当前位置:首页 >英文主页 >中英对照 > 报告详情

GitGuardian:2021年开发机密信息泄露态势报告(英文版)(23页).pdf

上传人: Kell****reet 编号:132512 2022-07-13 23页 1.83MB

下载:

1、The state of Secrets Sprawl on GitHubHOW LEAKY CAN IT GITGITGUARDIAN STATE OF SECRETS SPRAWL ON GITHUB2SummarySecrets Sprawl 4Findings 7Where leaks come from 10Why 11What type of secrets do we find 12File extensions that cause data breaches 13Pro bono alerting 16What happens after a leak 17Recommend

2、ations 20To conclude 21GITGUARDIAN STATE OF SECRETS SPRAWL ON GITHUB3GitHub is more than ever“The Place to Be”for developers when it comes to innovating,collaborating and networking.This amazing“octoverse”gathers more than 50 million developers working on their personal and/or professional projects.

3、So when 60 million repositories are created in a year and nearly 2 billion contributions*are added,some mistakes can happen,such as leaked secrets,Intellectual Property or PII.Some companies may think:I dont really care about public GitHub,we are not open sourcing our code,everything is stored on ou

4、r private repositories.But what about the developers of these companies they most likely have open source repositories and can leak secrets.*State of the octoverse 2020GITGUARDIAN STATE OF SECRETS SPRAWL ON GITHUB4Lets now focus on secrets.You would say that secrets stored in internal Version Contro

5、l Systems is a very bad practice but in fact it is much more frequent than you would think.But why is that?API keys,database connection strings,private keys,certificates,usernames and passwords As organizations move to cloud architectures,SaaS platforms and microservices,developers handle increasing

6、 amounts of sensitive information,more than ever before.To add to that,companies are pushing for shorter release cycles,developers have many technologies to master,and the complexity of enforcing good security practices increases with the size of the organization,the number of repositories,the numbe

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要讨论了GitHub上的“秘密蔓延”问题。GitHub是一个开发者和创新者聚集的平台,每天有数百万开发者在此工作。然而,由于开发者经常将个人和职业项目混合在一起,以及GitHub历史记录的公开性,秘密泄露事件时有发生。 GitGuardian分析了自2017年7月以来GitHub上所有公开提交的代码,发现每天有超过250,000个秘密泄露,2020年全年共检测到超过2500万个秘密泄露。其中,85%的泄露事件发生在组织拥有的公共仓库中,15%发生在开发者的个人仓库中。 泄露的“秘密”通常包括API密钥、数据库连接字符串、私钥、证书、用户名和密码等,这些信息一旦泄露,可能导致严重的数据安全问题。泄露的文件扩展名主要包括Python、JavaScript、JSON、XML等。 GitGuardian还提供了免费的秘密泄露警报服务,2020年共向开发者和安全团队发送了超过70万个警报。 为了减少秘密泄露的风险,建议公司使用自动化的秘密检测工具,监控开发者的个人仓库,并限制API的访问权限。同时,开发者也需要接受相关培训,了解如何安全地处理秘密信息。
如何在GitHub上保护敏感信息? 泄露的密钥对组织有哪些风险? 如何检测和修复GitHub上的安全漏洞?
客服
商务合作
小程序
服务号
折叠