{"id":23079,"date":"2022-05-09T15:26:34","date_gmt":"2022-05-09T22:26:34","guid":{"rendered":"https:\/\/salesforcedevops.net\/?p=23079"},"modified":"2022-05-11T08:25:49","modified_gmt":"2022-05-11T15:25:49","slug":"salesforce-bruised-over-heroku-breach-response","status":"publish","type":"post","link":"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/","title":{"rendered":"Salesforce Bruised over Heroku Breach Response"},"content":{"rendered":"\n<p class=\"has-drop-cap wp-block-paragraph\">Heroku, a cloud platform-as-a-service (PaaS) frequently used in Salesforce devops pipelines, was acquired by Salesforce in 2010. On May 3, 2022, Salesforce Incident Response sent out a carefully worded email alert to all owners of Heroku accounts. In the email, Salesforce stated that they will reset the passwords of all Heroku accounts on May 4. The email gave no details about a Heroku breach, except to refer readers to a thread on <a href=\"https:\/\/status.heroku.com\/incidents\/2413\">status.heroku.com<\/a>. The email also warned that any passwords previously used on Heroku should not be used on any other system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this post I take you through the breach, and what Heroku still needs to do. I will also describe why this breach says you need to evaluate your devops secrets management strategy today!<\/p>\n\n\n\t\t\t\t<div class=\"wp-block-uagb-table-of-contents uagb-toc__align-left uagb-toc__columns-1  uagb-block-b2fadea7      \"\n\t\t\t\t\tdata-scroll= \"1\"\n\t\t\t\t\tdata-offset= \"30\"\n\t\t\t\t\tstyle=\"\"\n\t\t\t\t>\n\t\t\t\t<div class=\"uagb-toc__wrap\">\n\t\t\t\t\t\t<div class=\"uagb-toc__title\">\n\t\t\t\t\t\t\tTable Of Contents\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"uagb-toc__list-wrap \">\n\t\t\t\t\t\t<ol class=\"uagb-toc__list\"><li class=\"uagb-toc__list\"><a href=\"#salesforce-incident-response-email-sparked-criticism\" class=\"uagb-toc-link__trigger\">Salesforce Incident Response Email Sparked Criticism<\/a><li class=\"uagb-toc__list\"><a href=\"#response-from-heroku\" class=\"uagb-toc-link__trigger\">Response from Heroku<\/a><li class=\"uagb-toc__list\"><a href=\"#wait-heroku-is-salesforce\" class=\"uagb-toc-link__trigger\">Wait, Heroku is Salesforce?<\/a><li class=\"uagb-toc__list\"><a href=\"#heroku-had-a-history-of-weak-defenses\" class=\"uagb-toc-link__trigger\">Heroku Had a History of Weak Defenses<\/a><li class=\"uagb-toc__list\"><a href=\"#waiting-for-github-restoration\" class=\"uagb-toc-link__trigger\">Waiting for GitHub Restoration<\/a><li class=\"uagb-toc__list\"><a href=\"#avoid-the-double-tap-cyberattack\" class=\"uagb-toc-link__trigger\">Avoid the Double Tap Cyberattack<\/a><li class=\"uagb-toc__list\"><a href=\"#devops-uses-secrets-management\" class=\"uagb-toc-link__trigger\">Devops uses Secrets Management<\/a><li class=\"uagb-toc__list\"><a href=\"#cyberattack-fast-recovery-is-critical-to-enterprise-resiliency\" class=\"uagb-toc-link__trigger\">Cyberattack Fast Recovery is Critical to Enterprise Resiliency<\/a><li class=\"uagb-toc__list\"><a href=\"#salesforce-gets-a-bruise-from-a-troubled-child\" class=\"uagb-toc-link__trigger\">Salesforce Gets a Bruise from a Troubled Child<\/a><li class=\"uagb-toc__list\"><a href=\"#heroku-breach-offers-lessons-and-cautions\" class=\"uagb-toc-link__trigger\">Heroku Breach Offers Lessons and Cautions<\/a><\/ol>\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\n\n\n<h2 class=\"wp-block-heading\" id=\"h-salesforce-incident-response-email-sparked-criticism\">Salesforce Incident Response Email Sparked Criticism<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The May 3<sup>rd<\/sup> email unleashed a <a href=\"https:\/\/news.ycombinator.com\/item?id=31255450\">firestorm of criticism<\/a> about the lack of an adequate response from Heroku about a security breach which had started two weeks earlier.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On April 12 GitHub informed Heroku that a cybersecurity threat actor had stolen the OAuth token which controls Heroku\u2019s GitHub integration. Then, on April 15 <a href=\"https:\/\/github.blog\/2022-04-15-security-alert-stolen-oauth-user-tokens\/\">GitHub published a blog post<\/a> about the breach, and Heroku notified customers in the <a href=\"https:\/\/status.heroku.com\/incidents\/2413\">support thread<\/a>. Heroku then shut down the connection with GitHub. Heroku later published some mitigation recommendations in the thread. However, no further information about the nature of the breach was available when the password reset email went out.