‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
https://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330
816 points · 99 comments · view on lemmy.world
99 Comments
demonsword@lemmy.world · 214 pts · 89d
vibe code go brrrrrrr
EDIT: wow it's far worse, it was a single contractor that decided that his convenience was above any and all security recommendations ever written. Pure. Genius!
lIlIlIlIlIlIl@lemmy.world · 72 pts · 89d
Leaving passwords in plaintext has zero to do with “vibe coding”
village604@adultswim.fan · 82 pts · 89d
It definitely can if an LLM did it.
wucking_feardo@lemmy.world · 7 pts · 89d
I agree and to expand the same point. Even if the llm didn't do it, it's entirely plausible the LLM recommended it and the dev just drank that coolaid
demonsword@lemmy.world · 26 pts · 89d
yeah, and this is why I edited my original post after reading the article.
crusa187@lemmy.ml · 45 pts · 89d
Only the best people
nymnympseudonym@piefed.social · 7 pts · 89d
You know what's ironic? FedRAMP rules dictate that Thou Must Scan Thy Repos for Secrets (tokens, passwords, etc)
GitHub, ButrBucket, etc all have this out of the box for enterprise customers
https://support.atlassian.com/bitbucket-data-center/kb/how-to-scan-for-and-remove-passwords-or-secrets-in-bitbucket-server-repositories/
wonderingwanderer@sopuli.xyz · 16 pts · 89d
Contractor, eh?
How much do you wanna bet he has close personal ties to the trump family and zero cybersecurity experience?
pulsewidth@lemmy.world · 200 pts · 89d
Six months of exposure.
There is zero chance that the CISA systems have not been comprehensively breeched by every foreign adversary.
Good thing Trump cut 1/4 of their workforce last year. It's really paying dividends for Putin.
SaveTheTuaHawk@lemmy.ca · 89 pts · 89d
mPony@lemmy.world · 29 pts · 89d
that chain saw is not at the correct height
smeenz@lemmy.nz · 7 pts · 89d
It's only...what, about half a metre too high ?
IsoKiero@sopuli.xyz · 5 pts · 89d
It doesn't seem to have kickback brake, so it kinda is. It just should be running on full speed and hit something on the tip.
wonderingwanderer@sopuli.xyz · 4 pts · 89d
Bye Elon!
SaveTheTuaHawk@lemmy.ca · 3 pts · 89d
his peepee already no worky.
homesweethomeMrL@lemmy.world · 25 pts · 89d
All going to plan, comrade
henfredemars@lemdro.id · 19 pts · 89d
Breached? But we left the keys in the ignition and the door was wide open. We could have, you know, tried.
flandish@lemmy.world · 13 pts · 89d
reminds me of when i lived in nashville and there had to be news bulletins reminding people to not leave firearms in their cars, as they were getting stolen.
MajorasTerribleFate@lemmy.zip · 9 pts · 89d
For a moment, I chose to imagine the danger was that your unattended firearm would steal your unattended car.
flandish@lemmy.world · 5 pts · 89d
that’s a new model s&w lol.
ironycanal@lemmy.dbzer0.com · 4 pts · 89d
we could not have done shit.
zd9@lemmy.world · 113 pts · 89d
jesus christ
This regime has caused so much damage to our national security, much of which we won't discover for years or decades. The Russians and Chinese (and literally anyone else) are probably fully infiltrated into our entire system in every aspect. SO fucking incompetent and corrupt.
henfredemars@lemdro.id · 46 pts · 89d
We’re barely even trying with the massive cuts to cyber security. It’s almost the exact playbook you would use if leadership were actively hostile.
zd9@lemmy.world · 49 pts · 89d
Trump and co are actively hostile to the US government though. There have been entire books written about how compromised he is. He's the perfect insider threat example: in debt to foreign powers, selfish and looking to make personal money, lies about his dealings, easily temptable with honeypot women (and Epstein girls, fucking sick), no allegiance or any form of duty to country or anything bigger than himself because he's a massive nihilist narcissist.
Really really scary times for anyone in America.
