HMAC Secrets Explained: Authentication You Can Actually Implement
A developer-first guide to implementing HMAC signatures correctly.
A developer-first guide to implementing HMAC signatures correctly.
Despite secrets like API keys, OAuth tokens, certificates and passwords being extremely sensitive, it is common for these to leak into git repositories through source code. This article looks at why this is true and how we can prevent it.
Credential theft is already a well-known adversary technique but the risk expands much wider when introducing secrets such as API keys. This article looks at automated secrets detection, the challenges, and potential solutions.
The first in a series of articles that will take a deep dive into secrets within source code: In this article, we will look at the concept of secret sprawl, the unwanted distribution of secrets through multiple systems, and how we can prevent it.
A helpful glossary of common terms and definitions used in DevSecOps explained with amusing comics.
How to scan local files for secrets like API keys and security certificates in python using the GitGuardian API.
An in depth guide intended for CISOs, application security and other security professionals who want to protect their organizations from credentials leaked on GitHub.
A list of 8 free must use security tools every developer should know about to help them secure their code and Shift Left.
Why precision and recall are such important metrics to consider when evaluating the performance of classification algorithms such as secrets detection.
Git hooks are extremely useful to secure the development practice. In this blog post, I will take the example of detecting secrets in source code to illustrate how you can make the most out of git hooks.
There is no doubt that the world's workforce is becoming more remote, particularly in tech as developers can now work from any location in the world. But there are a large number of new obstacles that come with this. The most pressing is security.
February 2020: despite being widely considered to be a very bad practice, secrets stored in internal Version Control Systems is the current state of the world. But why is that?
GitGuardian, the French company specialized in cybersecurity, raised 12 million dollars with Balderton Capital. The company’s CEO, Jérémy Thomas, is with FrenchWeb to tell us more.