State of Secrets Sprawl in 2024 with Mackenzie Jackson
Mackenzie Jackson, developer advocate at GitGuardian, talks about the State of Secrets Sprawl 2024 report. The study is the most comprehensive research on exposed secrets in public GitHub.
Transcript
This is Text Drunk tv. Hi everyone. Welcome back here to Text Drunk tv.
Uh, next up we, we have a, uh, a report from Git Guardian about the, uh, state of secrets sprawl, and we're joined by Mackenzie Jackson, who's developer advocate over at, at Get Guardian. Hey, Mackenzie, welcome to Techstrong tv. Hey, a, it's great to, great to be here.
Thanks for having me on. Thank you. Um, Mackenzie, before we jump into this report though, let's talk a little bit about you, you know, developer advocate is, look it, it's not, uh, 10 years ago, seven years ago, maybe we didn't have those kinds of roles, right?
Yeah. It's very new, but in today's world, it's not unusual. But let's hear a little bit about your journey to becoming a developer advocate at GI Guardian.
Yeah, yeah. It's, uh, I'll try to give you the condensed version, uh, of the, uh, the co-founder and, and CTO of a, of a previous startup in healthcare called Congo, which is, uh, still exists today, headquartered in, in Australia. Um, you know, but then it comes a point where a company grows, uh, grows so large, you need to make a decision.
Do, do you hire a real CTO or do you, or do you keep pretending? Um, mm-Hmm. And I, I found this role in, in developer advocacy where I get to work with research teams and kind of nerd out, which is exactly what I wanted to, to do and get to share, uh, in, in that research and in all the great stuff in security that's going on around, around the world.
Uh, so that's kind of how I ended up, uh, at, at at at GI Guardian at this point. Excellent. And, and for those of, uh, people in our audience, Mackenzie, who maybe aren't familiar with GI Guardian, how would you describe the company to them?
Yeah, we're, we're a code security platform and basically everything that we do is about, uh, helping, uh, developers, companies and organizations, uh, write secure software. Uh, so we started off detecting our, what we call secrets, so credentials, API, keys, things like that inside Source code. We've now expanded that into lots of different areas.
We, um, and to become a kind of complete code security, uh, platform. But everything that we do, we live and breathe security, and we are all about trying to make security as easy as possible and put it in the developer's lifecycle, uh, so that, uh, we become less of the, the people of the sticks and more of the, the people that can and help build secure software. Yep.
And, and, you know, with a name like Git Guardian, I'm assuming, you know, Git providing security within Git, sort of in a GI ops type of envir, uh, framework is, is important to the mission here, or not really? Yeah, ex No, exactly. And, uh, I mean, uh, for those that you know are in the world of tech, you're probably all familiar with what GIT is.
It's kind of like the central meeting place of everything. You know, where all the developers come to work, it's where pipelines spinoff from, um, it's where, so everything that between GI ops, DevOps, and DevSecOps and developmental kind of centralizes in this, in your Git repositories. So, you know, that was kind of the obvious place for us to start.
Now, of course, you know, the company's, uh, older than what it, what it was, you know, it's, it is been around for, for, for many years now. So we do more than just security around Git, but that's still central to, uh, our core, uh, as at securing software. Got it.
Got it. Got it, got it. com?
com? Yep. Perfect.
All right, Mackenzie, let's jump in here now to this, uh, it's the 2024 edition of the state of Secret Spor Sprawl report. Uh, you know, being that it's the 2024 edition, I'm assuming there's been previous editions, why don't you give us a little bit of the history and scope of, of the, uh, of this report, and then we'll jump into like this year's edition of it? Yeah.
Uh, I'd love to, uh, gig Guardian started, uh, as a company, almost as a side project with, with our founders scanning, uh, basically the largest data data set of source code there is, and that's public repositories, uh, on GitHub. Uh, and, uh, what they ended up fi finding was so many credentials that our whole business, and today, quite a large business was born from that. But one of the things that we do is, you know, it started off as a bit of a research project, and we've continued that research project, uh, every single year.
And basically one of the things that we do is we scan all public activity that happens on GitHub, um, and we look for secrets, things like API, key security certificates. And every single year, uh, this is the fourth edition that we've done, and every single year we publish, uh, our, our findings in it. The first year, uh, that we did, we found, uh, a little about over 3 million secrets.
Uh, we've, the, the next report we found 6 million, 10 million was last year. And this year, uh, we've continued the upward trend. 7 million secrets, so credentials that were publicly pushed, uh, on GitHub.
So that's a little bit about the history of the, the state of secrets for all report that we release. Yep. Let, let's talk about the nexus of like, secrets to the git guardian mission, right?
What, why is this real important to you guys? Yeah, so when you look at all the breaches that happen, uh, you can just take any headline. Um, the latest, the latest one in the headlines is the, a breach that's happening at Microsoft.
Nearly all of them leverage secrets at some point. The attackers leverage secrets at, at, at some point, whether it's they've made initial access into systems through secrets, whether it's, that's how they've kind of elevated the privileges or moved laterally. But secrets, you know, are, are really fundamental to attackers in being able to break into things.
And the reason is, is that we are, we are still not very good at protecting these secrets. The reason is when we look at modern applications, it's built up of all these different building blocks there. It's, it's no longer a monolith.
And all of these different building blocks, whether it be SaaS services, you know, whether it be managed systems, whether it be cloud infrastructure, all leverage secrets to be able to talk to each other, talk to your application, talk to your data. And because of that, a lot of people need to handle these secrets like developers, DevOps, your security personnel. And this makes them really hard to secure and means that it's really hard for them to kind of stay centralized so they end up sprawling an attack.
