NewsTruffleHog Searches for Secret Keys in Git Repositories

TruffleHog Searches for Secret Keys in Git Repositories

Developer.com content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

A security researcher named Dylan Ayrey has released an open source tool called TruffleHog that searches through Git repositories for cryptographic keys. TruffleHog looks for strings of characters with “high entropy,” in other words they look like encryption keys that would be difficult to crack. When it finds them, it displays them on the screen.

The tool represents an obvious security risk to developers who may have inadvertently committed keys to GitHub repositories, but it may have some beneficial uses as well. Amazon Web Services is said to use this tool or something similar to search repositories for keys for its cloud computing service in order to prevent attackers from finding the keys and running up large bills on other people’s accounts.

View article

Get the Free Newsletter!

Subscribe to Developer Insider for top news, trends & analysis

Latest Posts

Related Stories