{"id":268,"date":"2026-08-10T13:29:59","date_gmt":"2026-08-10T07:59:59","guid":{"rendered":"https:\/\/tierones.io\/blog\/?p=268"},"modified":"2026-08-10T13:30:01","modified_gmt":"2026-08-10T08:00:01","slug":"remote-intern-codebase-access-security","status":"publish","type":"post","link":"https:\/\/tierones.io\/blog\/remote-intern-codebase-access-security\/","title":{"rendered":"An Exposed Cloud Key Was Being Used Within Five Minutes. Your Remote Intern Is Not the Risk \u2014 Your Access Model Is."},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The objection to hiring a remote student engineer is almost never about ability. It is &#8220;I am not giving a stranger eight thousand miles away access to my codebase.&#8221; Worth checking that instinct against the evidence: Palo Alto Networks&#8217; Unit 42 tracked a campaign in which <a href=\"https:\/\/unit42.paloaltonetworks.com\/malicious-operations-of-exposed-iam-keys-cryptojacking\/\" rel=\"nofollow noopener\" target=\"_blank\">an attacker detected and used AWS IAM credentials within five minutes of their exposure on public GitHub, completing more than 400 API calls within seven minutes<\/a>. The threat that should keep a founder up at night is automated, indiscriminate and already in motion \u2014 and it is not a person you interviewed. It is a credential you left somewhere.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Key takeaways<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Credential abuse was the top initial attack vector in Verizon&#8217;s 2025 DBIR at 22% of breaches; third-party involvement doubled to 30%.<\/li>\n\n\n\n<li>28.65 million new hardcoded secrets landed in public GitHub commits in 2025, a 34% year-on-year rise.<\/li>\n\n\n\n<li>Internal repositories are roughly 6x more likely than public ones to contain hardcoded secrets \u2014 the repo you are about to share is the risk.<\/li>\n\n\n\n<li>An intern needs one repository, one scoped key and a seeded environment. Anything beyond that is convenience, not necessity.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">The risk in the data is not the one you are imagining<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Verizon&#8217;s 2025 Data Breach Investigations Report puts <a href=\"https:\/\/www.verizon.com\/about\/news\/2025-data-breach-investigations-report\" rel=\"nofollow noopener\" target=\"_blank\">credential abuse at 22 percent of breaches as an initial attack vector, ahead of exploitation of vulnerabilities at 20 percent, and reports that the percentage of breaches involving a third party doubled to 30 percent<\/a>. Founders read the third-party number as an argument against outside contributors. It is closer to the opposite: what breaks in third-party relationships is credential hygiene \u2014 access granted broadly, shared informally, and never withdrawn \u2014 not the loyalty of the person on the other end.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The distinction matters commercially, because the instinct to keep outsiders away from the code is what pushes small teams towards busywork internships that produce nothing either side values. You do not have to choose between security and useful work. You have to choose what a new person&#8217;s credentials can reach.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Your repository probably already leaks<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before worrying about who you let in, look at what is already inside. GitGuardian&#8217;s State of Secrets Sprawl 2026 found <a href=\"https:\/\/blog.gitguardian.com\/the-state-of-secrets-sprawl-2026\/\" rel=\"nofollow noopener\" target=\"_blank\">28.65 million new hardcoded secrets added to public GitHub commits during 2025, a 34 percent increase year on year and the largest single-year jump it has recorded, with AI service secrets reaching 1,275,105, up 81 percent<\/a>. The finding that should change a founder&#8217;s onboarding checklist is this one: <a href=\"https:\/\/blog.gitguardian.com\/the-state-of-secrets-sprawl-2026\/\" rel=\"nofollow noopener\" target=\"_blank\">internal repositories are roughly six times more likely than public ones to contain hardcoded secrets<\/a>. Private feels safe, so nobody cleans it. That private repository is the one you are about to hand to a new collaborator.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two further numbers close the argument. GitGuardian reports that <a href=\"https:\/\/blog.gitguardian.com\/the-state-of-secrets-sprawl-2026\/\" rel=\"nofollow noopener\" target=\"_blank\">64 percent of valid secrets from 2022 were still active and exploitable as of January 2026<\/a> \u2014 leaked credentials are not a transient problem, they are a permanent liability until someone rotates them. And <a href=\"https:\/\/blog.gitguardian.com\/the-state-of-secrets-sprawl-2026\/\" rel=\"nofollow noopener\" target=\"_blank\">about 28 percent of incidents originate entirely outside repositories<\/a>, in Slack, Jira and Confluence. If your onboarding involves pasting a connection string into a direct message, the repository permissions were never the control that mattered.