GitGuardian
Read post

The Perimeter Moved to the Laptop and Developer Endpoint

The security perimeter has shifted from the network to identity, and now to the developer endpoint itself. Developer laptops accumulate long-lived credentials — cloud access keys, API tokens, SSH keys, .npmrc tokens, and secrets cached by AI coding agents — in config files and shell history. No existing security layer (network controls, IAM, PAM, EDR, or repo secret scanning) is responsible for inventorying these at-rest credentials. Real-world attacks like the s1ngularity npm supply chain attack and the Shai-Hulud worm demonstrate that attackers exploit this gap by scanning developer machines for valid credentials rather than breaking through the perimeter. The argument is that endpoint credential discovery — finding and revoking exposed secrets before attackers use them — is the missing control that bridges identity security and endpoint protection.

    #security#secrets-management#gitguardian
Jul 16•11m read time•From blog.gitguardian.com
Post cover image
Table of contents
The perimeter keeps movingWhy credentials pile up on the developer endpointThe gap: what network and identity controls don't seeThe future of the perimeterSummary: the perimeter is wherever a valid credential sitsFAQs
226 Impressions
GitGuardian's image
GitGuardian

GitGuardian Blog provides insights, tutorials, and updates on secrets management, code security, and...

96 Followers

•

969 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard