UPDATED 23:02 EDT / JULY 27 2020

SECURITY

Source code from 50+ companies, including Nintendo, Microsoft and Adobe, published online

Source code from dozens of companies has been published online after a developer found the code exposed on public repositories.

More than 50 companies have had their source code published. They include Microsoft Corp., Adobe Systems Inc., Lenovo Group Ltd., Advanced Microsoft Devices Inc., Qualcomm Inc., Mediatek Inc., GE Appliances, Nintendo Co. Ltd. and the Walt Disney Co.

The developer, Tillie Kottmann, told Bleeping Computer today that it pulled the source code because of insecure DevOps applications that leave proprietary company information exposed. While noting that in releasing the code it does its best to prevent any major issues resulting directly from the releases, the developer admitted that affected companies are not always contacted before the code is released.

The published code from Nintendo is gaining much of the attention online because it gives an inside look at the source code behind a range of classic games including Mario, Mario Kart, Zelda, F-Zero and Pokemon series. The Nintendo code also includes pre-release art, fully playable prototypes of some games and even references to projects that were never completed.

“DevOps, DevSecOps and Configuration as Code, to name but a few buzzwords, all have a common element – they store source and potentially configuration information in code repositories,” Tim Mackey, principal security strategist at the Synopsys Cybersecurity Research Center, told SiliconANGLE. “The underlying technology used in many repositories was designed to facilitate collaboration within distributed teams, such as those common within open-source communities.”

Use of code repositories needs to be properly managed in order to avoid leaking critical information Mackey explained. “For example, an employee developing a set of QA tests will likely place their code in a repository,” he said. “If that code was intended as a prototype, they might not take precautions to properly manage secrets like passwords or access tokens. If the employee’s identity and employer is known, say via LinkedIn, and can be mapped to a repository, say GitHub, then a targeted attack could be mounted which looks for errors in judgement should the employee take short cuts when posting their prototype code.”

There’s some concern that the leaked code be used for nefarious purposes, such as a security specialist telling Tom’s Guide that “losing control of the source code on the internet is like handing the blueprints of a bank to robbers.” But other experts disagree.

“From a technical standpoint, these leaks are not that dramatic,” said Ilia Kolochenko, founder and chief executive officer of web security company ImmuniWeb. “Most of the source code is worthless unless you have other pieces of technology and, importantly, people to make complicated systems work properly. Moreover, the source code rapidly depreciates without daily support and improvement. Thus, unscrupulous competitors will unlikely to get much value unless they are seeking a very specific piece of software.”

Image: Pikist

A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.