logoalt Hacker News

parineumyesterday at 4:47 PM4 repliesview on HN

Not posting secrets to public GitHub repos doesn't need red teaming.


Replies

ceejayozyesterday at 4:50 PM

A red team might well notice that the build process doesn't check for accidentally committed secrets.

jnovekyesterday at 5:56 PM

Storing a bunch of passwords in a plain-text list that an individual can access violates zero-trust AND least-privilege which I think a red team might have some opinions on.

wil421yesterday at 7:43 PM

At my job the commits wouldn’t have even made it to our private GitHub repo. The scanners would’ve rejected it when you tried to push a commit.

They find keys and tokens all the time.

gumby271yesterday at 4:54 PM

And yet, here we are.