🦞🌯 Lobster Roll

Thread

Clone2Leak: Your Git Credentials Belong To Us (flatt.tech)

Stories related to "Clone2Leak: Your Git Credentials Belong To Us" across the full archive.

Clone2Leak: Your Git Credentials Belong To Us (flatt.tech)
git-secrets: Prevents you from committing secrets and credentials into git repositories (github.com)
I Leaked Credentials Onto A Public GitHub Repo (johnmathews.eu)
Preventing Abuse of Digital Credentials (w3.org)
Phandroid's Android Forums hacked: 1 million user credentials stolen | ZDNet (zdnet.com)
Enhancing digital certificate security (fake *.google.com SSL cert issued) (googleonlinesecurity.blogspot.de)
GitHub team management and repo security (fromonesrc.com)
Using Cryptography to Store Credentials Safely (android-developers.blogspot.com)
New GitHub Pages domain: github.io (due to security concerns) (github.com)
NIST Approves FIPS 186-4, Digital Signature Standard (cryptome.org)
Adobe credentials and the serious insecurity of password hints (troyhunt.com)
Google further improves digital certificate security (googleonlinesecurity.blogspot.com)
Improving GitHub's SSL setup (github.com)
Gitian: a secure software distribution method (gitian.org)
How I hacked Github again (homakov.blogspot.com)
GitHub RCE by Environment variable injection Bug Bounty writeup (gist.github.com)
ECDSA: The digital signature algorithm of a better internet (blog.cloudflare.com)
AWS urges developers to scrub GitHub of secret keys (mobile.itnews.com.au)
DigitalOcean Security Disclosure 2014-03-30: Not destroying droplets securely, data is completely recoverable (gist.github.com)
Github Pages Now Supports HTTPS, So Use It (konklone.com)
Maintaining digital certificate security (googleonlinesecurity.blogspot.com)
Forged certificates for Google were found in the wild, signed by a certificate that's present in (only) the Microsoft Root Store.
Digits - a better way to sign in (digits.com)
Vulnerability announced: update your Git clients (github.com)
Gitrob: Putting the Open Source in OSINT (michenriksen.com)
China's Man-on-the-Side Attack on GitHub (netresec.com)
Pin-pointing China's attack against GitHub (blog.erratasec.com)
HTTP Request Race Conditions on Facebook, DigitalOcean, LastPass (Fixed) (josipfranjkovic.blogspot.com)
Auditing GitHub users’ SSH key quality (blog.benjojo.co.uk)
One in every 600 websites has .git exposed (jamiembrown.com)
Sustaining Digital Certificate Security, Symantec mis-issuing 164 certificates over 76 domains (googleonlinesecurity.blogspot.com)