Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> *In most cases, I think we should consider invalidating secret keys instead of trying to delete it and hope nobody saw it.

Absolutely. AWS secret keys accidentally pushed to GitHub are abused within a few minutes. There's essentially no window where published keys remain safe.



That's for a public repo. I'd bet the vast majority of companies have private repos.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: