14
Contractor leaked live AWS keys, we caught it after 11 hours
I got a ping from our security scanner around 2pm last Tuesday saying a contractor had pushed a config file with live AWS keys, not dummy ones, to a public repo. We use those keys for a billing integration that hits our payment provider, so I had to act fast. I revoked them within 20 minutes and rotated every related secret across our three environments, which took the rest of the afternoon. The scary part is the repo had been public for almost 11 hours before the alert fired, so anyone could have grabbed those keys. I checked the logs and found no strange calls, but it felt like pure luck. Our team now uses a secret scanning hook on every push, but I still worry about third parties we can't control. How do you all handle API key leaks from contractors or outside vendors, especially when they ignore your onboarding checklist?
0 comments
Log in to join the discussion
Log In0 Comments
No comments yet
Be the first to share your thoughts on this discussion.