3 ms·
Do you believe this kind of thing is simply unavoidable? I wonder if this could've been avoided by simply making it impossible to access data without being conn
by tabeth 9y ago
Do you believe this kind of thing is simply unavoidable? I wonder if this could've been avoided by simply making it impossible to access data without being connected to a VPN in addition to having some sort of physical device connected to your computer.
- cdoxsey 9y agoFor amazon you can use IAM roles tied to specific EC2 instances, then no credentials are ever stored, you simply make S3 API calls in your code and as long as the machine you're making them from has access to the bucket you can get to the data.
- ajsharp 9y agoIt's entirely avoidable. Just don't commit secrets to source control. Ever.
- tabeth 9y agoThis is good advice, but even if you don't, it's possible that someone else on your team will.
- fiddlerwoaroof 9y agoI don’t think many people intentionally commit secrets to source control. Frequently, it’s a matter of committing a bunch of work and accidentally missing the credentials you stuck in some prototype code.
- chadbennett 9y agoI agree with ajsharp, this is completely avoidable. Along with never committing secrets to source control, implementing 3rd party data breach and data leak monitoring is necessary as recommended in NIST 800-63B