Lesson 2 / 24
How Secrets Leak
Recognise the usual leak paths: Git history, chat, logs, screenshots and shared files.
The usual suspects
Most leaks are accidents, not hacks: a key committed to Git, a password pasted into chat or a ticket, a token printed in CI logs, a .env file zipped and emailed, or a screenshot that shows a dashboard key.
Spot the leak
Both lines below put a secret where it can be read later. The first is stored forever in history, the second ends up in shared logs.
git add .env && git commit -m "add config"
curl -H "Authorization: Bearer $TOKEN" https://api.example.com -v # -v can print headersDeleting is not enough
Once a secret is in Git history, a chat message or a log, assume it was copied. Removing the file does not un-leak it. The fix is to revoke or rotate the secret.
Quick check: A key was committed and then deleted in the next commit. What should you do?
- Nothing, it is gone
- Wait to see whether anyone notices
- Rotate the key, because history still contains it
- Rename the repository
Answer
Rotate the key, because history still contains it — Old commits keep the value. Treat the key as compromised and replace it.