Research Reveals No Exposed Secrets in Public GCP Images
By
mooreds
10mo ago· 6 min readenInsight
100/100
Golden Brown
Bagelometer↗
Pulled from the oven just right. Trustworthy, fact-dense, deeply satisfying.
Score100TypeanalysisSentimentpositive
Summary
This guest post by cloud security researchers Eduard Agavriloae and Matei Josephs, part of Truffle Security’s Research CFP program, explores their findings from scanning 8,400+ public Google Cloud Platform (GCP) images for exposed secrets. Unlike their previous research on AWS and Azure, which revealed hundreds of exposed secrets, the GCP scan found none, highlighting the platform's tightly controlled image marketplace.
Key quotes
· 3 pulledWe scanned 8,400+ public GCP images and did not find a single exposed secret!
GCP’s curated, tightly-controlled image marketplace has seemingly eliminated secret exposure in its cloud images.
That’s a dramatic reversal compared to the hundreds we found in AWS AMIs and dozens in Azure Public images.
We scanned 8,400+ public GCP images and did not find a single exposed secret! That’s a dramatic reversal compared to the hundreds we found in AWS AMIs and dozens in Azure Public images. GCP’s curated, tightly- controlled image marketplace has seemingly el