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/tierones.io\/blog\/wp-content\/uploads\/2026\/08\/least-privilege-ladder-inline-opt-1024x576.jpg\" alt=\"least-privilege-ladder-inline\" class=\"wp-image-275\" srcset=\"https:\/\/tierones.io\/blog\/wp-content\/uploads\/2026\/08\/least-privilege-ladder-inline-opt-1024x576.jpg 1024w, https:\/\/tierones.io\/blog\/wp-content\/uploads\/2026\/08\/least-privilege-ladder-inline-opt-300x169.jpg 300w, https:\/\/tierones.io\/blog\/wp-content\/uploads\/2026\/08\/least-privilege-ladder-inline-opt-768x432.jpg 768w, https:\/\/tierones.io\/blog\/wp-content\/uploads\/2026\/08\/least-privilege-ladder-inline-opt-1536x864.jpg 1536w, https:\/\/tierones.io\/blog\/wp-content\/uploads\/2026\/08\/least-privilege-ladder-inline-opt.jpg 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Speed is the entire threat model<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Unit 42 research is worth sitting with because it dismantles the idea that you will notice in time. Over a monitoring window in late 2023 the researchers watched the operation they called EleKtra-Leak <a href=\"https:\/\/unit42.paloaltonetworks.com\/malicious-operations-of-exposed-iam-keys-cryptojacking\/\" rel=\"nofollow noopener\" target=\"_blank\">detect exposed IAM credentials within five minutes, perform reconnaissance, create security groups and launch large EC2 instances across multiple regions for cryptomining \u2014 roughly 474 unique mining instances during the period observed<\/a>. No human review loop operates at that speed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Which points at the correct control: block the exposure at push time rather than chase it afterwards. <a href=\"https:\/\/docs.github.com\/en\/code-security\/concepts\/secret-security\/push-protection\" rel=\"nofollow noopener\" target=\"_blank\">GitHub&#8217;s push protection rejects pushes containing supported secret types before they reach the repository<\/a>, and turning it on across your organisation costs one setting. Pair it with the rule that any credential you merely suspect was exposed is rotated rather than monitored, and the five-minute window stops being your problem.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The access ladder for a remote intern&#8217;s first month<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Clean the room before the guest arrives.<\/strong> Scan the repository they will work in for committed secrets and rotate anything you find. Internal repos are six times likelier to hold them.<\/li>\n\n\n\n<li><strong>Turn on push protection and secret scanning<\/strong> across the organisation, before anyone new pushes a first commit.<\/li>\n\n\n\n<li><strong>Add them as an outside collaborator on one repository<\/strong>, not as an organisation member. <a href=\"https:\/\/docs.github.com\/en\/organizations\/managing-user-access-to-your-organizations-repositories\/managing-outside-collaborators\/adding-outside-collaborators-to-repositories-in-your-organization\" rel=\"nofollow noopener\" target=\"_blank\">GitHub&#8217;s outside collaborator role exists for exactly this<\/a> \u2014 access to specific repositories, no team membership, permissions set per repository.<\/li>\n\n\n\n<li><strong>Require two-factor authentication<\/strong> at the organisation level. Enforced 2FA applies to outside collaborators before they can accept the invitation.<\/li>\n\n\n\n<li><strong>Give a seeded environment, never production data.<\/strong> A local or staging setup with synthetic records removes the largest category of accident entirely.<\/li>\n\n\n\n<li><strong>Issue their own scoped, expiring credentials.<\/strong> Never a copy of an existing engineer&#8217;s key. Individual credentials are what make revocation possible and attribution meaningful.<\/li>\n\n\n\n<li><strong>Ban secrets in chat.<\/strong> Twenty-eight percent of incidents start outside the repository. Use a secrets manager or a one-time link; a DM is permanent.<\/li>\n\n\n\n<li><strong>Escalate deliberately, in writing.<\/strong> When the work genuinely needs more, grant it, note it, and say what would trigger removal.<\/li>\n\n\n\n<li><strong>Write the offboarding list on day one.<\/strong> Every grant recorded in one place, so the last day is a checklist rather than an act of memory. Given that most leaked credentials stay valid for years, revocation is the step that actually ends the exposure.