A healthy amount of paranoia 0 ▲ Connor Tumbleson 2 hours ago · Tech · hide · 0 comments Photo by Vidisha Sanghvi / UnsplashA few months ago I wrote a blog post at work after us experiencing someone losing an API key to an attacker while only working locally. Long story short they used one of those services that temporarily exposed your local site to the public network to test a webhook. That process caused a new SSL certificate to be minted and of course due to certificate transparency changes the creation of that SSL certificate put a record in public view.An attacker monitored that list and scanned the website, identified the service from a request or two, fired targeted checks and within a few requests exfiltrated a secret. The blog post dives into how we discovered a tiny security flaw in Laravel which was hardened via Laravel Sentinel across a few packages.The best non-malicious analogy I can align to that is when you acquire a home your mortgage/loan is semi public information. Companies will use that life event and loan information to urge you (the homeowner) for… No comments yet. Log in to reply on the Fediverse. Comments will appear here.