3 ms·
A rule of thumb is: if the key is pushed into a git remote you should consider it compromised and roll a new key.
by urda 4y ago
A rule of thumb is: if the key is pushed into a git remote you should consider it compromised and roll a new key.
- celticninja 4y agoWhat if they key is in a git-crypted file? I get what you are saying about an open file, but surely best practice is to use encrypted files to store secrets that are needed e.g for deployment
- urda 4y agoAn encrypted file stored along with the git repo (without the decryption key) has a different attack surface. My original comment was more targeted towards users storing their keys in plaintext.