Hugging Face Spaces Secrets Security Update

Hugging Face has disclosed a security incident involving unauthorized access to the Spaces platform, specifically targeting Spaces secrets. This breach potentially exposed a subset of user secrets, prompting the immediate revocation of affected Hugging Face tokens and a transition toward more secure token management.

Unauthorized Access to Spaces Secrets

Unauthorized access was detected earlier in the week of May 2024, specifically related to the secrets stored within Hugging Face Spaces. Hugging Face suspects that a subset of these secrets may have been accessed without authorization.

To remediate the immediate risk, Hugging Face has already revoked a number of tokens present in those secrets. Users whose tokens were revoked have been notified via email.

Remediation and User Action

Users are strongly advised to refresh any keys or tokens that were stored as secrets in Spaces. As a part of this security upgrade, Hugging Face recommends switching to fine-grained access tokens, which are now the default setting.

Infrastructure Security Improvements

Following the incident, Hugging Face Hugging Face has implemented several technical improvements to the security of the Spaces infrastructure:

  • Key Management Service (KMS): The platform has implemented a Key Management Service (KMS) for Spaces secrets to improve encryption and management.
  • Removal of Org Tokens: Organization tokens have been completely removed to increase traceability and audit capabilities.
  • Leaked Token Identification: The system's ability to identify leaked tokens and proactively invalidate them has been expanded and robustified.
  • Token Deprecation: Hugging Face plans to deprecate "classic" read and write tokens once fine-grained access tokens reach feature parity.

Compliance and Investigation

Hugging Face is working with external cybersecurity forensic specialists to investigate the incident and review security policies. The event has been reported to the law enforcement agencies and Data protection authorities.

Sources