Hacker News
new
past
comments
ask
show
jobs
points
by
parineum
12 hours ago
|
comments
by
ceejayoz
12 hours ago
|
next
[-]
A red team might well notice that the build process doesn't check for accidentally committed secrets.
reply
by
jnovek
11 hours ago
|
prev
|
next
[-]
Storing a bunch of passwords in a plain-text list that an individual can access violates zero-trust AND least-privilege which I think a red team might have some opinions on.
reply
by
wil421
9 hours ago
|
prev
|
next
[-]
At my job the commits wouldn’t have even made it to our private GitHub repo. The scanners would’ve rejected it when you tried to push a commit.
They find keys and tokens all the time.
reply
by
gumby271
12 hours ago
|
prev
|
[-]
And yet, here we are.
reply