Attackers know this. So the first thing that an attacker does when they break into anything is try and find secrets, persist their access. And what we are focused on is taking, you know, the places that attackers look for this, scanning them, and then alerting people to where, where there are secrets.
So, you know, there's a lot of very sophisticated attacks that come out there and all these different chains and supply chain security. But when you get down to the core of it, you know, often the, the root causes of a lot of these breaches, um, or at least what kind of makes them bad, is something simple like a password and API key that was leaked in source code, in a email, in a Slack message, somewhere like that. So, you know, that's why we've always been just obsessed with finding these secrets because it's a very actionable attack path, and we can take that tool away from attackers really, you know, really well with the correct tooling.
Agreed. Agreed. Alright, let, let's, so the 2024 edition, as you said, we set a new high watermark for the amount of secrets that, uh, were kind of publicly accessible, you know, scanning GitHub.
Um, what, what other, you know, what are the kind of beyond that, what are the key sort of, or the big headline, you know, summary points of this? Yeah, there's one that really surprised everyone we know. We add data points every time we release this, this report.
And one of the, the data points that we added here is, you know, when we find secrets, not only do we, uh, do we detect them, but we also check where is possible if they're valid. So, hey, have you leaked, you know, a Google Cloud key? Yes.
And, and is that key still valid? So, you know, we, we've been doing this for a long time, but one of the things we added into the report this year is we decided to check, hey, after we've found a secret, after we've alerted the person to that secret, how long does it remain active for? And we're quite shocked because, uh, even with us reporting on it, over 90% of the secrets remained active after five days.
So we kind of slowed down checking on the secrets after, after five days. But, you know, it's, that's an incredibly long amount of time. And we also saw things like people would delete the data, so delete the repository.
If they've leaked a, a source code in, uh, the, to they've leaked in source code, they delete that repository, but they don't revoke the secret. And the secret's already been out there, it's already, it's already awash in public spaces. It's already backed up onto many different services.
So, you know, the fact that so many of these secrets were not just leaked, but also remained valid after five days, over 90%, that number this year was, was really, really shocking to us. You know, and, and another, another number that kind of shocks me, um, is the amount of different developers that leaked a secret. I think everyone probably understands that, you know, pushing a password somewhere, public's bad, right?
We all get that. So how often, and who actually does it? We have this idea that it would only be, you know, an idiot that would do that.
But actually what we find is that one in 10 commit authors. So that boils down to basically one in 10 developers leak a secret every year. So, you know, you've got a company with a hundred people, even if there are a hundred of the smartest people, you know, 10 of them are still probably going to leak a secret just because it's so easy to do.
So that number also jumps out at me at the report and say, Hey, this isn't just a problem of a couple of students making mistakes. This is a systemic problem in our entire industry. Um, and a lot of that comes down to the mechanisms of get that we won't go into, but you know, it, it, it is a big problem.
7 million. You know, the big numbers are always great, but these things really kind of add context to that. What, what's really I find interesting is secrets management is, you know, it's not an old sector of security or an old segment, but it's, it's, it's a somewhat mature Yeah.
Segment, right? With multiple players. Why aren't we do it?
Uh, why aren't we doing a better job or we're doing a better job, but it's just such a big problem, You know, I think it's a, it's a little bit of everything, and it's one of the, one of the issues with this, with this problem and, and why it's so, you know, dumbfounding sometimes is that secret sprawl should be a solved problem based on the technology that we have, right? We have amazing secret management solutions out there. We have great secret detection management solutions out there.
We can send secret securely. Every single technology has a way to handle these secret securely. So, you know, like, why on earth is this still happening?
And it, it just comes down to the pressure and speed of which we develop things and also just, uh, people not understanding, you know, how sensitive it these, these, these are. And you know, like some of the simple solutions is, you know, when you're a developer and you're working on a feature, let's say you need to connect to some kind of data sort set, you know, one of the first things you do, someone gives you an API key so that you can test it, right? You may save that key on your computer so you could access it later because it's a pain to get them through the management system.
And maybe the first thing you do is you hard code that in, you're gonna delete it later. But gi and version control is very unforgiving that once we do something once, then if you know what to do, you can go back in the history and find that right ev a record of everything you do is kind of maintained and get, so even though we, you know, these secrets are kind of non-visible to humans, you can look through a source code repository and not find anything, but if you go take a step back through the history, you know, you will. And it's these types of of reasons why, you know, it's not the fact that we're storing secrets unsecurely, although sometimes, you know, people are, but it's more the fact that once they get let out of their cage, it's a high value asset that's easily duplicatable and everything has backups now, right?
Your git is probably backed up in different services. You know, you may copy source code on through messaging systems. It may be on your computer, you may store it in your network, you know, it may be even on your personal work, uh, repositories or, or you know, all of these different things.
So it's just such a hard problem to solve because, you know, they just, they just kind of run wild once they get out of their, their cage. And it's just really hard to do. And, you know, it's one of those things you have to be perfect at it every single time, because if you fail once, you know, then these secrets are gonna end up All it takes.
Absolutely. Hey, Mackenzie, we're over our 15 minutes, but for people who wanna maybe download the report and check it out for themselves, where can they go? com, and, uh, you'll find, uh, all kinds of flashing banner there.
It's to download the state of secret sprawl. It's ungated, so you don't even need to share your email with us. com, um, is, uh, the, the best place to kind of see that and also see other research that we've, we've done.
Very cool. Hey, thanks for coming on and keeping us posted on this new edition of the, uh, state, state of secret SPR all report. And, uh, we'll speak to you soon.
Excellent. Thanks for having me. All right.
Mackenzie Jackson, developer advocate here from Git Guardian, ONTECH Strong. We'll take a break. We'll be back in a minute.