2026-09-26 –, Off-Main Track
When a secret is leaked most people look at who leaked the secret; the GitHub committers email, package author, but this sucks. Millions of commits are created by noreply emails, clankers and personal emails with no attribution back to your org at all.
We analysed hundreds of thousands of live, verified credentials with a new method of attribution, API calls to dynamically fetch ownership information. What we found will change the way you think about secret detection and remediation.
Using this methodology we were able to achieve attribution at scale, uncovering contextless keys that had access to medical devices, defense equipment and some of the most popular software packages ever (GnuTLS, OpenConnect), KYC databases and much more.
This session discusses:
Why attribution in its current form is broken
The challenges of attribution at scale
What our methodology looks like
Case studies of our findings
Luke Marshall is a Security Researcher at Truffle Security specialising in the discovery of exposed secrets and supply chain vulnerabilities. Formerly a Security Engineer at Bugcrowd, Luke focuses on research in massive public ecosystems to uncover novel attack vectors. He is a dedicated proponent of responsible disclosure and digging into large datasets to uncover hidden security gaps and systemic risks that often go unnoticed.