Aqarius@lemmy.world · 19 pts · 89d
Don't worry, soon the folks in charge will come to the inevitable conclusion that the government systems are all compromised, so clearly the only solution is to privatise them and have thevNSA run by Palantir.
zd9@lemmy.world · 17 pts · 89d
you joke... but that's literally the plan. Thiel, Musk, Andreeson, Horowitz, and the rest of the Yarvinites are trying to consume as much of the government and state power as possible.
Lost_My_Mind@lemmy.world · 18 pts · 89d
See, that's the thing. I always grew up with the phrase "Don't blame on malice what can be explained by incompetence".
But at a certain point, IS it incompetence anymore??? At this point it's starting to feel very very deliberate.
kent_eh@lemmy.ca · 12 pts · 89d
In this case it is both malice and incompetence acting together to create the worst possible outcomes.
Malyca@lemmy.zip · 3 pts · 89d
They are hostile, their mission is to destroy us
prole@lemmy.blahaj.zone · 9 pts · 89d
We're also creating generations of new enemies and potential "terrorists".
And Democrats will inevitably be blamed when they attack us in the future.
zd9@lemmy.world · 4 pts · 89d
I think we're headed towards a Troubles type scenario. Like a decade or more of stochastic terrorism, some organized groups, lots of violent suppression by the government, and further corporate capture of the state. I guess that's just the fascist end goal.
homesweethomeMrL@lemmy.world · 94 pts · 89d
But wait
This is shameful incompetence. Just head-rolling abysmal incompetence. These are the people they hired, for all you 1337 hax0rz currently looking.
atomicbocks@sh.itjust.works · 44 pts · 89d
As a dev who’s been unemployed for 18 months your last sentence was pretty much my first thought when reading the article.
homesweethomeMrL@lemmy.world · 6 pts · 89d
Sorry, I hear ya. You are so not the only one either. Hang in there. Hey - this place may have some open positions soon?
CosmicTurtle0@lemmy.dbzer0.com · 12 pts · 89d
Outside of the sheer incompetence of this administration, is there ANY chance this was done intentionally as a honeypot or something along those lines?
The fact that the commits were explicit along with bypassing all the checks could read as someone trying to see who knocks on the door.
homesweethomeMrL@lemmy.world · 14 pts · 89d
I don’t see it. Like the guy in the article said, it starts out looking like a joke . . . Buuuut it ain’t.
phutatorius@lemmy.zip · 1 pts · 89d
Not a honeypot. Treason.
TheVoiceOfRaison@thelemmy.club · 9 pts · 89d
ELIT please.
Explain like im Trump in case you didn't get the T bit. Sorry.
henfredemars@lemdro.id · 22 pts · 89d
Our best and finest left the safe combo next to the safe and then left for 6 months.
TheVoiceOfRaison@thelemmy.club · 4 pts · 89d
Best and finest indeed. Thanks for the dumbing down for me.
homesweethomeMrL@lemmy.world · -7 pts · 89d
Woke computer nerds fucked us
Edit: just to reassure the more anxious amongst us, I mean ‘woke’ in the maga sense of anything-i-don’t-like-is-woke. Not actually woke.
Actually woke computer nerds observe proper security protocols ffs.
squidman64@lemmy.world · 7 pts · 89d
Unfortunately you can’t ironically pretend to be a dumb asshole on the internet because you become indistinguishable from the actual dumb assholes
binux@sh.itjust.works · 8 pts · 89d
Poe’s law binds us all
Sidhean@piefed.social · 3 pts · 88d
Beautiful, woke computer nerds, and they're gonna replace nuclear. My uncle, he was a nuclear woke, and he said, he said you know what, computers are the future, they're gonna replace nuclear. He dosen't have the socks for it, and the electronic wokes, they have these socks that just make the computer work for them, ok, the computer works for them. The computers will work for the nuclear.
AA5B@lemmy.world · 7 pts · 89d
“Mistake”. Yeah, no. That’s someone thinking policies aren’t meant for them and blindly taking the easiest path. Sounds just like those 1337 hax0rs they gave the keys to
In a sane world this should get clearances revoked so they never again deal with any private data
boatswain@infosec.pub · 86 pts · 89d
Here's a link to the Krebs on Security article that Gizmodo used as a source: https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
mlg@lemmy.world · 86 pts · 89d
GitHub gets autoscanned by thousands of malicious actors for keys and credentials on every commit, including the comments lol.