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On May 5, Heroku posted new information about the breach in the support thread. In a shocking chronology, the company detailed a chain of events that led to the threat actor accessing authentication systems. A leading cybersecurity publication, <em>Bleeping Computer<\/em>, penned the headline \u201c<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/heroku-admits-that-customer-credentials-were-stolen-in-cyberattack\/\">Heroku admits that customer credentials were stolen in cyberattack<\/a>.\u201d<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-response-from-heroku\">Response from Heroku<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">On Friday, May 6, Bob Wise, the newly installed Heroku general manager and a Salesforce EVP, <a href=\"https:\/\/blog.heroku.com\/we-heard-your-feedback\">made a post<\/a>. He cited several missteps while handling the breach response. After acknowledging problems, Mr. Wise said they intend to perform better. The post <a href=\"https:\/\/news.ycombinator.com\/item?id=31291065\">did not quell the firestorm<\/a>, and left questions about the GitHub integration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mr. Wise said in the post that Heroku had detected no intruder activity since April 14. And, Heroku had not observed any threat actors accessing customer accounts or decrypting environment variables. He stated that they have received feedback on the May 5 post where they unveiled too much information all at once, weeks after Heroku had learned details about the breach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mr. Wise claimed to have the situation under control and said, \u201cthe integration between Heroku and GitHub is part of the magic of using Heroku.\u201d He went on to say that Heroku will update users \u201cover the next several weeks\u201d on the GitHub integration. In the meantime, the Heroku-GitHub connection remains down.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-wait-heroku-is-salesforce\">Wait, Heroku is Salesforce?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Part of the anger and confusion expressed by Heroku users is because they are getting notices about a Heroku breach from Salesforce Incident Response. Up until now, all Heroku users have communicated with Heroku using a pure Heroku identity. Why at this important moment did the email come from Salesforce? Has there been some mysterious behind-the-scenes activity?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Social media conversations about the Heroku breach often digress into lamentations about the \u201cgood old days\u201d of Heroku and complaints about Salesforce\u2019s handling of the company. One possible source of the complaints is that since its heyday, Heroku seems to have experienced a brain-drain. Social media is peppered with former employees who complain about rudderless management and product development.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the mid-2010s, Heroku pioneered the idea of lowering the cognitive load on developers. This was when, even after the Salesforce acquisition, Heroku \u201cjust worked\u201d and made deploying cloud native applications easy. But Heroku has fallen behind in compact, developer-friendly code deployment systems. A recent discussion on <a href=\"https:\/\/news.ycombinator.com\/item?id=31313779\"><em>Hacker News<\/em><\/a> cited PaaS alternatives like Vercel, DigitalOcean, Render.com, and Fly.io as Heroku alternatives.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-heroku-had-a-history-of-weak-defenses\">Heroku Had a History of Weak Defenses<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As the new Heroku GM, Mr. Wise has his work cut out for him. He needs to overcome years of poor oversight in cybersecurity. A management reckoning must be underway with this existential security breach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It appears this incident has been poorly handled partly due to the history of Heroku cybersecurity practices. One insider who worked in Salesforce Incident Response until 2020, and now works in the federal government, spoke confidentially to <em>SalesforceDevops.net<\/em> about Salesforce security management practices. Unlike other Salesforce clouds, Heroku incident management was handled \u201cat arm\u2019s length.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The resources devoted to Heroku cybersecurity in the years before this incident did not match the resources put into other Salesforce clouds or divisions, according to the former Salesforce cybersecurity analyst. Heroku security staffers lacked the resources required for a proper cybersecurity posture at the time. \u201cIt seems like they only had one or two guys, maybe not even full-time [cybersecurity staff],\u201d said the analyst.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Salesforce usually funds key operational functions like security and platform to a luxurious extent. The former Salesforce analyst confirmed that Salesforce Incident Response is well funded with generous staffing, excellent recruiting, access to key systems, and 24\/7 global management. Apparently, in the years before this incident, the Heroku cybersecurity team was off on a cybersecurity and operations island.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-waiting-for-github-restoration\">Waiting for GitHub Restoration<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">It is disconcerting that Heroku has yet to restore the GitHub connection. Without further information we are left to speculate about possible explanations. People are left to wonder if they still may not know exactly what happened and how to stop it in the future.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even though Heroku has not detected any activity since April 14, that does not mean the threat actor cannot perform further exfiltration activities. Due to this and other factors, the nature of the Heroku attack is worrisome for the former Salesforce cybersecurity analyst. \u201cThe man in the middle is the ever-present ghost sitting on your shoulder, and you never know when he\u2019s listening,\u201d he said ominously.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-avoid-the-double-tap-cyberattack\">Avoid the Double Tap Cyberattack<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Since user authentication information was exfiltrated from Heroku, every user must completely re-generate account passwords and associated environment variables. And the former Salesforce analyst warned that running mitigation activities just once may offer insufficient protection, however.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When a threat actor uses the \u201ckeys to the kingdom\u201d for exfiltration, a one-and-done attitude to mitigating a breach may not be enough. After full functionality is restored, or an acceptable retrospective is produced by Heroku, mitigation procedures should be rerun, advised the cybersecurity analyst.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threat actors have been known to remain undetected in breached systems. They wait for users of breached systems to regenerate credentials in a corrupted system. When a threat actor remains hidden for a secondary attack, it is known as the <em>Double Tap Cyberattack<\/em>. It should be emphasized that there is no evidence this is happening to Heroku.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The double tap cyberattack is named after a tactic used in the Iraq and Afghanistan wars. A double tap bombing attack occurs when an enemy terrorizes a civilian population by first bombing crowded public areas such as markets. That is the first tap. The enemy then waits a short period of time and attacks the first responders and civilians searching for survivors for the second tap.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-devops-uses-secrets-management\">Devops uses Secrets Management<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">OAuth tokens and environment variables are frequently used within Salesforce devops pipelines. Using a scripted command server, such as GitHub Actions, Azure DevOps, or even Opsera or Copado, sends the secrets over the Internet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Whenever authentication information must be handled in a pipeline, that activity is called <em>secrets management<\/em>. Authentication information is used in devops to log onto Salesforce, access source code repositories, run tests, perform cybersecurity scans, and access cloud-based services. In other words, secrets management is <em>everywhere<\/em> in devops.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cyberattack-fast-recovery-is-critical-to-enterprise-resiliency\">Cyberattack Fast Recovery is Critical to Enterprise Resiliency<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This Heroku breach, man-in-the-middle attacks, and the theoretical notion of a double tap cyberattack all highlight the potential vulnerability of your secrets management practices. The former Salesforce cybersecurity analyst emphasizes the need for users to be ready with a safe and responsive secrets management strategy. \u201cSetting up static things doesn\u2019t work. When faced with a cyberattack of my authentication data, I have two questions. What do I need to know? And how do I recover fast?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Fast recovery<\/em> is a key emphasis in the US government\u2019s civilian cybersecurity doctrine. Since 2021 <a href=\"https:\/\/www.cisa.gov\/\">CISA<\/a> and the <a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/statements-releases\/2021\/07\/28\/fact-sheet-biden-administration-announces-further-actions-to-protect-u-s-critical-infrastructure\/\">White House<\/a> have emphasized the need for critical infrastructure to have plans to recover quickly from an unanticipated cyberattack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is based on the realization that cyber attackers have the upper hand in <a href=\"https:\/\/origin.salesforcedevops.net\/index.php\/2021\/05\/17\/we-are-all-cyberwarriors-now\/\">cyberwar<\/a>. Attackers have access to zero-day exploits and use unforeseen attack methods, especially when attacks are state-sponsored. So, you are always at risk of being taken down by a malicious actor.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The proper response is to go beyond the active and passive measures designed to keep out intruders. You need to assume your secrets will eventually get exfiltrated. For application recovery resiliency you need a plan and a secrets management infrastructure ready to recover quickly from an attack.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-salesforce-gets-a-bruise-from-a-troubled-child\">Salesforce Gets a Bruise from a Troubled Child<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Without a doubt, the Heroku breach is a negative note for Salesforce cybersecurity and a red alert for every Heroku user. However, the problem appears to be more with corporate governance than a generalized Salesforce problem. After allowing the division to languish on a corporate island for years, the company is now faced with an embarrassing cybersecurity incident. But it appears that Salesforce is moving in the resources needed to fix the situation. Let\u2019s hope Heroku is fully resolved soon.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And, figuring out how Heroku moves forward isn\u2019t going to be easy. Heroku clearly has two separate customer bases. The first customer base consists of the cloud native developers who love all application deployment features. It should be noted that a fair number of those customers don\u2019t care about Salesforce.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The other Heroku user base consists of Salesforce users and the Salesforce platform itself. Many Salesforce customers have integrated Heroku into their IT infrastructure. And Heroku supports features in Salesforce, such as Salesforce Functions. Heroku is also frequently used by advanced Salesforce AppExchange packages. Based on these dependencies, it seems unlikely that Salesforce will abandon Heroku. The appointment of a new general manager is a good sign that changes may be underway.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-heroku-breach-offers-lessons-and-cautions\">Heroku Breach Offers Lessons and Cautions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Currently, there is still cause for concern about the Heroku breach. The company still needs to restore the GitHub connection and produce a reasonable technical retrospective on the incident. After that, it would be advisable for customers to re-run any mitigation procedures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hopefully this event will increase awareness about how secrets management permeates devops. If your authentication information is stolen, do you have a way to quickly change and re-deploy it in your devops pipeline?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Heroku, a cloud platform-as-a-service (PaaS) frequently used in Salesforce devops pipelines, was acquired by Salesforce in 2010. On May 3, 2022, Salesforce Incident Response sent out a carefully worded email&hellip;<\/p>\n","protected":false},"author":1,"featured_media":23082,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","footnotes":""},"categories":[4],"tags":[964,51],"post_series":[],"class_list":["post-23079","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-news","tag-heroku","tag-salesforce","entry","has-media"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.1 (Yoast SEO v28.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Salesforce Bruised over Heroku Breach Response - SalesforceDevops.net<\/title>\n<meta name=\"description\" content=\"Secrets management permeates devops. The Heroku breach asks do you have a way to quickly change and re-deploy secrets in your devops pipeline?\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Salesforce Bruised over Heroku Breach Response - SalesforceDevops.net\" \/>\n<meta property=\"og:description\" content=\"Secrets management permeates devops. The Heroku breach asks do you have a way to quickly change and re-deploy secrets in your devops pipeline?\" \/>\n<meta property=\"og:url\" content=\"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/\" \/>\n<meta property=\"og:site_name\" content=\"SalesforceDevops.net\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/salesforcedevopsnet\" \/>\n<meta property=\"article:published_time\" content=\"2022-05-09T22:26:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-05-11T15:25:49+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"675\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Vernon Keenan\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@salesforcedevop\" \/>\n<meta name=\"twitter:site\" content=\"@salesforcedevop\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Vernon Keenan\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"TechArticle\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2022\\\/05\\\/09\\\/salesforce-bruised-over-heroku-breach-response\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2022\\\/05\\\/09\\\/salesforce-bruised-over-heroku-breach-response\\\/\"},\"author\":{\"name\":\"Vernon Keenan\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#\\\/schema\\\/person\\\/f681893c994bc40406bb391546cd7ac8\"},\"headline\":\"Salesforce Bruised over Heroku Breach Response\",\"datePublished\":\"2022-05-09T22:26:34+00:00\",\"dateModified\":\"2022-05-11T15:25:49+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2022\\\/05\\\/09\\\/salesforce-bruised-over-heroku-breach-response\\\/\"},\"wordCount\":1779,\"publisher\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2022\\\/05\\\/09\\\/salesforce-bruised-over-heroku-breach-response\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/salesforcedevops.net\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/heroku-cover.png\",\"keywords\":[\"Heroku\",\"Salesforce\"],\"articleSection\":[\"Industry News\"],\"inLanguage\":\"en-US\",\"copyrightYear\":\"2022\",\"copyrightHolder\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2022\\\/05\\\/09\\\/salesforce-bruised-over-heroku-breach-response\\\/\",\"url\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2022\\\/05\\\/09\\\/salesforce-bruised-over-heroku-breach-response\\\/\",\"name\":\"Salesforce Bruised over Heroku Breach Response - SalesforceDevops.net\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2022\\\/05\\\/09\\\/salesforce-bruised-over-heroku-breach-response\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2022\\\/05\\\/09\\\/salesforce-bruised-over-heroku-breach-response\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/salesforcedevops.net\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/heroku-cover.png\",\"datePublished\":\"2022-05-09T22:26:34+00:00\",\"dateModified\":\"2022-05-11T15:25:49+00:00\",\"description\":\"Secrets management permeates devops. The Heroku breach asks do you have a way to quickly change and re-deploy secrets in your devops pipeline?\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2022\\\/05\\\/09\\\/salesforce-bruised-over-heroku-breach-response\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2022\\\/05\\\/09\\\/salesforce-bruised-over-heroku-breach-response\\\/#primaryimage\",\"url\":\"https:\\\/\\\/salesforcedevops.net\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/heroku-cover.png\",\"contentUrl\":\"https:\\\/\\\/salesforcedevops.net\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/heroku-cover.png\",\"width\":1200,\"height\":675,\"caption\":\"Heroku Logo\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#website\",\"url\":\"https:\\\/\\\/salesforcedevops.net\\\/\",\"name\":\"SalesforceDevops.net\",\"description\":\"Elevating Salesforce Devops with Insights and Innovation\",\"publisher\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/salesforcedevops.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#organization\",\"name\":\"SalesforceDevops.net\",\"url\":\"https:\\\/\\\/salesforcedevops.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/salesforcedevops.net\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/7760e9c16fc75961659174739887197e-sticker.png\",\"contentUrl\":\"https:\\\/\\\/salesforcedevops.net\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/7760e9c16fc75961659174739887197e-sticker.png\",\"width\":421,\"height\":421,\"caption\":\"SalesforceDevops.net\"},\"image\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/salesforcedevopsnet\",\"https:\\\/\\\/x.com\\\/salesforcedevop\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/vernonkeenan\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCOgOn9rD5gyXSOmV7-Q0n7g\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#\\\/schema\\\/person\\\/f681893c994bc40406bb391546cd7ac8\",\"name\":\"Vernon Keenan\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f1183f1ebb5c059e052825760f95b25244abc5ef832145327f298f3697f980c7?