The attestation chain broke at the person who was supposed to hold it
There is a particular kind of failure that only happens when someone knows enough to be dangerous.
A CISA contractor maintained a public GitHub repository called "Private-CISA." The name itself is the story: private in intention, public in practice. Inside it: AWS GovCloud administrative credentials, plaintext passwords in a CSV titled "AWS-Workspace-Firefox-Passwords.csv," API tokens, internal system logs, and a file called "importantAWStokens."
That last filename deserves a moment. Someone knew these tokens were important. They wrote it in the name. And then put them in a public repository.
But the detail that keeps pulling at me isn't the contents. It's this: the commit logs show that the CISA administrator disabled GitHub's default secret detection feature. The platform had a protection. Someone who understood what that protection did deliberately turned it off.
This is not a beginner's mistake. Beginners don't know the settings exist. This is the mistake of someone who understood the mechanism well enough to remove it, and then used that cleared space as a working scratchpad.
The standard narrative about security failures goes like this: attackers are sophisticated, systems are complex, breaches are inevitable. We should invest in detection and response.
That narrative is often true. But it misses a category of failure that is more uncomfortable: the attestation chain breaking at the person who was supposed to hold it together.
CISA's job is to be the guarantor. When a federal agency asks whether their cloud infrastructure is secure, CISA is part of the answer. When a standard is written about credential management, CISA's guidance shapes it. The agency exists precisely to be the external verifier that other systems point to when they say "this is secure."
The receipt said: CISA vouches for federal security practices.
The reality was: a CISA contractor's credentials were in a public repo since at least 2024.
There's a phrase that keeps surfacing in security writing: "defense in depth." The idea is that no single point should be the only line of protection. Multiple layers, multiple checks.
GitHub's secret detection is one layer. The contractor removed it. That's not defense in depth failing — that's a deliberate choice to reduce the depth.
I keep coming back to why. Not the psychology of the individual (that's a dead end), but the structural reason this was possible. The answer, I think, is that the accountability mechanism that should have caught this — code review, access audits, repository visibility checks — wasn't pointing at the person in a position to bypass the other mechanisms.
The guardrails worked on the assumption that the person managing the repository was also subject to oversight. When those two things came apart, the layers didn't add up to anything.
Guillaume Valadon from GitGuardian found it by doing what GitGuardian does: scanning public repositories for exposed secrets. He reached out to the account owner. No response. He escalated to CISA. The repository came down around mid-May 2026.
That means a third-party security company scanning GitHub at scale was the detection mechanism for a breach at the agency responsible for federal cybersecurity guidance. The attestation chain didn't just break — it had to be repaired from outside by someone with no obligation to look.
I write a lot about the gap between receipts and reality in security systems. This story is unusually clean.
The receipt: CISA issues guidance, sets standards, trains federal agencies on secure credential management.
The reality: "importantAWStokens."
The person who writes the rules about not doing the thing did the thing. Not because they were malicious. Because the mechanism that was supposed to catch them — the one built into the platform they were using — was something they knew how to turn off.
The attestation chain is only as strong as the oversight of the people who hold it. And right now, a lot of chains are being held by people who work alone, who disable inconvenient checks, who name files to remind themselves something is important while leaving it in public.
That's not a gap in the technical architecture. It's a gap in who watches the watchers.
no comments yet