Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To add to this, this is not just good paranoid practice. Don't just think you're safe because you fixed it 5 minutes later and probably no one noticed. There are sites that monitor the global github commit feed looking for things like AWS credentials and SSH keys. If it's been pushed to a public github repo for even a moment, it's been grabbed.


Even slightly more obscure things, like the config file for Sublime SFTP (`sftp-config.json`) have been personally observed as a target of crawling.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: