4 ms·
We make no distinction between dev keys and production. Consider them production. Since it's of interest to HN, I am working on educating our very small team o
by thieving_magpie 6y ago
We make no distinction between dev keys and production. Consider them production.
Since it's of interest to HN, I am working on educating our very small team on how keys should be protected and used. I am the youngest developer by about 15 years. It's a very rural company and it often feels like all learning and passion for development stalled around 2005. It's a company that gave me a chance to grow into a development role with no previous experience so I feel indebted to try my best to keep the lights on.
- dijit 6y agoaha, sounds fair. I don't judge too harshly- anyone who has black and white principles on these matters has never worked in any other industry most likely... all you can do is your best to steer the ship and convey the downsides. I think it's important too because it helps us understand how much friction people will tolerate. In many cases, even a small amount of friction will cause people to stop functioning completely; I recently tried setting up vault and it was a nightmare, I understand why people avoid picking it up. That doesn't mean we should not try; we have to become the advocates, arbiters and helpers for those systems. Good luck, you're not alone.
- thieving_magpie 6y agoThanks for the kind words. Good luck to you as well.
- Ididntdothis 6y agoOne thing i have noticed is that “security conscious” people are very good at criticizing things and pointing out flaws. But they are not as good at proposing clear and workable solutions that don’t add huge burden to users. It should be no surprise that people do insecure stuff under deadline pressure.
- a1369209993 6y ago> are very good at criticizing things [but] not as good at proposing clear and workable solutions This is definitely true, but not actually surprising. It's much easier to notice that, say, a violin performance or plumbing repair is done very badly, than it is to actually do it correctly yourself. Which also leads to a great deal of exasperation when people (either apparently or actually) don't even notice that what they're doing is insecure. There's a big difference between "yeah, it's broken, but it'd be a huge pain to fix and we'd probably get it wrong anyway, so we'd rather take our chances" versus "there is no problem".
- uaas 6y agoUsing different ones for dev and prod still might be good idea. If either one is compromised, there’s a chance the other is safe. You can still rotate them regularly, and/or if either one is compromised.