Truffle Security found more than half a million still-valid credentials exposed in public GitHub repositories.