3 ms·
True, but Github and a PaaS platform tell you that your data is leaving your computer. It isn't something that happens in the background from a simple autocompl
by AtheistOfFail 10y ago
True, but Github and a PaaS platform tell you that your data is leaving your computer. It isn't something that happens in the background from a simple autocomplete application.
The other thing is that a proper 12-factor app separates secrets and keys into environment variables that are not committed to Github or your PaaS. They are added after a deployment which this "product" just scoops up. For reference, here's what a AWS key being leaked on Github leads to (https://www.theregister.co.uk/2015/01/06/dev_blunder_shows_github_crawling_with_keyslurping_bots/ https://www.theregister.co.uk/2015/01/06/dev_blunder_shows_g...). Now, imagine that project that is running in production having to be brought offline because this company leaks thousands of AWS keys that were used in development. It's dangerous, sloppy and stupid, three things I generally try not to mix.