.@trufflesec co-founder and CEO Dylan Ayrey on the danger of exposed credentials and the Hugging Face incident:
"We partnered with Hugging Face to clean up credentials that had been exposed in training sets people hosted on their platform."
"There were about a quarter million live keys, many of which had direct supply chain implications."
"There was a foundational Linux library that one of the keys had direct push access to. It could have pushed malware to most machines on the planet."
"While in the middle of doing that, the CTO of Hugging Face shoots me a note, 'There's this OpenAI thing that just happened, take a look.'"
"And sure enough, the first thing listed in the incident response was stolen credentials. The path of least resistance is always the first step."
@InsecureNature
Video
roon (@tszzl)
needless to say but if you have any API keys, eth wallet keys, user credentials, etc hanging out on the open internet in pastebins, GitHubs, etc now is the time to take it down before the tireless eagle eyes of a million models come looking
— https://nitter.net/tszzl/status/2085193063157383558#m