Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets episode artwork

EPISODE · May 14, 2026 · 45 MIN

Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

GitGuardian found 29 million hard-coded secrets in public GitHub commits in one year—a 34% increase and its largest jump yet. Why is a supposedly simple problem getting worse? Principal Developer Advocate Dwayne McDaniel explains what the 2026 State of Secrets Sprawl report reveals about public and private repositories, AI coding tools, MCP server templates, and developer-targeted supply-chain attacks. He and Chris unpack why standing credentials persist, how private repositories create false confidence, and why frontier models may improve without solving the organizational problem. The conversation moves from detection to governance: short-lived identity, ownership, feedback loops, and the political will to remove embedded keys. Dwayne's core challenge is blunt—organizations already have better authentication patterns, so what will make them finally use them?Connect with Dwayne McDaniel:→ Dwayne McDaniel on LinkedIn→ State of Secrets Sprawl 2026Mentioned in this episode:→ GitGuardian State of Secrets Sprawl Report 2026→ LangChain→ OpenRouter→ DeepSeek→ Mistral AI→ Perplexity→ Ox Security→ SPIFFE→ CNCF→ AWS STS→ OpenID Connect→ GitHub Octoverse→ Claude CodeFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Dwayne McDaniel00:39 Dwayne's path into secrets security02:23 How GitGuardian builds the report05:10 Where the private-repository data comes from06:20 Twenty-nine million leaked secrets09:15 Why the problem persists12:37 Secrets, identity, and standing privilege15:21 Three ways AI makes leakage worse16:39 Explosive growth in AI-service credentials17:57 MCP templates teach insecure authentication20:08 Is Claude Code getting safer?22:55 Hope for frontier models24:36 What will the OWASP Top 10 become?27:27 AI-assisted attacks target developers30:29 Old supply-chain attacks at machine speed33:06 What are organizations protecting now?35:39 Private repositories are six times riskier38:48 Moving from the problem to solutions39:21 Does the organization have the will to fix it?40:53 Governance and short-lived credentials44:51 Closing thoughts

Episode metadata supplied by the publisher feed · Published May 14, 2026

Embed this episode

GitGuardian found 29 million hard-coded secrets in public GitHub commits in one year—a 34% increase and its largest jump yet. Why is a supposedly simple problem getting worse? Principal Developer Advocate Dwayne McDaniel explains what the 2026 State of Secrets Sprawl report reveals about public and private repositories, AI coding tools, MCP server templates, and developer-targeted supply-chain attacks. He and Chris unpack why standing credentials persist, how private repositories create false...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets

0:00 45:27

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 45 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on May 14, 2026.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!