3 ms·
Maybe there's a way to have a secret in GitHub actions that can decrypt the browser-side-encrypted code.
by crazysim 4y ago
Maybe there's a way to have a secret in GitHub actions that can decrypt the browser-side-encrypted code.
- woodruffw 4y agoThey could probably do something like that, but you'd still be putting your credential into an input form on a third-party service and counting on that service to encrypt it. The more concerning part to me is that, even with the best of intentions, this flow is completely indistinguishable from the TOTP phishing flow that we try to train users to avoid.
- varunsharma07 4y agow.r.t phishing: a maintainer intends to publish a release, will go to their GitHub Actions build log, and will click the link in the build log. So it is not a typical phishing scenario where one gets an email without context and clicks the link. Please let me know if I am missing something. There are also ideas about using a phone app and/or a CLI related to end-to-end encryption https://github.com/step-security/wait-for-secrets/issues/56 https://github.com/step-security/wait-for-secrets/issues/56.