--- title: "Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets" url: https://appsecpodcast.com/dwayne-mcdaniel-secrets-sprawl-and-how-ai-is-impacting-secrets/ date: 2026-05-14 duration_seconds: 2727 season: 13 episode: 4 guests: ["Dwayne McDaniel"] topics: ["OWASP Top 10", "API Security"] audio: https://www.buzzsprout.com/1730684/episodes/19172124-dwayne-mcdaniel-secrets-sprawl-and-how-ai-is-impacting-secrets.mp3 video: https://www.youtube.com/watch?v=_uNnyc_3fV0 transcript: true --- # Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets *May 14, 2026 · 45 min · Season 13, episode 4* with [Dwayne McDaniel](https://appsecpodcast.com/guests/dwayne-mcdaniel/) on [OWASP Top 10](https://appsecpodcast.com/topics/owasp-top-10/), [API Security](https://appsecpodcast.com/topics/api-security/) [Audio](https://www.buzzsprout.com/1730684/episodes/19172124-dwayne-mcdaniel-secrets-sprawl-and-how-ai-is-impacting-secrets.mp3) · [Video](https://www.youtube.com/watch?v=_uNnyc_3fV0) ## Show notes GitGuardian found 29 million hard-coded secrets in public GitHub commits in one year—a 34% increase and its largest jump yet. Why is a supposedly simple problem getting worse? Principal Developer Advocate Dwayne McDaniel explains what the 2026 State of Secrets Sprawl report reveals about public and private repositories, AI coding tools, MCP server templates, and developer-targeted supply-chain attacks. He and Chris unpack why standing credentials persist, how private repositories create false confidence, and why frontier models may improve without solving the organizational problem. The conversation moves from detection to governance: short-lived identity, ownership, feedback loops, and the political will to remove embedded keys. Dwayne's core challenge is blunt—organizations already have better authentication patterns, so what will make them finally use them? Connect with Dwayne McDaniel: → [Dwayne McDaniel on LinkedIn](https://www.linkedin.com/in/dwaynemcdaniel) → [State of Secrets Sprawl 2026](https://www.gitguardian.com/files/the-state-of-secrets-sprawl-report-2026) Mentioned in this episode: → [GitGuardian State of Secrets Sprawl Report 2026](https://www.gitguardian.com/files/the-state-of-secrets-sprawl-report-2026) → [LangChain](https://www.langchain.com/) → [OpenRouter](https://openrouter.ai/) → [DeepSeek](https://www.deepseek.com/) → [Mistral AI](https://mistral.ai/) → [Perplexity](https://www.perplexity.ai/) → [Ox Security](https://www.ox.security/) → [SPIFFE](https://spiffe.io/) → [CNCF](https://www.cncf.io/) → [AWS STS](https://docs.aws.amazon.com/STS/latest/APIReference/Welcome.html) → [OpenID Connect](https://openid.net/developers/how-connect-works/) → [GitHub Octoverse](https://github.blog/news-insights/octoverse/) → [Claude Code](https://claude.com/product/claude-code) Chapters: 00:00 Meet Dwayne McDaniel 00:39 Dwayne's path into secrets security 02:23 How GitGuardian builds the report 05:10 Where the private-repository data comes from 06:20 Twenty-nine million leaked secrets 09:15 Why the problem persists 12:37 Secrets, identity, and standing privilege 15:21 Three ways AI makes leakage worse 16:39 Explosive growth in AI-service credentials 17:57 MCP templates teach insecure authentication 20:08 Is Claude Code getting safer? 22:55 Hope for frontier models 24:36 What will the OWASP Top 10 become? 27:27 AI-assisted attacks target developers 30:29 Old supply-chain attacks at machine speed 33:06 What are organizations protecting now? 35:39 Private repositories are six times riskier 38:48 Moving from the problem to solutions 39:21 Does the organization have the will to fix it? 40:53 Governance and short-lived credentials 44:51 Closing thoughts ## Transcript *7,768 words · assemblyai* **0:00 Chris Romeo:** Dwayne McDaniel is a principal developer advocate who has been on a mission to help people figure stuff out for over a decade. At GitGuardian, he specializes in secret security and non-human identity governance across cloud and DevOps environments. A frequent speaker at events like DevOps Days and BSides, he helps security and engineering teams better understand complex issues. Quick note, we're opening up a few sponsorship spots on the Application Security Podcast. **0:28 Robert Hurlbut:** If you want to get in front of real AppSec practitioners, the folks actually making decisions, this is a great place to do it. **0:35 Chris Romeo:** Just reach out to me, Chris Romeo. **0:37 Robert Hurlbut:** I'd love to chat. **0:38 Chris Romeo:** You can find me on LinkedIn. **0:39 Robert Hurlbut:** Hey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo, and I'm flying solo today as Robert, I guess, had to work or do something else. Excited to be joined by Dwayne McDaniel today. Dwayne and I have had the honor of doing a webinar before, but searching the AppSec Podcast archives, we haven't done a podcast yet. And so, Dwayne, what that means is you get to lead off with your security origin story. How did you get into this wild, wacky world of security? **1:27 Dwayne McDaniel:** Uh, the short version is I worked for a security vendor and it was the first time I worked for a security-specific company. Uh, but before I joined GitGuardian, my current company, I actually been talking about security through Git hooks for a little while. I have been a nerd about Git for a very long time and I've taught well over 1,000 people Git basics and internals and like how to think about it at scale. And I started thinking about the implications of Git hooks back in about 2020, 2021, like the implications of using Git hooks for security scanning and all that shift left stuff going on. And that's actually how I ended up at GitGuardian. So I had never had a role where I was focused on the world of security before I got here. So that's, it's not your typical origin story. I know that nobody has a like traditional path into security, but that's how I ended up here. **2:23 Robert Hurlbut:** Very cool. And so, uh, the topic