March 6, 2021
Hot Topics:

TruffleHog Searches for Secret Keys in Git Repositories

  • By Developer.com Staff

A security researcher named Dylan Ayrey has released an open source tool called TruffleHog that searches through Git repositories for cryptographic keys. TruffleHog looks for strings of characters with "high entropy," in other words they look like encryption keys that would be difficult to crack. When it finds them, it displays them on the screen.

The tool represents an obvious security risk to developers who may have inadvertently committed keys to GitHub repositories, but it may have some beneficial uses as well. Amazon Web Services is said to use this tool or something similar to search repositories for keys for its cloud computing service in order to prevent attackers from finding the keys and running up large bills on other people's accounts.

View article

This article was originally published on January 9, 2017

Enterprise Development Update

Don't miss an article. Subscribe to our newsletter below.

Thanks for your registration, follow us on our social networks to keep up-to-date