161

Dear me,

We have noticed you uploaded files to a public github with your API keys in plaintext.

Please proceed to bang head against desk until you have learned your lesson.

Sincerely me.

Comments
  • 6
    Does github bot send you email to warn API keys? They need have this feature long times ago!
  • 1
    @LicensedCrime I prefer dotenv or private repo, but it's good to have a bot!
  • 1
    @LicensedCrime But I'm a JS developer. If I dont setup Node server, I cant even access fs πŸ˜…
  • 2
    Don't worry. Companies like DJI made the same mistake and it went unnoticed for a long time.
  • 1
    @LicensedCrime I'm quite certain there are people run bots scraping github for private keys.

    This is definitely a good project if use it for good.

    I think I will take it!

    Thanks a lot!
  • 1
    Did this yesterday with flumBot's key :/
  • 1
    @sunfishcc GitHub has this feature, I accidentally uploaded API keys by mistake once and got an email right away.
  • 0
    If you want to know specifically, j had an email from sendgrid about 15 hours after the commit saying my account was suspended until I reset the key pair
  • 1
  • 1
    @Awlex The font on that page is insame
  • 1
    @sunfishcc Insame, that perfecly describes it🀣🀣🀣
  • 0
    Are you me?

    I did literally that for a discord bot I'm making.

    Every server which the bot was connected to got around 600 pictures (in each text channel!) of "cat grill"s, no nudity tho

    You learn from your mistakes ¯\_(ツ)_/¯
  • 1
    Surprised people don't automatically use bitbucket for free private repositories. No fuck you if you forget your gitignore
  • 0
    not an programmer but tried using AWS SDKs, at least for java, the DefaultCredentialsProviderChain , in which hardcoding keys is discouraged but usable, and got other options to avoid it.
  • 0
    I wonder if I've done that, but as long as I haven't uploaded the file where the API are stored , aren't I safe ?? or any quick way to check ??
  • 1
    Maybe the following can be made to run before Each Git Push?
    https://github.com/kootenpv/...
Add Comment