New open-source tool puts the spotlight on developer laptops

BoostSecurity Labs has released Bagel, an open-source tool for assessing security risk on developer workstations. The premise is that organisations invest heavily in securing the build chain, while a compromised laptop can expose credentials of far higher value: GitHub tokens, SSH keys and cloud access secrets. Such credentials can give attackers access to source code, cloud infrastructure or package registries, opening the door to large-scale compromise. The tool helps organisations identify risky configurations and exposed secrets on those machines.

What this means for your organisation

Controls in the build chain count for little if an attacker can lift a valid key off a laptop and act as a trusted developer. For organisations that build software themselves, or buy from suppliers who do, this is a concrete question to raise in supplier follow-up. It is also one of the few areas where a simple inventory gives you an answer immediately.

Berigo recommends

  • Run a sweep for secrets stored in clear text on developer machines and prioritise those granting access to production.
  • Replace long-lived tokens with short-lived credentials tied to identity rather than to a machine.
  • Raise developer workstation security in your supplier assessments of anyone building software for you.
  • Make sure credentials can be revoked quickly, and rehearse doing so at least once a year.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch