CISOOnline

GitHub App keys can still enable takeovers long after they are forgotten

“It is possibly an intentional design trade-off, not an oversight,” Sarkar said, commenting on the implementation of short-lived tokens alongside a permanent key. “This is how machine-to-machine authentication traditionally works and it prevents unexpected downtime.” The “forever” design prioritizes operational simplicity and continuity; the security burden of rotation falls entirely on App owners, he added.

GitGuardian recommends regularly rotating or revoking the private keys because they can outlive both the people who created them and the reason they did it, said Ferry. “A key committed by mistake in 2020 can still authenticate today, long after the mistake is forgotten,” he said.

Sarkar said that manual revocation is extremely rare and almost always reactive, though. “Most IT service management manuals mention its necessity, but rarely demonstrate it unless a security incident, an audit, or a specific change requires it,” he explained.



Source link