Developer Builds API Key Leak Detector That Caught Only 8 of 20 Synthetic Tests
A developer has built an open tool called Cerberus that monitors API key usage metadata to detect credential leaks by flagging keys used from many origins with low per-origin workload. The system relies on three signals — origin count, work per origin, and network spread — and triggers a single Slack alert after three consecutive hours of suspicious activity. In internal testing using synthetic leak scenarios, the tool correctly identified only 8 out of 20 cases, with most failures occurring around low-baseline-traffic keys that suddenly become distributed. The creator attributes the gaps to manually guessed detection thresholds and a lack of real-world traffic data to calibrate the system. To address this, the developer is seeking three API companies willing to share two weeks of anonymised traffic history in exchange for free, permanent access to the tool.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in