“In the course of outreach for this project, we discovered at least 15 incidents where the publisher was unaware they had made their project public,” the authors wrote. “Without naming any names, we did want to mention some of these were from very large companies that have robust security teams. Accidents can happen to anyone.”

Over the past decade, various mechanisms have become available for allowing code to securely access databases and cloud resources. One is .env files that are stored in private environments outside of the publicly available code repository. Others are tools such as the AWS Secrets Manager, Google Cloud’s Secret Manager, or the Azure Key Vault. Developers can also employ scanners that check code for credentials inadvertently included.

The study examined PyPI, which is just one of many open source repositories. In years past, code hosted in other repositories such as NPM and RubyGems has also been rife with credential exposure, and there’s no reason to suspect the practice doesn’t continue in them now.



Source link

Tags: accessiblecodecredentialsdevelopersExposingpubliclystop
Share199Tweet125Send

Related Posts

Refrigerator Buying Guide 2026: Single Door, Double Door & Inverter Tech | Tech News
Technology

Refrigerator Buying Guide 2026: Single Door, Double Door & Inverter Tech | Tech News

June 9, 2026
WhatsApp Says Spyware Maker NSO Group Is Still Targeting Its Users
Technology

WhatsApp Says Spyware Maker NSO Group Is Still Targeting Its Users

June 8, 2026
Notion restores access to Anthropic after service disruption
Technology

Notion restores access to Anthropic after service disruption

June 7, 2026
School shooting survivor sues AI gun detection firm after system failed to spot weapon
Technology

School shooting survivor sues AI gun detection firm after system failed to spot weapon

June 7, 2026
Load More
  • Trending
  • Comments
  • Latest
9 Festivals to Celebratein August in India

9 Festivals to Celebratein August in India

August 8, 2025
Corruption cases against govt officials: SC bats for striking balance | Latest News India

Corruption cases against govt officials: SC bats for striking balance | Latest News India

August 5, 2025
Guru Randhawa – SIRRA ( Official Video )

Guru Randhawa – SIRRA ( Official Video )

July 1, 2025
Baharon Phool Barsao – Suraj – Rajendra Kumar, Vyjayanthimala – Old Hindi Songs

Baharon Phool Barsao – Suraj – Rajendra Kumar, Vyjayanthimala – Old Hindi Songs

0
Phool Maangu Na Bahaar Maangu – Video Song | Raja | Madhuri Dixit & Sanjay Kapoor

Phool Maangu Na Bahaar Maangu – Video Song | Raja | Madhuri Dixit & Sanjay Kapoor

0
Dil Ka Rishta Song – Aishwarya Rai,Arjun Rampal, Alka Yagnik,Udit Narayan,Kumar Sanu, Nadeem-Shravan

Dil Ka Rishta Song – Aishwarya Rai,Arjun Rampal, Alka Yagnik,Udit Narayan,Kumar Sanu, Nadeem-Shravan

0
Government Reduces Annual Subsidised LPG Cylinder Quota For Ujjwala Beneficiaries To Four | India News

Government Reduces Annual Subsidised LPG Cylinder Quota For Ujjwala Beneficiaries To Four | India News

June 9, 2026
Bangladesh vs Australia 1st ODI Live Streaming: When, where and how to watch BAN vs AUS live on TV and online

Bangladesh vs Australia 1st ODI Live Streaming: When, where and how to watch BAN vs AUS live on TV and online

June 9, 2026
Refrigerator Buying Guide 2026: Single Door, Double Door & Inverter Tech | Tech News

Refrigerator Buying Guide 2026: Single Door, Double Door & Inverter Tech | Tech News

June 9, 2026
India News Online

24x7 Online News From India
India News Online is your news, entertainment, music fashion website. We provide you with the latest breaking news and videos straight from the entertainment industry.

Categories

  • Business
  • Entertainment
  • Health
  • Hindi News
  • Hindi Songs
  • India
  • International
  • Lifestyle
  • Panjab
  • Politics
  • Punjabi Songs
  • Sports
  • Technology
  • Travel
  • Uncategorized
No Result
View All Result

Recent Posts

  • Government Reduces Annual Subsidised LPG Cylinder Quota For Ujjwala Beneficiaries To Four | India News
  • Bangladesh vs Australia 1st ODI Live Streaming: When, where and how to watch BAN vs AUS live on TV and online
  • Refrigerator Buying Guide 2026: Single Door, Double Door & Inverter Tech | Tech News
  • Home
  • Disclaimer
  • DMCA
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact

Copyright © 2021 - India News Online.

No Result
View All Result
  • Home
  • News
    • India
    • Punjab
    • International
    • Entertainment
  • Hindi News
  • Politics
  • Health
  • Business
  • Sports
  • Technology
  • Lifestyle
  • Video
  • Travel
  • Game

Copyright © 2021 - India News Online.