The fact that CISA themselves never saw an automated breach attempt only minutes after pushing to github is the more interesting story here.
Either the contractor is so incompetent that they didn't have any logging set up and the breach went completely unnoticed for 6 months.
Or this really is some fat honeypot that they won't admit is a honeypot because they've been using it to watch or bait APTs.
This is literally impossible unless it really was a honeypot. You can demo this yourself in real time. Make a throwaway cloud account on your favorite provider, commit the cloud auth token into a repo, and you will see an automated bot login within minutes.
Commiting any secrets to a public repo should just be considered auto compromised because of how potent it is.
That stuff ususlly gets exposed via poor CI/CD permissions where credentials are required, but straight up file commit is like publicly announcing exactly where you left your house keys lol.
Ironfacebuster@lemmy.world · 32 pts · 89d
Can confirm, with one of my first discord bots I accidentally committed the token and within a day someone logged in and announced in every server it was in that the token was compromised
Taldan@lemmy.world · 29 pts · 89d
Based greyhat
trackball_fetish@lemmy.wtf · 9 pts · 89d
My first thought was that sounds intentional..
4am@lemmy.zip · 8 pts · 89d
Straight up file committing is like making a copy of your house keys for anyone who can see you at that moment and all moments thereafter lol
whotookkarl@lemmy.dbzer0.com · 70 pts · 89d
Imagine fucking up so bad security researchers think it must be an obvious honey pot until they see what the credentials give access to
dreadbeef@lemmy.dbzer0.com · 50 pts · 89d
This isnt a leak. This is incompetency.
LodeMike@lemmy.today · 12 pts · 89d
"Store gets robbed after owner leaves door wide open at night"
dreadbeef@lemmy.dbzer0.com · 3 pts · 88d
"Store owner invited robbers at night to steal their own goods" is how this article would word that
dhork@lemmy.world · 36 pts · 89d
Why are people acting surprised? This is exactly what DOGE intended to do.
cyberpunk007@lemmy.ca · 5 pts · 89d
This is like being surprised someone died in a fatal car accident after their wheel came off on the highway because they handed a wheel and lug nuts to a 10 year old and said "put this on"
MeThisGuy@feddit.nl · 2 pts · 89d
10 yr olds are allowed to work on cybertrucks?
phutatorius@lemmy.zip · 2 pts · 89d
Who knows what happens in Chinese factories?
db2@lemmy.world · 36 pts · 89d
"Leak"
Kowowow@lemmy.ca · 14 pts · 89d
Not exactly a B&E if I leave my keys where others can use them
tomiant@piefed.social · 3 pts · 89d
That's a fire hydrant strength jet of piss.
wonderingwanderer@sopuli.xyz · 30 pts · 89d
Is this the same cybersecurity agency that fired all its professionals to replace them with sycophants?
BaroqueInMind@piefed.social · 29 pts · 89d
Its dumb shit like this that reassures me that AI will definitely take over cyber security jobs and make shit even LESS secure than everything already is.
fullsquare@awful.systems · 10 pts · 89d
the few who will stay sharp will have endless job security
phutatorius@lemmy.zip · 2 pts · 89d
You'll have a history of pushing back so they'll regard you as a potential problem employee.
fullsquare@awful.systems · 2 pts · 89d
good luck with picking and choosing after brainrot as a service does irreparable damage
Mulligrubs@lemmy.world · 19 pts · 89d
Governments and corporations are made up of people, and when people see other people treated like garbage, they tend to become less diligent in their own duties, and loyalty is thrown out the window. Revenge is never off the table.
Also, even if you get rid of everybody so that no witnesses of your injustice remain, you've filled those positions with neophytes, who are incompetent for quite some time (at least).
that's the notorious "double whammy catch-22 fuck around find out" phenomenon, a TRIPLE THREAT
Marshezezz@lemmy.blahaj.zone · 19 pts · 89d
GreenKnight23@lemmy.world · 2 pts · 89d
tomiant@piefed.social · 13 pts · 89d
Wow. Wowowowowowowowow. Wow.
jjlinux@lemmy.zip · 2 pts · 89d
This is the only logical reaction, honestly 🤣
Lost_My_Mind@lemmy.world · 2 pts · 89d
It was super easy! Barely an inconvenience!
