3 ms·
You should not trust automatic tools to do that. They will inevitably be subject to both false negatives and false positives, and will most probably just give y
by ChALkeR 11y ago
You should not trust automatic tools to do that. They will inevitably be subject to both false negatives and false positives, and will most probably just give you a false sense of security but will not protect you from the actual leak.
You should better review stuff that you publish. That includes commit review, package contents review before publishing them, config files review, logs review before sharing them.
If you have an org — it would better to educate your devs more and make each commit go through an independent review. Also, don't forget about checking package contents.
- BinaryIdiot 11y agoWhile you should do everything you said I don't see the harm in an extra safety net where an automated tool may catch something you miss. Automated tools won't be as good as s human but humans are not perfect either and are bound to make a mistake; if there are tools that can assist I'm all for it.
- joepie91_ 11y agoThe problem is the false sense of security. The idea that "something is better than nothing" does not necessarily hold true in security, and additional layers can weaken your security rather than strengthen it.
- BinaryIdiot 11y agoI don't think sanity checks are a form of false sense of security. Ideally the way you develop software those types of credentials would never even be in your project but maybe you're testing something and they're temporarily in there (because we've all done that); a warning could let you know you're about to screw up. Naturally anyone can become dependent on anything designed to assist them. I'm not really passionated about either direction really.