amuck-landowner

Devs should not upload their configs - check this bad example

peterw

New Member
Amazon Web Services (AWS) is urging developers using the code sharing site GitHub to search for their AWS keys.

Thousands of ‘secret keys’, which unlock access to private Amazon Web Services accounts are currently available unencrypted to members of the public.

The secret keys are issued by Amazon Web Services when users open an account and provide applications access to AWS resources.


Read more: http://www.itnews.com.au/News/375785,aws-urges-developers-to-scrub-github-of-secret-keys.aspx
Check your AWS logins, a search for AWS keys returns almost 10,000 results.
 

Dylan

Active Member
This is an incredibly deceptive thread title -- implying Amazon leaked keys when that's not remotely true.

People uploaded code to GitHub which includes their secret keys. This isn't a leak, just developers being stupid with their own code: no different than if I uploaded a script containing my root password. Amazon did absolutely nothing wrong and implying there was a leak is a seriously irresponsible way to create unjustified rage and panic.
 
Last edited by a moderator:
Top
amuck-landowner