3 ms·
Private repo or not, checking your credentials into git is amateur. I’d normally say eventually it’d bite you if you fall into the habit and do it on a public
by odammit 9y ago
Private repo or not, checking your credentials into git is amateur.
I’d normally say eventually it’d bite you if you fall into the habit and do it on a public repo by accident but it looks like it can bite you on a private one too.
Manage your secrets. Use something like Vault[1] or Pass[2] they’re free and awesome projects.
I keep all of my secrets even non-prod ones in one of these two because if you think about it, even your “non-prod” github credentials are kinda prod since you have access to code.
1- https://www.vaultproject.io/ https://www.vaultproject.io/
2- https://www.passwordstore.org/ https://www.passwordstore.org/
Also when it comes to AWS secrets, give your developers read only access, make them turn on MFA and assume a role that scopes permissions to the work they need to do.
Leaking AWS secrets is really asking for it. The amount of bots that consistently scan public git repos and then use the credentials to spin up massive instances to mine crypto currency is impressive. I’ve seen it do upwards of $10000 in AWS usage within five minutes of the commit containing the credentials.
- sillysaurus3 9y agoIt may be amateur, but it's one of the most common mistakes. Even at top companies.
- odammit 9y agoAmateur may not have been the best word. Maybe easy or lazy or debt. Ive seen it a lot where it was something that was inherited and the current team knows its a problem, but they have a 1000 features to build and never get around to fixing that debt.
- sillysaurus3 9y agoThe cure for this is to get a pentest. It forces you to care.
- zanedb 9y agoIf you still want to use a Git repo, at least use an encrypted Keybase teams repo[0]. [0]: https://keybase.io/blog/encrypted-git-for-everyone https://keybase.io/blog/encrypted-git-for-everyone