4 ms·
> if someone is in your server you are pwned anyways. This is false and also a symptom of an all-or-nothing approach to cybersecurity, which isn't feasible in
by NegativeK 2y ago
> if someone is in your server you are pwned anyways.
This is false and also a symptom of an all-or-nothing approach to cybersecurity, which isn't feasible in the real world.
- TZubiri 2y agoI suppose they could have read only access to the filesystem and read the api keys, like through an http server
- qweqwe14 2y agoSorry but it is largely all-or-nothing in this case, if someone has access to the user the app runs as, you are screwed. It doesn't matter whether you use env vars or files. I'm assuming the parent intended to say "if someone gained access to your user you are pwned anyways", which is true, unless you actually go to the effort of storing the secrets securely using OS-provided mechanisms. Env vars are not that. > which isn't feasible in the real world Well of course it isn't, how would you justify those sweet cybersecurity experts' paychecks otherwise? Not saying cybersecurity isn't important, but there's way too much snake oil in the industry nowadays (always has been?).