Truffle Security has published the results of an analysis of credential leaks in repositories hosted on GitHub. As a result of scanning 224 million repositories containing 58 billion files, 543 thousand unique credentials (tokens, keys and passwords) were identified that continue to be valid. Valid credentials remained in the repositories for at least a year, since the study used a snapshot of GitHub status from August 7 last year, and verification of the relevance of credentials, implemented through test calls to APIs, network services and hosts, was performed at the end of July this year.
The median time that credentials were publicly available was estimated at 784 days, while the oldest still valid access keys were dated 2009 Nearly 200,000 found valid credentials were pushed into repositories after GitHub enabled by default a mechanism to block leaks of sensitive data and access tokens that performs verification at the point of sending push requests. Leaks were not recognized due to placement in formats not supported in the implemented protection, despite the fact that directly enabling filters reduced leaks of recognized credentials by approximately half.
It turned out that GitHub successfully detects token leaks to common services, such as GitHub, AWS, Slack, SendGrid, Stripe and GCP, but misses connection parameters left in the code DB, Google API access keys and private keys. Database connection parameters and private keys are not blocked by default to avoid false positives. Google API access keys are not blocked, as they have the prefix AIzaSy, like Google Maps public keys intended for integration into web pages.
As for the credentials found that turned out to be non-working, most of them relate to access tokens and keys associated with services that provide a revocation mechanism. For example, out of 101,886 NPM tokens, only one was identified as valid (0.001%), out of 73,048 GitHub tokens – 260 (0.35%), and out of 30,437 Hugging Face tokens – 15 (0.05%). For Stripe keys, the survival rate was 4%, AWS – 8%, GCP – 8%, Slack – 2%, GitLab – 0.64%. For comparison, out of 12985 identified parameters for connecting to the PostgreSQL DBMS, 11465 (88%) remained active, out of 2421 parameters for connecting to MySQL – 1806 (74%), out of 126963 Google Cloud service accounts – 69041 (54%), out of 3790 tokens to Docker Hub – 1244 (33%), and out of 22800 keys to SendGrid – 9189 (40%).
Prior to this, the researchers examined about 7.5 PB of data for training AI models distributed through Hugging Face, and identified there were 221 thousand valid credentials in them.