8 ms·
Thank you SO for being open and listing the best practices. It seems like even few security best practices makes it harder for hackers to get in to your system.
by 120bits 6y ago
Thank you SO for being open and listing the best practices. It seems like even few security best practices makes it harder for hackers to get in to your system.
I have database connecting strings and password as ENV variables. But I still don't know what is the best practice. Lets say someone gets access to the server, they can still read the ENV vars, right? It definitely prevents from accidently checking in your code git repo. But still . Does anyone has good recommendation for storing credentials like database passwords in a way secured way.
- cbg0 6y agoI don't think there's a magic way to do this, if your app can connect to the database and someone has access to your app server - they have access to your database as well.
- dividuum 6y ago> Lets say someone gets access to the server, they can still read the ENV vars, right? Correct. Easiest way is to look at `/proc/$pid/environ`. It contains the \0 separated values for that process.