Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Coffee, Chaos and ProdSec. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Coffee, Chaos and ProdSec or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Ep 09 - Secrets in the Code - How Leaked Keys Can Sink a Ship

54:21
 
Share
 

Manage episode 521475389 series 3703758
Content provided by Coffee, Chaos and ProdSec. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Coffee, Chaos and ProdSec or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

Ever pushed an API key at 2 a.m. and hoped nobody noticed? In this episode, we dig into one of the most preventable but devastating security failures: secrets in code. From leaked AWS keys and OAuth tokens to misconfigured GitHub Actions, we explore how small oversights can open the door to massive breaches, and why this problem keeps growing every year.

We break down real-world incidents like hardcoded admin credentials and recent supply-chain compromises, showing how each one spiraled from simple mistake to global impact. Then we look at the systemic reasons it keeps happening, velocity over hygiene, CI/CD complexity, and the myth that “encrypted” equals “secure.”

Grab your mug and join us as we share practical fixes that actually work, from automated scanning and vault integration to culture-level change. Because in the end, secrets management isn’t a feature, it’s survival.

  continue reading

16 episodes

Artwork
iconShare
 
Manage episode 521475389 series 3703758
Content provided by Coffee, Chaos and ProdSec. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Coffee, Chaos and ProdSec or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

Ever pushed an API key at 2 a.m. and hoped nobody noticed? In this episode, we dig into one of the most preventable but devastating security failures: secrets in code. From leaked AWS keys and OAuth tokens to misconfigured GitHub Actions, we explore how small oversights can open the door to massive breaches, and why this problem keeps growing every year.

We break down real-world incidents like hardcoded admin credentials and recent supply-chain compromises, showing how each one spiraled from simple mistake to global impact. Then we look at the systemic reasons it keeps happening, velocity over hygiene, CI/CD complexity, and the myth that “encrypted” equals “secure.”

Grab your mug and join us as we share practical fixes that actually work, from automated scanning and vault integration to culture-level change. Because in the end, secrets management isn’t a feature, it’s survival.

  continue reading

16 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play