Skip to content
Artwork for The Application Security Podcast
The Application Security Podcast · May 14 · 45 min

Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets

GitGuardian found 29 million hard-coded secrets in public GitHub commits in one year—a 34% increase and its largest jump yet. Why is a supposedly simple problem getting worse? Principal Developer Advocate Dwayne McDaniel explains what the 2026 State of Secrets Sprawl report reveals about public and private repositories, AI coding tools, MCP server templates, and developer-targeted supply-chain attacks. He and Chris unpack why standing credentials persist, how private repositories create false confidence, and why frontier models may improve without solving the organizational problem. The conversation moves from detection to governance: short-lived identity, ownership, feedback loops, and the political will to remove embedded keys. Dwayne's core challenge is blunt—organizations already have better authentication patterns, so what will make them finally use them? Connect with Dwayne McDaniel: → Dwayne McDaniel on LinkedIn → State of Secrets Sprawl 2026 Mentioned in this episode: → GitGuardian State of Secrets Sprawl Report 2026 → LangChain → OpenRouter → DeepSeek → Mistral AI → Perplexity → Ox Security → SPIFFE → CNCF → AWS STS → OpenID Connect → GitHub Octoverse → Claude Code Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Meet Dwayne McDaniel 00:39 Dwayne's path into secrets security 02:23 How GitGuardian builds the report 05:10 Where the private-repository data comes from 06:20 Twenty-nine million leaked secrets 09:15 Why the problem persists 12:37 Secrets, identity, and standing privilege 15:21 Three ways AI makes leakage worse 16:39 Explosive growth in AI-service credentials 17:57 MCP templates teach insecure authentication 20:08 Is Claude Code getting safer? 22:55 Hope for frontier models 24:36 What will the OWASP Top 10 become? 27:27 AI-assisted attacks target developers 30:29 Old supply-chain attacks at machine speed 33:06 What are organizations protecting now? 35:39 Private repositories are six times riskier 38:48 Moving from the problem to solutions 39:21 Does the organization have the will to fix it? 40:53 Governance and short-lived credentials 44:51 Closing thoughts Follow the Application Security Podcast: ➜ Home: appsecpodcast.com ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast

0:00-45:27

transcript

No transcript — this publisher did not publish one.

show notes

GitGuardian found 29 million hard-coded secrets in public GitHub commits in one year—a 34% increase and its largest jump yet. Why is a supposedly simple problem getting worse? Principal Developer Advocate Dwayne McDaniel explains what the 2026 State of Secrets Sprawl report reveals about public and private repositories, AI coding tools, MCP server templates, and developer-targeted supply-chain attacks. He and Chris unpack why standing credentials persist, how private repositories create false confidence, and why frontier models may improve without solving the organizational problem. The conversation moves from detection to governance: short-lived identity, ownership, feedback loops, and the political will to remove embedded keys. Dwayne's core challenge is blunt—organizations already have better authentication patterns, so what will make them finally use them?

Connect with Dwayne McDaniel:
Dwayne McDaniel on LinkedIn
State of Secrets Sprawl 2026

Mentioned in this episode:
GitGuardian State of Secrets Sprawl Report 2026
LangChain
OpenRouter
DeepSeek
Mistral AI
Perplexity
Ox Security
SPIFFE
CNCF
AWS STS
OpenID Connect
GitHub Octoverse
Claude Code

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Dwayne McDaniel
00:39 Dwayne's path into secrets security
02:23 How GitGuardian builds the report
05:10 Where the private-repository data comes from
06:20 Twenty-nine million leaked secrets
09:15 Why the problem persists
12:37 Secrets, identity, and standing privilege
15:21 Three ways AI makes leakage worse
16:39 Explosive growth in AI-service credentials
17:57 MCP templates teach insecure authentication
20:08 Is Claude Code getting safer?
22:55 Hope for frontier models
24:36 What will the OWASP Top 10 become?
27:27 AI-assisted attacks target developers
30:29 Old supply-chain attacks at machine speed
33:06 What are organizations protecting now?
35:39 Private repositories are six times riskier
38:48 Moving from the problem to solutions
39:21 Does the organization have the will to fix it?
40:53 Governance and short-lived credentials
44:51 Closing thoughts

Follow the Application Security Podcast:

➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast

links20