SabinStargem@lemmy.today · 10 pts · 89d
homes@piefed.world · 9 pts · 89d
that's, uh... that's bad, right?
giacomo@lemmy.dbzer0.com · 9 pts · 89d
well, its not good
mech@feddit.org · 13 pts · 89d
Unless you're China.
homesweethomeMrL@lemmy.world · 1 pts · 89d
Mmmmm . . Nnno, i don’t have that one. Oh - there’s a “Ghyynah”, is that it?
TryingToBeGood@reddthat.com · 8 pts · 89d
OMG
LovableSidekick@lemmy.world · 7 pts · 89d
I'm surprised whatever software the keys were for didn't detect this and deactivate the keys. Discord did this automatically when I pushed a file to github that had a bot login token in it. Apparently Discord constantly scans github for such things, or maybe github does and sends Discord a msg, I dunno. But it was amazingly fast, like within 2 minutes.
Wildmimic@anarchist.nexus · 7 pts · 89d
that feature was probably deactivated, just like the feature on github which prevents uploading of SSH keys that had been explicitly disabled
LovableSidekick@lemmy.world · 6 pts · 89d
No, I just checked - it's part of github's "Secret Scanning", which checks pushes for secret values and notifies partner services (like Discord) to deactivate them.
mynameisbob@lemmy.ml · 6 pts · 89d
U.S. Cybersecurity Agency == Chat_gipity_techno_turds or short version doge_after_birth... like top jorb in the land man...or should be. Always running from or running to. Constipation or diarrhea
sp3ctr4l@lemmy.dbzer0.com · 5 pts · 89d
Fast. Cheap. Good.
At best, pick 2.
This applies to code and coders as well, despite management's inability to comprehend reality.
Professorozone@lemmy.world · 4 pts · 89d
Defund DHS.
wewbull@feddit.uk · 4 pts · 89d
...but remember, everything needs to be written in memory safe languages to stop security breaches.
gnufuu@infosec.pub · 6 pts · 89d
"I might get mugged in a dark alley, so why should I bother locking my door at home?"
smeenz@lemmy.nz · 3 pts · 89d
Security breeches stop your phone falling out while riding a horse.
Monte_Crisco@thelemmy.club · 4 pts · 89d
And, when mainstream media periodically interviews republican congressmen who happen to be opposed to the Trump admin’s latest corruption/idiocy, why the hell do they never ask “Since you’re against these illegal/irresponsible actions… what the flying F are you gonna do about it?”
getFrog@piefed.social · 2 pts · 89d
huh, so they've never used npm?
Agent641@lemmy.world · 2 pts · 89d
Honeypot?
Bytemeister@lemmy.world · 3 pts · 89d
A container of sweet stuff that you get stuck in.
Basically, a system full of juicy looking data that takes forever to collect and process... And then it was all fake data the whole time.
Plus, you can hide some real info, like the name of the machine compromised, or info about the attacker's system in the data, and then when it gets compromised, sold on the black market, and eventually published, you can reference the leaked data to see exactly which system the hackers got into, and get some insights on how they did it.
DragonOracleIX@lemmy.ml · 1 pts · 89d
cadekat@pawb.social · -3 pts · 89d
Passwords were a mistake.
homesweethomeMrL@lemmy.world · 3 pts · 89d
Government contractors were a mistake
Feathercrown@lemmy.world · -4 pts · 89d
What are the odds this was AI related vs some underpaid intern
dogslayeggs@lemmy.world · 8 pts · 89d
This was a dev who wanted to sync data between their home and work computers so they could do check-ins from home. This is a combination of a lazy person who values their own ease of use over basic security practices, plus a government contractor who values making as much money as possible by paying shitty devs without any real oversight over those shitty devs, plus an oversight government entity that had its funding slashed by people who only understand cutting money as opposed to national security.
Feathercrown@lemmy.world · 1 pts · 89d
Nothing can beat real organic stupidity
homesweethomeMrL@lemmy.world · 6 pts · 89d
I’m sure that will be an excuse but no, this was lazy-ass we-dont-wanna incompetent garbage devs.
Hawke@lemmy.world · 3 pts · 89d
Odds are neither and it’s a “plausibly deniable” attack.
frongt@lemmy.zip · -1 pts · 89d
Or worse, both