that we want to discuss here is this new report that GitGuardian has just put out, the State of Secret Sprawl 2026. But before we dive into any of the data, because there are some, some very interesting conclusions and, and things that we can see in this data, I wanted to understand where's the data for a report like this coming from? Like, what's the source? of all these conclusions that you've drawn? **2:53 Dwayne McDaniel:** So the biggest source by far is GitHub Public. There's a feed for this, it's literally in the name of the product, GitHub Public Repos, is api.github.com/events. It's the event feed. There's multiple other API endpoints, but that's the fire hose, that's everything that's happening. So we are one of the companies that looks at every single new event. Specifically, we're looking at commits, and things that were private that got turned public. So, it's public events. And we'd scan it right then and there for a secret. Now, if we find a secret, we immediately, completely automated, sealed off from humans touching it, immediately email that committer right then and there. So, it's important to, you know, use an email you actually can get alerts from, just in general, not just because of us, but we will send you an email and say, hey, we, found this in public. This looks like a secret to us. Probably not a good idea. Here's a link to some resources and here's what our product does. And we do that completely for free. That is our pro bono. We call it the Good Samaritan program. And there's a whole landing page about that we have. But we do that as a public good. We've been doing that since the very beginning, since 2018. We see it as a duty in the security space. It's like, let people know, hey, you did this, you need to be safe. But we also collect data off of that, a lot of telemetry off that. And then that's the vast majority of stuff. But in the last couple of years, we've added internal data. So anonymized data from customers. So you hook up a repo to us, we can tell how many secrets we found in that new repo, or you hook up a package registry to us or a Slack or Jira, some kind of internal source. And we don't share whose customers' data is what, but we have the counts, the metadata counts of what was found where. And this year is the first year we included some research from our security researchers who went and found access, public access into some stuff that shouldn't have been public. And we started doing some scans there as well. So there's a little bit of data from some of the GitLab instances we were able to get into from just pure research. **5:10 Robert Hurlbut:** And then there are some conclusions that we're going to talk about that are in regards to private repos. So are those, is that data coming from like things that you're scanning in the, in the use case you just described about where your tool is scanning some private repos, or is that private repo coming data coming from anywhere else? **5:33 Dwayne McDaniel:** Uh, no, that, that's our customer data. That is customers. connect their VCS to GitGuardian so we can scan there as well. Uh, like right now we have over 600 scanners that we've built, plus we do contextual scanning for, uh, we call them generic scanners, but finding, you know, weird long strings that contextually, if it's not there and that return function doesn't work, then the whole thing breaks. Like, we're pretty sure that's secret versus comment, weird long string that someone just jammed on the keyboard. **6:06 Robert Hurlbut:** So the— **6:07 Dwayne McDaniel:** Mm-hmm. Machine learning underneath the covers, like, smart enough to know that, but that's where that data comes from for private repos is literal private repos people connected up to GitGuardian. Okay. **6:20 Robert Hurlbut:** So if we start getting into the data here, you know, the, the, the first big thing that we see, 29 million hardcoded secrets in public GitHub commits in a single year, 29 million. **6:37 Dwayne McDaniel:** Yeah. **6:37 Robert Hurlbut:** This is one of those problems that's— this is not a 2026 or 2025, this new problem hits the scene. This is something that's been around for 10+ years, and this number is continuing to grow. So what do you attribute this to? **6:54 Dwayne McDaniel:** Oh, we wish we knew exactly. But yeah, you're right. This is the 34% jump year over year as the biggest single jump we've ever witnessed. And we've put out this report for multiple years. This is our 5th report in a row, and it's always backwards looking. So the 2021 report was actually 2020 data, and this is actually 2025 data. And that first report was 11 million hardcoded secrets that we found, and this year was, you know, close to 29 million. And the stats on that work out to, if you look at population growth on GitHub Public, like how many developers are even out there, that only grew by 98% over that same stretch, but secret leakage grew at 152%. So the gut feeling of like, this is just a new developer problem, that's immediately disproven. Like, this isn't just a new developer problem. We think this year, and this is what we actually called the report, The Year Software Changed Forever, We have never seen this much code pushed, like ever. GitHub stats from October, from the Octoverse report they put out every year, I don't remember the exact stats, but they have never seen this many people join in one year. They have never seen this many lines of code. There have never been this many PRs. There's never been this many issues. They're just, we are doing more faster than ever before. Partly that is because of AI. We'll talk about those numbers here in a bit, but that can't be the whole thing. When we first started looking at the report numbers and it went up so much, that was some internal people's gut instinct was like, this is all AI-driven. This is completely AI problem. And the numbers didn't vet that out. The things that were leaking have changed and they've updated