frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

GitLab scan finds 17,000 secrets in public repos, leading to $9000+ in bounties

https://trufflesecurity.com/blog/scanning-5-6-million-public-gitlab-repositories-for-secrets
30•adrianwaj•2mo ago

Comments

vatsachak•2mo ago
9000 in bounties for 17,000 secrets?

You could make as much in a month creating those vulnerabilities

3eb7988a1663•2mo ago
The post keeps saying "verified secrets" - how are they verified? Did the author attempt to login to each service? Or does verified just means that it looks like a valid token?
ctippett•2mo ago
Tools like TruffleHog[1] will attempt to verify any credentials it finds by making some sort of authenticated request.

[1] https://github.com/trufflesecurity/trufflehog#validation-

jsiepkes•2mo ago
> Each Lambda invocation executed a simple TruffleHog scan command with concurrency set to 1000. This setup allowed me to complete the scan of 5,600,000 repositories in just over 24 hours.

Gitlab must have been thrilled about a bot cloning 5.6 million repo's in 24 hours. That doesn't really sound responsible to me.

treyd•2mo ago
That's 64 clones per second. That's quite a lot but it seems like something that a forge operating at the scale of GitHub can handle, especially if they were --depth=1 (which might have missed some secrets if someone was lazy about clearing their git history).
nojs•2mo ago
Gitlab*
digi59404•2mo ago
Provided someone told GitLab Support. This was likely fine. GitLab can handle this much load. The platform as a whole has increased and improved over the years as new customers are added.

Think about this… every CI/CD Job runs a clone. That’s a lot..

47282847•2mo ago
If they don’t like, they will apply rate limiting? Assuming they were well behaved (user agent, IPs).
pcdevils•2mo ago
Assuming bog standard lambda they'd have to rate limit a whole Aws region lambda range which would risk affecting legit usage. Bit of an arse way to behave against a service
3eb7988a1663•2mo ago
I also thought the sleep(0.03) was cute. Some well deserved rest for the server to avoid hammering it.
iwontberude•2mo ago
Truffle Security treasury dollars: There are dozens of us! Dozens!
greatgib•2mo ago
"Google Cloud Platform (GCP) credentials were the most leaked secret type on GitLab repositories"

Not surprising, Google SDK are sucking so much in term of authentication. It's never something simple like an API key, always a shitty iam like opaque function based on an opaque sdk needing to be installed that in the end requires a huge json. And most of the time, it is a pain in the ass to provide the token "as-is" in a buffer but the sdk expects that you give a file path to it. So, I easily guess that a lot of lazy devs will just store the credential json file in their project and consider it a job done.

France's homegrown open source online office suite

https://github.com/suitenumerique
228•nar001•2h ago•120 comments

British drivers over 70 to face eye tests every three years

https://www.bbc.com/news/articles/c205nxy0p31o
12•bookofjoe•12m ago•4 comments

Start all of your commands with a comma (2009)

https://rhodesmill.org/brandon/2009/commands-with-comma/
380•theblazehen•2d ago•135 comments

Hoot: Scheme on WebAssembly

https://www.spritely.institute/hoot/
65•AlexeyBrin•3h ago•12 comments

Reinforcement Learning from Human Feedback

https://arxiv.org/abs/2504.12501
42•onurkanbkrc•3h ago•2 comments

OpenCiv3: Open-source, cross-platform reimagining of Civilization III

https://openciv3.org/
749•klaussilveira•18h ago•234 comments

The Waymo World Model

https://waymo.com/blog/2026/02/the-waymo-world-model-a-new-frontier-for-autonomous-driving-simula...
1005•xnx•23h ago•570 comments

Coding agents have replaced every framework I used

https://blog.alaindichiappari.dev/p/software-engineering-is-back
113•alainrk•3h ago•125 comments

Show HN: One-click AI employee with its own cloud desktop

https://cloudbot-ai.com
9•fainir•1h ago•4 comments

First Proof

https://arxiv.org/abs/2602.05192
13•samasblack•42m ago•7 comments

Stories from 25 Years of Software Development

https://susam.net/twenty-five-years-of-computing.html
10•vinhnx•1h ago•1 comments

Vocal Guide – belt sing without killing yourself

https://jesperordrup.github.io/vocal-guide/
136•jesperordrup•8h ago•55 comments

Unseen Footage of Atari Battlezone Arcade Cabinet Production

https://arcadeblogger.com/2026/02/02/unseen-footage-of-atari-battlezone-cabinet-production/
92•videotopia•4d ago•21 comments

A Fresh Look at IBM 3270 Information Display System

https://www.rs-online.com/designspark/a-fresh-look-at-ibm-3270-information-display-system
7•rbanffy•3d ago•0 comments

Ga68, a GNU Algol 68 Compiler

https://fosdem.org/2026/schedule/event/PEXRTN-ga68-intro/
30•matt_d•4d ago•6 comments

Making geo joins faster with H3 indexes

https://floedb.ai/blog/how-we-made-geo-joins-400-faster-with-h3-indexes
148•matheusalmeida•2d ago•40 comments

Show HN: Look Ma, No Linux: Shell, App Installer, Vi, Cc on ESP32-S3 / BreezyBox

https://github.com/valdanylchuk/breezydemo
254•isitcontent•18h ago•27 comments

Monty: A minimal, secure Python interpreter written in Rust for use by AI

https://github.com/pydantic/monty
267•dmpetrov•18h ago•142 comments

Show HN: Kappal – CLI to Run Docker Compose YML on Kubernetes for Local Dev

https://github.com/sandys/kappal
10•sandGorgon•2d ago•2 comments

Hackers (1995) Animated Experience

https://hackers-1995.vercel.app/
532•todsacerdoti•1d ago•258 comments

Sheldon Brown's Bicycle Technical Info

https://www.sheldonbrown.com/
409•ostacke•1d ago•105 comments

Show HN: I spent 4 years building a UI design tool with only the features I use

https://vecti.com
354•vecti•20h ago•160 comments

Show HN: If you lose your memory, how to regain access to your computer?

https://eljojo.github.io/rememory/
324•eljojo•21h ago•198 comments

What Is Ruliology?

https://writings.stephenwolfram.com/2026/01/what-is-ruliology/
55•helloplanets•4d ago•56 comments

An Update on Heroku

https://www.heroku.com/blog/an-update-on-heroku/
450•lstoll•1d ago•296 comments

Microsoft open-sources LiteBox, a security-focused library OS

https://github.com/microsoft/litebox
365•aktau•1d ago•191 comments

Cross-Region MSK Replication: K2K vs. MirrorMaker2

https://medium.com/lensesio/cross-region-msk-replication-a-comprehensive-performance-comparison-o...
6•andmarios•4d ago•1 comments

How to effectively write quality code with AI

https://heidenstedt.org/posts/2026/how-to-effectively-write-quality-code-with-ai/
294•i5heu•21h ago•247 comments

Dark Alley Mathematics

https://blog.szczepan.org/blog/three-points/
103•quibono•5d ago•30 comments

Female Asian Elephant Calf Born at the Smithsonian National Zoo

https://www.si.edu/newsdesk/releases/female-asian-elephant-calf-born-smithsonians-national-zoo-an...
53•gmays•13h ago•22 comments