3 ms·
% bzgrep "BEGIN PRIVATE KEY" \*.bz2 disk.tar.bz2:Binary file (standard input) matches drive.tar.bz2:Binary file (standard input) matches extsearch.tar.bz2
by rmac 4y ago
% bzgrep "BEGIN PRIVATE KEY" \*.bz2
disk.tar.bz2:Binary file (standard input) matches
drive.tar.bz2:Binary file (standard input) matches
extsearch.tar.bz2:Binary file (standard input) matches
...
- pshirshov 4y agoNothing surprising. The development culture was shit back there. Though I would expect these keys to be just some stub config values which allowed engineers to quickly run the shit locally.
- corytheboyd 4y agoChecked in private keys are fine if they're just used in tests, local development, etc.
- inhumantsar 4y agoTechnically fine yes but from a habits and practice standpoint it's safest to stick to a "not ever" rule and work around the limitations.
- leoh 4y agoyolo
- michens 4y agoCare to explain? Keeping private keys inside the repo sounds fine for me as long as these keys are only used for local development, they are rotated regularly and are only valid for localhost (in case of TLS certs).
- hypeatei 4y agoNot GP: If you make it normal to check in credentials and keys, then the risk of accidentally checking in prod secrets increases. It's basically making it comfortable for devs to deal with keys in repos and I think that's inherently dangerous.
- sparr0 4y agoYou should be using automated checks to keep credentials out of your repo, not relying on individual developers. And those checks can have explicit exceptions for known safe/public/test keys, just like you might explicitly allow testing or fake credit card numbers.
- gnulinux 4y agoChecking in fake private keys is fine for testing. Why is it bad, out of principle, just in case you check in bad private key? I think that's a bad argument because there are a lot of benefits to being able to run end-to-end tests with some key.
- jesprenj 4y agoIt could also be a script that imports a private key and searches for the string BEGIN PRIVATE KEY. Likewise if someone searched HN for this string he'd find your comment (:
- gnulinux 4y agoPeople check in fake private keys to git repos all the time for testing. My own tests have private keys too. They're just sample, unused, publicly advertised private keys I found online. They're useful to make sure your code is working end to end with some private key. EDIT: For example, here: https://ospkibook.sourceforge.net/docs/OSPKI-2.4.7/OSPKI-html/sample-priv-key.htm https://ospkibook.sourceforge.net/docs/OSPKI-2.4.7/OSPKI-htm... or here: https://docs.vmware.com/en/VMware-NSX-Data-Center-for-vSphere/6.4/com.vmware.nsx.admin.doc/GUID-BBC4804F-AC54-4DD2-BF6B-ECD2F60083F6.html https://docs.vmware.com/en/VMware-NSX-Data-Center-for-vSpher... or: https://www.ietf.org/archive/id/draft-bre-openpgp-samples-01.html https://www.ietf.org/archive/id/draft-bre-openpgp-samples-01...