news.volyx.in

CISA Admin Leaked AWS GovCloud Keys on GitHub (krebsonsecurity.com)

478 points by LelouBil · 102 days ago · 182 comments on HN

Article summary

A contractor for the Cybersecurity & Infrastructure Security Agency (CISA) leaked credentials to several highly privileged AWS GovCloud accounts and internal CISA systems on a public GitHub repository. The leak included files detailing how CISA builds, tests, and deploys software internally, and represents one of the most egregious government data leaks in recent history. The repository was taken offline after the leak was reported, but the exposed AWS keys remained valid for another 48 hours. CISA is investigating the incident and has stated that there is no indication that any sensitive data was compromised.

Main themes

  • Government data leak
  • Cybersecurity agency breach
  • AWS GovCloud security
  • GitHub repository security
  • Sensitive data exposure
  • CISA incident response

What commenters say

  • The leak is a result of individual incompetence rather than budget cuts or lack of funding.
  • Budget cuts and lack of resources are to blame for the leak, as they can lead to situations where unqualified individuals handle sensitive information.
  • The use of large language models (LLMs) can pose a significant risk to security, as they can memorize and potentially extract sensitive information.
  • Short-lived credentials and proper security practices can mitigate the risk of data leaks, but human error and poor security hygiene can still lead to breaches.
  • The incident highlights the need for better security practices and oversight within government agencies, particularly those responsible for cybersecurity.
  • The leak is a symptom of a larger problem of inadequate security measures and lack of accountability within government agencies.
  • The use of tools like SOPS and Varlock can help keep secrets out of plaintext and reduce the risk of data leaks.
  • The threat model for LLMs is not well understood, and more research is needed to determine the risks and consequences of using these models with sensitive information.