Lesson 2 / 24

How Secrets Leak

Recognise the usual leak paths: Git history, chat, logs, screenshots and shared files.

The usual suspects

Most leaks are accidents, not hacks: a key committed to Git, a password pasted into chat or a ticket, a token printed in CI logs, a .env file zipped and emailed, or a screenshot that shows a dashboard key.

Spot the leak

Both lines below put a secret where it can be read later. The first is stored forever in history, the second ends up in shared logs.

git add .env && git commit -m "add config"
curl -H "Authorization: Bearer $TOKEN" https://api.example.com -v   # -v can print headers

Deleting is not enough

Once a secret is in Git history, a chat message or a log, assume it was copied. Removing the file does not un-leak it. The fix is to revoke or rotate the secret.

Quick check: A key was committed and then deleted in the next commit. What should you do?

  • Nothing, it is gone
  • Wait to see whether anyone notices
  • Rotate the key, because history still contains it
  • Rename the repository
Answer

Rotate the key, because history still contains it — Old commits keep the value. Treat the key as compromised and replace it.