Skip to content
Artwork for Security Insights
Security Insights · May 28 · 29 min

In plain sight: hunting secrets shared in code

Security researchers have found millions of hard-coded secrets, in plain text, across both public and private code repositories. These include credentials, API keys, AI tokens and MCP configuration files. And AI is making the problem worse, with AI-assisted commits adding to this "secrets sprawl". Unless developers control how they manage secrets in their code, we are leaving the door open to malicious actors. And the growth of non-human identities (NHIs) only makes it worse. Our guest is Dwayne McDaniel, principal developer advocate at GitGuardian, which recently published their research into secrets sprawl.

0:00-29:55

transcript

No transcript — this publisher did not publish one.

show notes

Security researchers have found millions of hard-coded secrets, in plain text, across both public and private code repositories.

These include credentials, API keys, AI tokens and MCP configuration files.

And AI is making the problem worse, with AI-assisted commits adding to this "secrets sprawl".

Unless developers control how they manage secrets in their code, we are leaving the door open to malicious actors. And the growth of non-human identities (NHIs) only makes it worse.

Our guest is Dwayne McDaniel, principal developer advocate at GitGuardian, which recently published their research into secrets sprawl.

links1