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f1183f1ebb5c059e052825760f95b25244abc5ef832145327f298f3697f980c7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f1183f1ebb5c059e052825760f95b25244abc5ef832145327f298f3697f980c7?s=96&d=mm&r=g\",\"caption\":\"Vernon Keenan\"},\"description\":\"Vernon Keenan (LinkedIn) works as a senior information technology industry consultant based in Oakland, California. He earned his B.Sc. in Biomedical Engineering at Northwestern University where he programmed a PDP-8 with punched paper tape. In his 34-year-long career he has been a teacher, SPSS programmer, database administrator, clinical researcher, technology journalist, product marketing manager, market researcher, management consultant, and industry analyst. Most recently he is a telecom operator, cloud architect, Go devops engineer and Salesforce Developer\\\/Architect. For inquiries about Salesforce strategy briefings or solution architect work please contact Vern directly at +1-510-679-1900 or vern@vernonkeenan.com.\",\"sameAs\":[\"https:\\\/\\\/ceres-gw.tnxs.net\",\"https:\\\/\\\/linkedin.com\\\/in\\\/vernonkeenan\",\"https:\\\/\\\/x.com\\\/salesforcedevop\"],\"url\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/author\\\/vern\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Salesforce Bruised over Heroku Breach Response - SalesforceDevops.net","description":"Secrets management permeates devops. The Heroku breach asks do you have a way to quickly change and re-deploy secrets in your devops pipeline?","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/","og_locale":"en_US","og_type":"article","og_title":"Salesforce Bruised over Heroku Breach Response - SalesforceDevops.net","og_description":"Secrets management permeates devops. The Heroku breach asks do you have a way to quickly change and re-deploy secrets in your devops pipeline?","og_url":"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/","og_site_name":"SalesforceDevops.net","article_publisher":"https:\/\/www.facebook.com\/salesforcedevopsnet","article_published_time":"2022-05-09T22:26:34+00:00","article_modified_time":"2022-05-11T15:25:49+00:00","og_image":[{"width":1200,"height":675,"url":"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover.png","type":"image\/png"}],"author":"Vernon Keenan","twitter_card":"summary_large_image","twitter_creator":"@salesforcedevop","twitter_site":"@salesforcedevop","twitter_misc":{"Written by":"Vernon Keenan","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"TechArticle","@id":"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/#article","isPartOf":{"@id":"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/"},"author":{"name":"Vernon Keenan","@id":"https:\/\/salesforcedevops.net\/#\/schema\/person\/f681893c994bc40406bb391546cd7ac8"},"headline":"Salesforce Bruised over Heroku Breach Response","datePublished":"2022-05-09T22:26:34+00:00","dateModified":"2022-05-11T15:25:49+00:00","mainEntityOfPage":{"@id":"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/"},"wordCount":1779,"publisher":{"@id":"https:\/\/salesforcedevops.net\/#organization"},"image":{"@id":"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/#primaryimage"},"thumbnailUrl":"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover.png","keywords":["Heroku","Salesforce"],"articleSection":["Industry News"],"inLanguage":"en-US","copyrightYear":"2022","copyrightHolder":{"@id":"https:\/\/salesforcedevops.net\/#organization"}},{"@type":"WebPage","@id":"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/","url":"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/","name":"Salesforce Bruised over Heroku Breach Response - SalesforceDevops.net","isPartOf":{"@id":"https:\/\/salesforcedevops.net\/#website"},"primaryImageOfPage":{"@id":"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/#primaryimage"},"image":{"@id":"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/#primaryimage"},"thumbnailUrl":"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover.png","datePublished":"2022-05-09T22:26:34+00:00","dateModified":"2022-05-11T15:25:49+00:00","description":"Secrets management permeates devops. The Heroku breach asks do you have a way to quickly change and re-deploy secrets in your devops pipeline?","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/#primaryimage","url":"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover.png","contentUrl":"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover.png","width":1200,"height":675,"caption":"Heroku Logo"},{"@type":"WebSite","@id":"https:\/\/salesforcedevops.net\/#website","url":"https:\/\/salesforcedevops.net\/","name":"SalesforceDevops.net","description":"Elevating Salesforce Devops with Insights and Innovation","publisher":{"@id":"https:\/\/salesforcedevops.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/salesforcedevops.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/salesforcedevops.net\/#organization","name":"SalesforceDevops.net","url":"https:\/\/salesforcedevops.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/salesforcedevops.net\/#\/schema\/logo\/image\/","url":"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2021\/03\/7760e9c16fc75961659174739887197e-sticker.png","contentUrl":"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2021\/03\/7760e9c16fc75961659174739887197e-sticker.png","width":421,"height":421,"caption":"SalesforceDevops.net"},"image":{"@id":"https:\/\/salesforcedevops.net\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/salesforcedevopsnet","https:\/\/x.com\/salesforcedevop","https:\/\/www.linkedin.com\/in\/vernonkeenan","https:\/\/www.youtube.com\/channel\/UCOgOn9rD5gyXSOmV7-Q0n7g"]},{"@type":"Person","@id":"https:\/\/salesforcedevops.net\/#\/schema\/person\/f681893c994bc40406bb391546cd7ac8","name":"Vernon Keenan","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f1183f1ebb5c059e052825760f95b25244abc5ef832145327f298f3697f980c7?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f1183f1ebb5c059e052825760f95b25244abc5ef832145327f298f3697f980c7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f1183f1ebb5c059e052825760f95b25244abc5ef832145327f298f3697f980c7?s=96&d=mm&r=g","caption":"Vernon Keenan"},"description":"Vernon Keenan (LinkedIn) works as a senior information technology industry consultant based in Oakland, California. He earned his B.Sc. in Biomedical Engineering at Northwestern University where he programmed a PDP-8 with punched paper tape. In his 34-year-long career he has been a teacher, SPSS programmer, database administrator, clinical researcher, technology journalist, product marketing manager, market researcher, management consultant, and industry analyst. Most recently he is a telecom operator, cloud architect, Go devops engineer and Salesforce Developer\/Architect. For inquiries about Salesforce strategy briefings or solution architect work please contact Vern directly at +1-510-679-1900 or vern@vernonkeenan.com.","sameAs":["https:\/\/ceres-gw.tnxs.net","https:\/\/linkedin.com\/in\/vernonkeenan","https:\/\/x.com\/salesforcedevop"],"url":"https:\/\/salesforcedevops.net\/index.php\/author\/vern\/"}]}},"uagb_featured_image_src":{"full":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover.png",1200,675,false],"thumbnail":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover-150x150.png",150,150,true],"medium":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover-300x169.png",300,169,true],"medium_large":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover-768x432.png",768,432,true],"large":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover-1024x576.png",980,551,true],"1536x1536":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover.png",1200,675,false],"2048x2048":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover.png",1200,675,false],"lightbox":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover.png",1200,675,false],"search_results":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover-125x125.png",125,125,true],"blog_entry":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover.png",750,422,false],"blog_post":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover.png",750,422,false],"blog_post_full":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover.png",1200,675,false],"blog_related":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover.png",1200,675,false],"gallery":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2022\/05\/heroku-cover.png",1200,675,false]},"uagb_author_info":{"display_name":"Vernon Keenan","author_link":"https:\/\/salesforcedevops.net\/index.php\/author\/vern\/"},"uagb_comment_info":2,"uagb_excerpt":"Heroku, a cloud platform-as-a-service (PaaS) frequently used in Salesforce devops pipelines, was acquired by Salesforce in 2010. On May 3, 2022, Salesforce Incident Response sent out a carefully worded email&hellip;","_links":{"self":[{"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/posts\/23079","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/comments?post=23079"}],"version-history":[{"count":0,"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/posts\/23079\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/media\/23082"}],"wp:attachment":[{"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/media?parent=23079"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/categories?post=23079"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/tags?post=23079"},{"taxonomy":"post_series","embeddable":true,"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/post_series?post=23079"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}