just as like you're not deploying old web tech anymore. You're always deploying new web tech. And then type of tech we're deploying is modified and changing a little bit. Things like, Uh, LangChain, things like, um, uh, OpenRouter, um, DeepSeek. You know, we're deploying different things than we were a few years ago, but it's not just that it's new people doing new technology. It is a combination of a lot of things. We don't know exactly why, other than we're just doing more, more, more code, more problems. **9:15 Robert Hurlbut:** Because it's not, like it's a super hard problem to solve once you're aware of it. That's what, that's what constantly gets me about this is it's one thing if it's the design of an authentication system, which is very complicated, can be very complicated. Now, there are certainly frameworks and things that we can plug into, and there's things like OAuth and whatnot that we can use as standards to help make that easier. But authentication is 100 times in my mind, more difficult than storing a secret today. With the cloud providers, everybody's got a vault that you can use to store and kind of one-time learn how to store secrets in the vault, and then it's something that'll last you a lifetime. Like, it just, it doesn't add up to me that this problem has gotten so much worse. Like, do you think it is a simple solution? **10:14 Dwayne McDaniel:** If it was simple, I think we would've maybe moved toward it there, but like, this is authentication. It's terribly done. We married the idea of authentication and authorization together as these standing privilege keys that we issue to things, uh, a person or a non-human identity, um, like a machine identity or a workload, uh, like that. We'd give them freestanding access. Now, the idea of, I'm going to vault this and properly call AWS Vault. Works great per project, works great for your individual use case. Uh, one of the problems that we've witnessed, and I've written a couple of pieces on this over the years, uh, last couple of years, is vault sprawl. The idea that you don't have just one vault, you have many vaults across your organization. And if you acquire another company, guess what? You got their vault sprawl on top of it. So yeah, I know how to use A vault, but now I'm on a new project and I have never seen this particular provider before. Like if somebody threw CyberArk Conjure at you and you're very used to AWS Secret Manager, they're similar technologies. They do the same thing under the covers, but the ins and outs, the minutia of it is enough friction that even, uh, so we didn't report it in this year's report, but last year we, uh, the numbers was 5.1%. Uh, of all repos that had a Vault call somewhere in it also had hardcoded secrets. So it's not just, hey, the Vault's going to save the day. It is the developers need to consistently use a process that makes sure they're using the Vault correctly, because the downside of not getting it exactly right and getting it slightly wrong is your app doesn't work. **12:02 Chris Romeo:** And downtime. **12:05 Dwayne McDaniel:** Is a much bigger evil from a business risk perspective than the possibility that someone might find that key eventually if they ever got their hands on the source code one day, maybe. There's a lot of maybes in there, and if you're doing a giant risk assessment, that's what you're doing. You're balancing off how much money will we lose from the downtime for properly doing this versus it's already running, they hardcoded the secret, they shouldn't have, slap their hand, tell them not to do it next time, but that thing's still running and we do not want to take it down. That's a business-level conversation well beyond what we should be doing with security. **12:37 Robert Hurlbut:** When you think about the dataset here, I'm just curious, like, what percentage of secrets that are, and not exactly, but I'm just kind of looking for a ballpark here. What percentage of secrets that are hardcoded are being used to authenticate that particular process or that particular machine to something else. Is it close to 100%? **13:06 Dwayne McDaniel:** Well, there's really the old joke. There's only 2 things in the whole world, a potato and not a potato. There's only 2 things we're dealing with here. And this is why one of the reasons I do not like the term non-human identity is you're dealing with a human being who is trying to access a thing as a person, Or it is a non-human trying to access something else and it's not a person. So the vast majority is non-human identity connections. That just has to be based on what we know. Um, it's somewhere like 150 to 1, the ratio for every single person logging into your system, you have 150 non-humans making some kind of TLS or mTLS request. And this is happening sometimes milliseconds, and then that workload disappears. And sometimes it's persistent for years and years. That's one of the other data points from the, from the research that bothers me more than anything else in the report is even though we have the Good Samaritan program, even though we make a lot of noise about this problem, there is an ongoing concern of not rotating keys, even if they're known to be leaked. Uh, we did the, we try to validate every key we find. Can't validate everything, but it's like over 400 providers we can validate, make a non-intrusive call, non-intrusive call to that system, say, hey, does this API key actually work? And we took that dataset of keys that we found to be valid in 2022, took a subset of that, about 11,000 keys. And in 20— beginning of 2025, for last year's report, we tried to revalidate those same exact keys, and 70% came back as valid. We said the exact same thing with the exact same dataset at the beginning of 2026, and 64% came back as valid. It's not that we have a problem. It is a remediation and political will to do anything about this problem. **15:08 Robert Hurlbut:** To make the changes. Yeah, that makes