4 ms·
It's not their job to prevent that.
by _II__II_ 7y ago
It's not their job to prevent that.
- soulofmischief 7y agoIt is a sys admin's job to mitigate damage from security leaks and to introduce hardened, fault-tolerant security paradigms.
- mkagenius 7y agoYou are just hacking the leaves. Once the secret is posted. It is public, it has multiple copy elsewhere on the internet. Even if you delete there is a copy kept somewhere on the internet -- and that's not an assumption. For example, iirc, Github copy is dumped to google every some-x-time.
- justinclift 7y agoHmmm, it seems like having layered security, where accidentally exposed credentials aren't automatically "game over" would be better than not. Not sure how practical that is to implement for every technology, but for many it could probably be done. Seems like a time+money vs risk trade off thing.