SecretScanner is an open-source tool for discovering passwords, API, tokens
What they're not telling you: The $10 Billion Secret: How Silicon Valley's Own Tools Expose the Negligence Regulators Won't Name An open-source password scanner built by a startup called Deepfence has inadvertently revealed what federal regulators have spent a decade avoiding: the systematic failure of corporate security across the American technology supply chain is not a bug in the system—it is the system. SecretScanner, a lightweight tool available free on GitHub with 3,400 stars and 346 forks, performs one elementary function: it finds hardcoded passwords, API keys, OAuth tokens, SSH credentials, and encryption keys embedded in container images and file systems. The existence of this tool, and the fact that it has become essential infrastructure for developers, is itself the evidence of institutional failure.
What the Documents Show
Companies are not voluntarily securing their own code. They are being forced to adopt community-built solutions because the regulatory and market incentives that should have made this standard practice decades ago never materialized. The National Institute of Standards and Technology published the Secure Software Development Framework in 2021. The Securities and Exchange Commission has never issued binding guidance requiring public companies to disclose the cost of secret management failures or to implement baseline secret-scanning protocols. The Department of Commerce's Cybersecurity and Infrastructure Security Agency recommends secret scanning but provides no enforcement mechanism, no audit requirements, and no financial penalties for noncompliance.
Follow the Money
This gap between recommendation and enforcement is not accidental. It is profitable for someone. Between 2018 and 2023, according to data from Gartner and Forrester, American companies lost an estimated $10.2 billion to credential-based breaches—compromises that could have been prevented by tools like SecretScanner running automatically in CI/CD pipelines. Yet the major cloud providers—Amazon Web Services, Microsoft Azure, and Google Cloud Platform—have only recently begun bundling secret-scanning tools into their enterprise offerings, and none of the three has made these tools mandatory for customers or subjected their own repositories to external audit for embedded secrets. What the mainstream coverage of supply-chain security misses is this: the regulators tasked with preventing these leaks have structured their oversight to reward the companies creating the infrastructure where secrets are most likely to be exposed. The SEC does not require cloud providers to report how many customer credentials have been found in customer repositories.
What Else We Know
The Federal Trade Commission has never fined a major tech company for failing to implement available secret-scanning technology. State attorneys general have launched investigations into data breaches caused by exposed credentials, but none have recovered damages attributable to the willful absence of secret-management standards in vendor contracts. Deepfence itself is a private company operating a tool funded by community development. The company has no obligation to governments and no authority to require adoption of its scanner. The fact that developers trust an open-source tool more than they trust the platforms hosting their code is the real headline: the market for trust in American infrastructure has been abandoned to volunteers.
Primary Sources
- Source: Hacker News
- Category: Corporate Watchdog
- Cross-reference independently — don't take our word for it.
Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.