sense. Okay. All right. **15:11 Dwayne McDaniel:** That helped. **15:12 Robert Hurlbut:** That's helpful. Just as I'm, I'm, I'm kind of building a mental model. in my head of how these things, how everything connects together. **15:20 Chris Romeo:** Let's make it worse. **15:21 Robert Hurlbut:** Let's talk about AI. So AI coding tools, you know, I know you can share some data from the report about how AI is making it worse. Like, I don't know, let's explore why AI is making it worse. **15:35 Dwayne McDaniel:** Well, there's 3 things around AI. The first is what we're building. is changing. I mentioned that earlier. It's the actual infrastructure and what we're building with. So it's the same mistakes we've always made with a new technology. Hey, we're going to roll out this new technology. Is it accounted for everywhere in the vault? Oh, we're just going to do a quick MCP, not MCP, got MCP on the brain. We're going to do a quick MVP, minimum viable product. And what does business do whenever they see an MVP actually function in a demo? Like, let's ship it, let's get it to production, like, right now. And a lot of shortcuts that developers make with good intention of like, this isn't a production system, this is never gonna see the light of day. I think that's actually part of this, where we think we're gonna make this short-term trade-off, but it's not technical debt, 'cause you pay off debt. This is technical, like, irresponsibility and bankruptcy. This is like, oh, right, we're just gonna do it, and it worked, and we'll fix it later. **16:37 Robert Hurlbut:** Yeah. **16:39 Dwayne McDaniel:** Maybe, but we're seeing that with new technologies the same way we always have. Like I mentioned OpenRouter earlier, Brave Search, like, oh, so OpenRouter, 48x increase in leakage of secrets from the previous year to, from 2024 to 2025. Yeah, part of that is because OpenRouter wasn't popular in 2024 because we were still figuring out how to deal with LLMs at scale. DeepSeek though, we've had that one for a while now and we saw 23x more leaks in 2025 than we did in 2024. But then there's things that popped up for the first time like Mistral and Diffie and some other players out there, Perplexity, which makes more sense that we would see that really pop up in 2025. So That's part of the equation. Other piece is the MCP servers themselves are leaking like crazy out there. And from our research, we found like 24,000 valid keys across GitHub in 2025, which doesn't sound like a lot, and it's a drop in the bucket compared to the millions, but realizing what that has, those give access to generally very broadly, um, that's problematic. But why we think that's happening. **17:56 Robert Hurlbut:** Yeah. **17:57 Dwayne McDaniel:** is template files. If you have a template file for MCP server, it typically tells you to do the worst things in the world for authentication, because you're going to figure that out on your own. You're going to have a, someone at some point, if you're going to put this in production, is going to say, well, this is how we have to handle authentication. And then we just ship it that way. Also, there's all the research right now from people like Ox Security that MCP is just fundamentally broken on the authentication side. And they put way too much onus on the endpoint or on the developer themselves. Like, you're going to secure this, right? Don't worry about like running arbitrary code. And if you do it wrong, like, that's not our problem as Anthropic. That's not our problem with the standard. Anyway, that's a whole different rabbit hole. But the big thing that everybody's mind just jumps to first and foremost is AI assistants, AI assist bots, like the Claude coworker or Claude, yeah, Claude coworker, Claude code, Gemini, Copilot, just name your favorite, Cursor, whatever LLM you're invoking under the hood with any of those. And that's where everyone's mind jumps to is like, is this making it worse? And that's the number that jumps out at most people from the report is across the year, if you co-authored a commit Or let Claude Code co-author your commit, you were 2.4 times as likely to have committed a secret across 2025. Now, on the surface, that sounds like, oh, obviously there's your smoking gun. Claude Code caused all of these secrets, but it's more nuanced than that. If you break it down month by month, in January, there were no commits co-authored by Claude Code. That wasn't a thing. Like technically the annotation system existed, but you wasn't able to just flip it on in Claude code. And then we see it spike up. So by the middle of the year, it's like 31 secrets per, uh, per 1,000 commits. And then it drops off, like in September, it starts dropping off and we can pinpoint it literally to the new model, to the new Opus. **20:07 Robert Hurlbut:** Hmm. **20:08 Dwayne McDaniel:** model rolling out and to improvements in the underlying model. And it keeps falling and it doesn't reach parity by the end of the year. It's still, so for every 1,000 commits, it's like 1.4 or 1.5 commits will contain a secret if a human does it with no sign that Claude Code was involved. Claude Code co-committed or co-authored That's what we're saying is like across the year on average, including that giant spike in the middle of the year, you're 2.4% more likely to commit code that contained a secret. And that there's a deeper level there. And I know I've been talking for a good chunk of time here, but it's important to understand this. This isn't saying the AI itself is forcing you to leak secrets. It's saying if you are the type of developer who lets Claude Code just do its thing and also go ahead and co-author the commit and go ahead and make that Git action happen. Go ahead and push this for me. You're less likely to have taken the time to stop, review what actually happened, try any other preventive tools, any kind of developer tooling to like, hey, did we any— got any— did we push any secrets in here? Did secrets ever get accessed? You're just less likely to be that person. So you're more likely overall to just ship whatever you got. And that unfortunately includes a lot of secrets. **21:31 Robert Hurlbut:** So is Claude— so Claude— so Anthropic's models are getting better is what I heard throughout the year, which gives us hope that they may eventually solve this from a Claude code perspective where it'll stop adding secrets in. But like, is it— is this a training data problem? Is it the fact that Opus has ingested so much Stack Overflow from the last 20 years that it sees hardcoded secrets as an okay principle to apply in some scenarios? Like, what are your thoughts there? **22:10 Dwayne McDaniel:** The guess is yes. It's a black box. We'll never really, really know. But based on MCP specifically, we— that subsection, that's why I brought that up. We know it is directly because of template files, because of the setup instructions for so many of them. If you let AI just do it, just like, hey, go to set this up for me, it will do whatever the instructions generally suggested. And that is, hey, just slap your API key right there. And we know on the surface, that's a terrible idea, but if you're a developer in a hurry and okay, that ran in the background, does the MCP server work? Oh, okay. It functions. Is it safe? That's— I ain't got time to ask that question. I have too many other things going on. **22:54 Robert Hurlbut:** Yeah. **22:55 Dwayne McDaniel:** But no, I think it is getting better. My hope, and I know I'm kind of out there with this, but actually I'm really hopeful for the frontier models. I think we're not that far away from— it will be hard to ship insecure code. We'll still always ship insecure code somewhere. The OWASP Top 10 is going to be the OWASP Top 10 until the end of time. But the things that we're doing, like the low-hanging fruit of why is this so hard for people to get this? Like, we still have never crossed, stopped cross-site scripting. We've still never stopped SQL injection. Like, why? Well, because it's really hard to get it right every single time. But if the assistants start getting better, and that's what I think we're looking at with Mythos, if it can hack that well, think about how much better it should be at contextually fixing things if it has full access and you can jar a million tokens and you're the person who has the source code. You're the person who has all the context to give it and say, make this secure, make sure you can't hack it. Go ahead and try to attack this thing. Try to prompt inject anywhere, SQL inject any way you can. And just fix all of that. I don't see why that would be unreasonable to expect a developer, like, here, I bought you Claude code. Make sure when you check things in, you actually had it attack your own changes and that doesn't affect anything and, or wouldn't, uh, it wouldn't work. Like, I don't see that's a, I don't think that's sci-fi. I think that's maybe 6 to 8 months from now. That timeline's maybe aggressive, but. I think secrets is going to be part of that as well. **24:36 Robert Hurlbut:** Timelines are a funny thing right now because we, we can sit there and go, like, we can't even talk about 5 years in the future from now because things are moving way so fast. And, you know, you got me thinking about like, what does the OWASP Top 10 look like 10 years from now? And I think it does exist. I think that there'll be more opportunity for business logic flaw exploitation. **25:04 Dwayne McDaniel:** Yes. **25:04 Robert Hurlbut:** Than just something like, 'cause you think about it from a design perspective, we've got a well-documented set of mitigations for SQL injection, you know, input validation, um, or use of ORMs. Like we've got things that in new apps should be relatively easy to do. And it seems like those are, are things that we should be able to teach the coding bots to be able to, to replicate those design patterns. or even have the design stage influence those. But I don't think we're— I'm with you. I don't think we're going to reach the point where the OWASP Top 10 gets retired. I think things are just going to be different. It's going to be— we're finally going to fix some of those things, but other more logic-based things, I believe, will become part of the challenge. **25:51 Dwayne McDaniel:** So I think there's a fundamental misconception about the OWASP Top 10 out there that people see it the same way they see NIST or other like PCI And it is not. I was at LastCon last year and like one of the old, like people who wrote, helped write the original back in 2002 reminded us that they like, look, OWASP Top 10 is not prescriptive. It is a dark mirror of what we've gotten wrong. It's literally just saying, here's the problem set, y'all. Here's what you should probably be working on because these are the most common problems we're documenting out in the wild. There'll always be an OWASP top 10 list. What's going to be on it? I would not hazard to guess right now, but I do think we were going to shift more toward the authentication side and more identity-based attacks than we could have dreamed of in the new terrifying ways that I don't really want to talk about because that side of the world scares me a bit. But that's— there's somebody wrote a really good report when Anthropic made their big news with Anthropic security back beginning of the year. It's like all Anthropic did was remind us there's 2 doors. There's zero-day backflip vulnerabilities where I buffer overflowed the thing because I was able to get one more character into the thing and you didn't understand how fonts worked inside of your application, but it took an entire team a month to figure that out. And now that entire team can throw $20,000 of credits at it and get to the same result. And that's great and all if you're North Korea, Lazarus or, you know, China, like a nation state, but guess what? They were already going to do that. **27:26 Robert Hurlbut:** Mm-hmm. **27:27 Dwayne McDaniel:** The other way in, 89% increase in AI-assisted attacks that were malware-free, uh, according to CrowdStrike's last report, uh, across the last year. Yeah, the phishing's only going to get worse. The spear phishing, especially, um, account takeover, like Um, what do you call it? Info stealers. We're only going to see more pervasive. That's all the madness going on right now in the supply chain attacks. Like the goal of supply chain attacks is no longer just taking over that endpoint, just getting malware on the production instance. Like that's not what's going on. The number one target right now for all this malware is the developer on their machine to steal all of the credentials they have on that machine. If they can steal some crypto and keep the thing running, great. Other than that, keep stealing npm tokens, uh, uh, PyPI tokens. And hey, if I have access to this, let's repopulate. Let's go, uh, not repopulate. Let's keep this attack going by propagating through those channels and just keep replicating. Like Shai Halud, uh, started that idea of like, it brought back worms in a major way. Worms never went away, but now we're seeing like the true picks, Trivy, uh, Team PCP. We thought Axios, but that turned out to be North Korea doing a really, really, really complex spear phishing. Um, which was crazy. But, uh, what was the other one we just saw like yesterday? Element, um, Element OSI, uh, what is it? Element's the The larger package. Uh, I say that and I can't remember what the heck it was. Um, hold on. Elementary Data. Yeah. Elementary Data. Uh, that just got popped, like, as of the time of this recording, yesterday or 2 days ago. And that's got a million downloads a month. And the whole point of that is let's go steal your passwords. Let's go steal your access and let's impersonate you to do this terrible thing. So I think we're going to see more and more of that. And unfortunately, that comes down to what we're talking about in our report. Uh, if you have standing access, if you have standing privilege for anything, assume it's going to be abused, assume it's already compromised. If you are, if you have anything plaintext on your machine, including environment variables, I never thought, and I've been saying this a lot lately, I never thought in a million years I'd be saying, yeah, local environment variables are a danger now. It's, it's, it's actual danger. We need to put control points around. If you have environment variables on your machine, you can dump, and that's a work machine and you're doing anything that affects your work life on it, assume they're compromised. Just that's, it sounds reactionary. It sounds way overblown, but that's literally the conclusion we're coming to. Otherwise, how do we stop this madness of the supply chain attacks we're seeing? **30:29 Robert Hurlbut:** It's funny to me that the concept of what's old is new again. One of the biggest incidents I ever worked on the periphery of was back in the late '90s. I was working for a web hosting company, Exodus, and there was a hacker by the name of Fluffy Bunny. And Fluffy Bunny's way into our data center network was through one of the developers' home machines. And, but now you, now what you're describing is something that's a whole lot more complicated because it's malware-driven. This was human being driven, but still the vector was the same to get to the good stuff in the middle. Why go through all the defenses we put in the data center when you can work through the developer's, uh, machine at home that where he had an SSH tunnel running back to the control network and off the attacker went into the fun. **31:27 Dwayne McDaniel:** Yeah, the, the, it, it's not like the attackers are targeting developers for the first time. It's just, they're doing it in a much more efficient, automated way that nobody saw coming even a year ago. Like I've been having this conversation with a bunch of people, like there was this thing called SolarWinds that happened. And it was a big deal and it was one thing called SolarWinds and it was massive and it was, but it was like this huge deal. We're seeing the equivalent of SolarWinds every 2 days at this point. And we don't, we can't even describe it in the same terms because if I say the Kiks breach, then I'm leaving off like 15 other attacks that are related directly. So we're starting to say Team PCP, which is the attack group. And now rating it, the attacks are like, was this likely Team, uh, Team PCP directly, or was this inspired by them? Like, that's the level we're having this conversation at. And I don't like that. I personally don't like it. Sometimes it feels like we're celebrating these terrible criminals, and that's what they are, criminals causing havoc out there. And the only good side of all of this Is maybe we're too close to this insecurity and there are going to be no negative outcomes in this. Like Cisco got breached a few weeks ago and 300 internal repos got made public, like gigs of data. What's the outcome of that? End user, what has happened to them? Sure. My personal data got leaked. **33:05 Robert Hurlbut:** Great. **33:06 Dwayne McDaniel:** It's Tuesday. Like, that's going to happen. That's just, my data is already out there. Like, what are we protecting at this point? Like, what are, what is the goal at this point other than just saying, hey, this is a bad practice. This is scary. Like, that's where I'm kind of at with everything. Like, where, where do we go from here? What do we do to actually protect ourselves? Because there's security in the bigger sense. Like, what's the best possible way you should do this? The best practice of security, no matter what you're doing. Passkeys, multifactor authentication, all of those, great. And then there's corporate security. Then there's like the enterprise security. And that's where I spend so much of my time thinking about, of like, I'm actually am thinking about that end user that if their information gets out there, they're going to be more likely targeted by a much more narrow phishing campaign, uh, spear phishing at that point. Like you can get down to the individual level. And, but at the same time, that's already happening. So I keep coming back to here and I'm, I know that's kind of out of nowhere. I don't have a good solution here, but that's, I think a lot of people out there in the security world are having the same general feeling of like, how do, how do we fix this? How do we actually go and try to fix this? And from the code perspective, I actually see a path with AI. From the individual access perspective, that's where We're struggling because as you said much earlier ago, this should be solvable. This should be at least approachable that like you don't have plaintext passwords anywhere. You don't have plaintext API keys anywhere. All of your API keys expire within, ideally as soon as they're used and you issue new ones and nothing ever holds standing privilege. But these aren't new ideas. This is like SPIFFE. That is what I'm basically describing, a secure production identity framework for everyone. It's been out for 8 years. It's mature from the cloud native's perspective, Cloud Native Computing Foundation's perspective. It's at the same maturity level as Kubernetes itself. Like, they're both graduated, they're both out there, they're both flagships. Why haven't we adopted this? Well, back to political will. **35:14 Robert Hurlbut:** Yeah. **35:15 Dwayne McDaniel:** And if you're on a board and you have to give budget to a team and they say, here's all the scary stuff and here's what we gotta do to like try to make the scary stuff go away. It's like, okay, but the real scary stuff is that we're struggling as a company and we can't take that machine down. And if we do, we're going to lose X amount of dollars per second. And you're saying there's a possibility that someone's data might leak and that might affect us. **35:39 Robert Hurlbut:** Yeah. So if we kind of turn back to a couple more things from the report that I want to make sure we hit on. Uh, one of them was in regards to this, internal repos are 6 times more likely than public ones to contain hardcoded secrets. So what does this tell us about ProdSec, AppSec, internal security functions versus what we're seeing on the public end? **36:09 Dwayne McDaniel:** Yeah. Tip of the iceberg is what we're seeing in public. Um, the likelihood you're going to commit a secret in to a public repo is not small. It's like 5.6% of all repos that are on GitHub in public got updated with a hardcoded secret last year. Uh, but there's a false sense of security that I'm doing this internally. Like, um, it's, it's, it's interesting for the, uh, code perspective. And yeah, it's, it's 6 times more, 38% of all repos when they first hook up to GitGuardian contain a secret of some form. Um, that's troubling, but there's that perception of like, well, this is a private repo, or this was just for the testing environment. And then someone connects the testing environment to production data to run one test. And suddenly the attackers that already knew how to get into that testing environment, see a new data source. That literally happened to AstraZeneca a few years or 2, 2 years ago, 3 years ago. Like, that's exactly what happened. The testing environment was known to be, hey, somebody could probably get in here. Like, we're not really careful. It was testing environment. Then someone hooked up real data. That's a real concern there. The bigger story out of there is the other data sources. When we connect into Jira, Slack, Confluence, those are the 3 we included on this report. There's only a, there's like 29% of all leaks we find for private customers happen in those other sources outside of code. And it's only 4% overlap. of a secret that's found in those sources is also found in code. What we're inferring from that, and what we've had many conversations with customers about this, is the secrets are properly accounted for. There is a good Vaulty system. They, they, they're consistently using it, except for these edge cases where we're finding a bug and we've been working on this thing for hours. Well, we got to go. We got to move on. We got to move this to the next person's hands. What do you do? Well, here's the logs. Did they contain a secret? I didn't even think about that. Or here's the actual key for the thing you actually need, because it's going to save the next person so much time and effort. You're being nice, but you're doing it inside of Jira. And it's like, oh, what's the likelihood that Jira is going to get popped? Go ask Cloudflare. Go ask, like everybody else has had Jira instances get compromised. Um, Uber from a few years ago. Uh, that was one of the first things that that attacker hit. They got in with PAM and it's like, well, all right, Jira, what do we got in here? Slack, what do we got in here? Uh, and then just keep moving laterally. **38:48 Robert Hurlbut:** So we've, we've had a chance to explore a number of different statistics and patterns of the problem, what I would call the problem space. But I think we should spend a few minutes considering like, what is the solution space here? And I know there's been mention of like non-human identity governance. There certainly is secret detection, but like, how do we truly fix this from an organizational perspective? **39:21 Dwayne McDaniel:** Man, that's a really good question from a large-scale organizational perspective. And that goes back to that thing I got on my little side tangent rant there. Do we have the political will? Is this something that we are willing to address and fix? Like, what are, what are the controls telling us? Like, the controls broke down. Are we going to get fined from this? Like, I think that might be the, the right answer for certain size companies and for certain comp— certain organizations, for certain verticals. But the big answer is, do you care enough to fix this? From a technological perspective, you said it really well at the beginning of the show. Yeah, this isn't that hard to fix. Uh, just getting a vault in place fixes a lot of this. Moving away from, uh, standing privilege fixes an entire class of problem, but how do we get people to embrace that? You mentioned NNTRI governance. I actually wrote a blog article a couple months ago. Uh, at this point called, uh, NHI governance is the outcome because it's a categorical, categorical, uh, categorical misunderstanding that's happened, I think. And it's kind of, we did the exact same thing with DevOps. So this isn't unique to just security, uh, where people are saying, I am selling an NHI governance tool, which means I am buying NHI governance. It's like, I am buying a DevOps tool. Therefore I have DevOps now. **40:51 Robert Hurlbut:** Yeah. **40:53 Dwayne McDaniel:** No, you have some tools you bought that can explain the state of things and help with communication, feedback loops, and iteration. That's what you bought. Like, what's your governance plan? That's what I ask everyone. They bring up governance, like, yeah, what's your governance plan? And they look at me like, no, I'm trying to buy one. I'm like, well, that's not how governance works. Like, governance is the end result of putting processes in place and knowing if you are within or without the state, the good state you've described. So that's like what our NHAI governance product does. We can tell you the state of your secrets and how it connects to all of the non-human identities. Like what entity is consuming it? Where is this going? When was it issued? Who owns it? All of that stuff. But that doesn't fix the problem. That tells you what to fix. I think if you have standing privilege for any entity, that's bad, but that's not a new concept. That's zero trust architecture. That's literally verify, verify, verify, then trust for just long enough to get the work done and then forget they ever verified them and treat 'em like strangers when they come back. And I, we need to move architectures that do that. It's technically very achievable. One of the biggest advancements that's happened in 2025, it flew under the radar for a lot of people, 'cause I talk about this from stage when I'm giving talks, like this is an exciting piece for me, or exciting times for me. AWS has a service they have for years called Security Token Service. So you can simply call the service and it can issue you a token to say, this is my identity. I guarantee you anybody that sees this, this is the identity you're supposed to have. And that identity then gets assigned roles. And so it can move to another service in AWS and say, I'm me, let me in, let me do my thing across this trust boundary. And if you're on AWS, it's like, yeah, I can verify this. End of last year, they federated that. So the, the STS itself contains a phone home, contains a private or a public key. So anybody that gets it, like literally anything that gets it, Azure, Google Cloud, Databricks, those are the first 3 that they talked about in the article from August. Uh, but it's since expanded greatly. So anybody that can basically do, um, OpenID Connect, if you can do that verification step, Then you can say, all right, here's something that's coming in. And through configuration, we know it should have this role, but you don't issue a key. You're issuing identity. And it can take that identity and say, here, here I am at the gate. Like, let me, let me in and let me do my thing. Let me call, let me call the issuer. Let me say this key checks out. Okay. Everybody's cool. We trust you now. What did you want to do again? And only then, if it all checks out, do you issue the actual token for the work. And it only exists for the time you've agreed upon. I think 5 minutes is plenty, um, because we're talking workloads at this point. You might need to refresh, you might need to make it longer. I don't know. I don't know you and your, your things, but this is technically possible. And the price point on it is free, not from a technical, like overhead perspective, but from a price point perspective on AWS. This is such a good idea. They're like, yeah, this is available for everything we make. And it's no cost. Why haven't we done this yet? Why haven't everyone ripped out all of their API keys and said, we're moving to this, like right now? Well, there's actually a few reasons for that. The biggest is political will. You have to account for that in code. And it used to be, that was an impossible mountain, like a million lines of code and you're going to do what? And how much of that revenue is this going to bring in? But now we got Mythos coming up. Now we have agents that can like go rewrite all these calls and all we got to do is test it in a test environment. Like, yeah, it all works. Let's roll that to production now. And then we get rid of all our keys. That's a future we can embrace if we're politically brave enough to do it. Uh, we get better results. Developers don't have to worry about longstanding keys. **44:51 Robert Hurlbut:** They're— **44:51 Dwayne McDaniel:** an entire slew of problems go away because I know if I see a codebase that has an API key, I personally, and I'm not a criminal, but I am personally tempted to see what I can get into from a research perspective. Like, where does this go? What do I get into? If I see an STS call or a SPIFFE ID, I get excited. I'm like, yes, they're tackling this head on. **45:11 Chris Romeo:** Dwayne, thank you so much for joining me today on the Application Security Podcast. The State of Secret Sprawl 2026 report is packed with data, and you did a great job breaking it all down. Folks, go check it out over at GitGuardian. The link will be in the show notes. Thank you. --- Source: https://appsecpodcast.com/dwayne-mcdaniel-secrets-sprawl-and-how-ai-is-impacting-secrets/