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">What this unlocks<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Set up this way, an intern in Kanpur or Warangal can open a real pull request in week one against a repository that no longer holds live keys, using credentials that reach nothing you would mind losing. That is a materially better security posture than most teams have with their own permanent staff, and it arrives as a side effect of onboarding one student properly. The remaining questions are contractual rather than technical, and we covered those in <a href=\"https:\/\/tierones.io\/blog\/hire-indian-student-contractor-us-startup\/\">the five things US startups get wrong about hiring an Indian contractor<\/a> \u2014 intellectual property assignment in particular, which under Indian law does not default the way American founders assume.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tierones handles the part that comes before any of this: students at IITs, NITs and IIITs verify their identity with an .ac.in email and connect the work they have actually shipped, so the person you are granting access to is a known, verified individual with a reviewable body of work rather than a r\u00e9sum\u00e9 claim. Roles are remote and part-time, and you set the rate \u2014 we do not set, suggest or cap it. If the review loop that follows is the part you are less sure about, <a href=\"https:\/\/tierones.io\/blog\/remote-intern-code-review-loop\/\">we wrote that up separately<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">FAQ<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Is it safe to give a remote intern access to our codebase?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It is as safe as your access model. Verizon&#8217;s 2025 DBIR puts credential abuse at 22 percent of breaches as the leading initial vector and notes third-party involvement doubled to 30 percent \u2014 figures about over-scoped, shared and un-revoked credentials, not about intent. One repository, one scoped key and a seeded environment leaves an intern carrying about as much risk as a laptop.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What access should a new remote intern get on day one?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The least that lets them ship something real in week one. Write access to a single repository rather than the organisation, added as an outside collaborator rather than an org member, a staging or local environment instead of production data, and their own scoped credentials rather than a copy of anyone else&#8217;s. Escalate deliberately and log every grant so offboarding is a checklist.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How quickly does a leaked credential get abused?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Faster than anyone can respond. Unit 42 documented an operation that detected and used AWS IAM credentials within five minutes of their exposure on public GitHub and completed more than 400 API calls within seven. Prevention at push time beats detection afterwards, and any credential you suspect was exposed should be rotated rather than watched.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Hiring a remote engineer from an Indian Tier-1 campus and want to know who you are actually granting access to? <a href=\"https:\/\/tierones.io\/employers#hire\">Tell us what you need<\/a> \u2014 we&#8217;ll show you proof, not CVs. Questions go to <a href=\"mailto:hire@tierones.io\">hire@tierones.io<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>28.65 million secrets hit public GitHub in 2025 and an exposed key was abused within five minutes. How to give a remote intern real access without the keys.<\/p>\n","protected":false},"author":1,"featured_media":274,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[180,35,181,178,174,182,179,137],"class_list":["post-268","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-for-employers","tag-contractor-access","tag-india","tag-least-privilege","tag-remote-intern-codebase-access","tag-remote-onboarding","tag-secrets-management","tag-security","tag-startup-hiring"],"_links":{"self":[{"href":"https:\/\/tierones.io\/blog\/wp-json\/wp\/v2\/posts\/268","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tierones.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tierones.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tierones.io\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/tierones.io\/blog\/wp-json\/wp\/v2\/comments?post=268"}],"version-history":[{"count":2,"href":"https:\/\/tierones.io\/blog\/wp-json\/wp\/v2\/posts\/268\/revisions"}],"predecessor-version":[{"id":276,"href":"https:\/\/tierones.io\/blog\/wp-json\/wp\/v2\/posts\/268\/revisions\/276"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/tierones.io\/blog\/wp-json\/wp\/v2\/media\/274"}],"wp:attachment":[{"href":"https:\/\/tierones.io\/blog\/wp-json\/wp\/v2\/media?parent=268"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tierones.io\/blog\/wp-json\/wp\/v2\/categories?post=268"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tierones.io\/blog\/wp-json\/wp\/v2\/tags?post=268"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}