this post was submitted on 12 Jul 2024
371 points (97.4% liked)
Programmer Humor
19503 readers
1263 users here now
Welcome to Programmer Humor!
This is a place where you can post jokes, memes, humor, etc. related to programming!
For sharing awful code theres also Programming Horror.
Rules
- Keep content in english
- No advertisements
- Posts must be related to programming or programmer topics
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Well from my personal PoV there are a few problems with that
Easy. You check in the password file first. Then you can check if the codebase contains any entry on the blacklist.
Wait…
You were so close! The right solution is of course training an AI model that detects credentials and rejects commits that contain them!
You joke, but GitHub advanced security does this and more. On top of the AI component, they check the hash of all things that look like an api key and then also check them against their integrated vendors to see if they’re non-expired. I don’t know how well it works, but they claim like a .1% false positive rate or something like that.
I need one of those reminder bots, so I can share a link to an inevitable startup, six months from now, based on your humorous comment.
No. Never.
In this situation, it would be better to write a simple script that can generate fresh and unique values for the dev.
Laziness is not an excuse.