I’ve never met anyone as obsessed with uncovering secret leaks as @theriley106. He’s been doing it for fun in his spare time, rose to the top 2% globally on HackerOne, and now launched @bitpatrol_io to give his superpowers to every company.
@curious_vii Founder here 👋 Appreciate the question! GitGuardian and tools like it are solid at detecting keys with known patterns and shapes (AWS keys, GH tokens, etc) when they show up in clean, predictable ways in code.
BitPatrol catches those too, but really shines with what those tools call “generic secrets” -- internal API keys, DB creds, obfuscated tokens, etc. We detect secrets that regex-based tools miss by understanding code context.
Prior to starting BitPatrol, I submitted dozens of secret leaks on HackerOne. Many of these companies were actively using our competitor's secret scanning tools.
@victordevguy @ycombinator@bitpatrol_io hey @victordevguy 👋 yep, it's just me! i think YC prefers companies with multiple cofounders, but i know of a few others as well that are also solo!
@IceSolst Founder here 👋 For context -- before starting BitPatrol, I submitted dozens of secret leaks on HackerOne. I’d estimate ~30% of the leaks I found wouldn’t pass the default entropy thresholds used by many entropy-based scanners. This is especially true for things like passwords, which often don’t have high entropy.
Our model analyzes not just the contents of a secret, but also the context around it. When something is flagged, we cross-reference it against a dataset built from billions of public commits, open-source packages, Docker images, and more to see how often that exact string has been exposed (which helps us drastically reduce false positives).
Entropy is a great starting point, and I have huge respect for the folks who built those tools!
@Visaals@Visaals Was looking for a post about this! Such an awesome tool that you’ve built here, man!! Can’t wait to upgrade once it’s switched over to live mode! 🧘
Rocking that 4242 pro badge for now 😎
Vibe coding is flooding GitHub with leaked secrets.
BitPatrol (@bitpatrol_io) catches secrets that traditional scanners miss—preventing costly security incidents without slowing down development.
Congrats on the launch, @theriley106!
https://t.co/Yjv13qHS8m
@abacaj@abacaj Can you share the part list of your multi-3090 rig? I’m trying to build something similar with 4x 3090s, a 3955WX Threadripper and a Gigabyte MC62-G40. Super inspired by the work you’re doing here 🙏🏻
@OasisLabs@OasisLabs I know this is an old tweet, but I was curious if OasisLabs vulnerabilities fall within the scope of the OasisProtocol bug bounty? I found a 10.0 CVSS/Critical vulnerability and wasn't sure of the correct avenue for reporting it
cc @dawnsongtweets
Applying to @ycombinator for Summer 2022? Our team of YC application reviewers is ready to help and give feedback. Get in touch before March 14 at https://t.co/56GnKnxfvp.
Stripe is partnering with Apple to enable Tap to Pay on iPhone: https://t.co/THtuND9EvQ.
(You can sign up to be notified when it's available over at https://t.co/DCFWV1KwAW.)