{"id":5449,"date":"2021-03-16T08:26:48","date_gmt":"2021-03-16T08:26:48","guid":{"rendered":"https:\/\/www.intelligentcio.com\/north-america\/?p=5449"},"modified":"2021-03-17T08:19:42","modified_gmt":"2021-03-17T08:19:42","slug":"talend-secures-its-source-code-with-automated-secrets-detection-from-gitguardian","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/north-america\/2021\/03\/16\/talend-secures-its-source-code-with-automated-secrets-detection-from-gitguardian\/","title":{"rendered":"Talend secures its source code with automated secrets detection from GitGuardian"},"content":{"rendered":"\n<p><strong><em>Talend\u2019s deployment of GitGuardian Public Monitoring is protecting Talend from secrets exposure both on its company repositories and on its developers\u2019 personal repositories.<\/em><\/strong><\/p>\n\n\n\n<p>\u201cHuman error exists, but the key is to be alerted and be able to take appropriate action when a leak is found,\u201d said Anne Hardy, Talend CISO.<\/p>\n\n\n\n<p>Talend is a global leader in data integration and data integrity solutions and a pioneer in the open-source world. Talend was the first company to market open-source data integration software. As a result of this \u2018open-source DNA\u2019, Talend uses GitHub.com extensively to collaborate and share code with the community.<\/p>\n\n\n\n<p>When Talend CISO, Anne Hardy, joined the company in 2020, she quickly identified that there was an issue relating to infrastructure credentials and other secrets leaking through GitHub.<\/p>\n\n\n\n<p>\u201cWhen I arrived, I heard about quite a few issues with GitHub, including leaks of private information, keys, passwords that could be unintentionally stored and publicly exposed on GitHub by our developers or some of our professional services. We absolutely had to deal with the problem quickly,\u201d said Hardy.<\/p>\n\n\n\n<p>Talend had already tried to remedy this problem by developing an in-house tool. This complex project quickly exposed the limitations of building effective in-house detection solutions. The solution not only had some flaws but also proved to be both challenging and expensive to maintain. Additionally (and crucially), it couldn\u2019t identify and monitor developers\u2019 public personal repositories.<\/p>\n\n\n\n<p>\u201cThis is a recurring limitation but also a recurring blind spot most companies do not bear in mind. We often hear \u2018I am not open sourcing so why should I care about public GitHub?\u2019, the issue is that secrets sprawling occurs most of the time on developers\u2019 personal repositories,\u201d said Henri Hubert, Head of GitGuardian Secrets Team.<\/p>\n\n\n\n<p>It was at this point that Talend decided to look for a ready-made solution available on the market. The desired solution needed to allow for active monitoring of all its GitHub code repositories as well as the public personal code repositories of its developers.<\/p>\n\n\n\n<p>Hardy said: \u201cWe started by looking at open-source solutions but they did not meet our expectations. In particular, it was necessary to declare all the directories to be monitored, which represented a substantial workload.\u201d<\/p>\n\n\n\n<p>Indeed, it is tricky to identify personal repositories belonging to developers, especially when dealing with large teams. Automating this process was the only feasible way forward.<\/p>\n\n\n\n<p>Hardy added: \u201cThen we discovered the GitGuardian solution and analysts confirmed that it was a solid solution and suited our needs.<\/p>\n\n\n\n<p>\u201cOnce we decided to deploy GitGuardian\u2019s GitHub public monitoring solution, the ramp-up was rapid. As soon as we had access to the platform, we were able to start remediating past incidents.\u201d<\/p>\n\n\n\n<p>In parallel with the deployment of the solution, a procedure was put in place to treat this type of leak, and all 400 developers were trained on secrets management.<\/p>\n\n\n\n<p>Hardy said: \u201cWhat I have found to be very effective with GitGuardian is that we can analyze the history of Talend-related alerts on the entire GitHub perimeter, whether they are our official public directories or any public directory outside the control of Talend.<\/p>\n\n\n\n<p>\u201cWe launched this audit and several leaked secrets were brought to our attention. What was very interesting and what we didn\u2019t anticipate was that most of the alerts came from the personal code repositories of our developers.\u201d<\/p>\n\n\n\n<p>Hubert said: \u201cThis is what our constant monitoring of every single commit pushed to public GitHub unveils: 85% of the leaks occur on developers\u2019 personal repositories. Secrets present in all these repositories can be either personal or corporate and this is where the risk lies for organizations as some of their corporate secrets are exposed publicly through their current or former developer\u2019s personal repositories.\u201d<\/p>\n\n\n\n<p>Talend\u2019s first priority after taking ownership of the solution was to go through the list of historical incidents and enact the new procedure. This allowed them to start on a sound basis and rely on GitGuardian\u2019s real-time alerting going forward.<\/p>\n\n\n\n<p>Hardy said: \u201cIt took us three months to clean everything up and solve problems especially with employees who had left the company.\u201d<\/p>\n\n\n\n<p>Today, GitGuardian continuously monitors all commits within Talend\u2019s perimeter, whether on Talend-owned repositories or developers\u2019 personal repos. Credentials are detected a couple of seconds after they become publicly-visible and then listed on the dashboard along with information that will facilitate remediation.<\/p>\n\n\n\n<p>\u201cThis real-time alerting is a key element for companies security, as we know that an exposed secret can be identified and used by hackers very quickly. Most of open-source secrets detection solutions do not offer this real time alerting capacity,\u201d said Hubert.<\/p>\n\n\n\n<p>Talend has deployed GitGuardian for the Infosec team. They will also extend it to their team of security champions, developers who will act as an extension to the Infosec team and encourage best practices.<\/p>\n\n\n\n<p>\u201cAt GitGuardian we believe that putting \u2018developers in the loop\u2019 is key to address code security as developers own the code, they have the knowledge and are central in the remediation process,\u201d said Hubert.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Talend\u2019s deployment of GitGuardian Public Monitoring is protecting Talend from secrets exposure both on its company repositories and on its developers\u2019 personal repositories. \u201cHuman error exists, but the key is to be alerted and be able to take appropriate action when a leak is found,\u201d said Anne Hardy, Talend CISO. Talend is a global leader [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":5450,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[9,510,34,39,514],"tags":[1710,1708,1711,1709,1707,1263],"class_list":["post-5449","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-case-studies","category-case-study-newsletter","category-more-news","category-software","category-used","tag-anne-hardy","tag-gitguardian","tag-henri-hubert","tag-public-monitoring","tag-secrets","tag-talend"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/5449","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/comments?post=5449"}],"version-history":[{"count":8,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/5449\/revisions"}],"predecessor-version":[{"id":5485,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/5449\/revisions\/5485"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media\/5450"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media?parent=5449"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/categories?post=5449"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/tags?post=5449"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}