BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsidesluxembourg-2025//speaker//GXXGJL
BEGIN:VTIMEZONE
TZID:Europe/Paris
BEGIN:DAYLIGHT
DTSTART:20240619T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20241027T030000
RDATE:20251026T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20250330T030000
RDATE:20260329T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Fresh Secrets From The Docks: Lessons Learnt from Analyzing 15\,00
 0\,000 Public DockerHub Images - Guillaume Valadon
DTSTART;TZID=Europe/Paris:20250619T133000
DTEND;TZID=Europe/Paris:20250619T141500
DTSTAMP:20260907T124303Z
UID:pretalx-bsidesluxembourg-2025-8A7FZZ@pretalx.com
DESCRIPTION:Hardcoded secrets remain a common practice in containerized en
 vironments\, often used for convenience during testing or deployment\, des
 pite their significant\, well-known security risks. \n\nDocker images are 
 not immune and can inadvertently leak secrets through Dockerfiles\, config
 uration files\, or image layers. Once pushed to registries such as DockerH
 ub\, these secrets become discoverable to attackers\, putting environments
  at risk.\n\nIn this session\, we will share insights from an extensive an
 alysis of 15\,000\,000 public Docker images retrieved from DockerHub\, unc
 overing a staggering number of secrets from. More than 100\,000 of these s
 ecrets were valid when the study was conducted in late 2024\, including AW
 S keys\, GCP keys\, OpenAI tokens\, and GitHub tokens belonging to Fortune
  500 companies.\n\nFinally\, we will discuss common misuses and pitfalls i
 n Dockerfile files that lead to secrets being leaked\, and describe best p
 ractices for handling secrets in Docker images.
LOCATION:Main Stage
URL:https://pretalx.com/bsidesluxembourg-2025/talk/8A7FZZ/
END:VEVENT
END:VCALENDAR
