# How Secrets Leak — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/sh-common-leaks

> Recognise the usual leak paths: Git history, chat, logs, screenshots and shared files.

## The usual suspects

Most leaks are accidents, not hacks: a key committed to Git, a password pasted into chat or a ticket, a token printed in CI logs, a `.env` file zipped and emailed, or a screenshot that shows a dashboard key.

## Spot the leak

Both lines below put a secret where it can be read later. The first is stored forever in history, the second ends up in shared logs.

```bash
git add .env && git commit -m "add config"
curl -H "Authorization: Bearer $TOKEN" https://api.example.com -v   # -v can print headers
```

## Deleting is not enough

Once a secret is in Git history, a chat message or a log, assume it was copied. Removing the file does not un-leak it. The fix is to revoke or rotate the secret.

**Quiz:** A key was committed and then deleted in the next commit. What should you do?

- [ ] Nothing, it is gone
- [ ] Wait to see whether anyone notices
- [x] Rotate the key, because history still contains it
- [ ] Rename the repository

*Answer:* Rotate the key, because history still contains it. Old commits keep the value. Treat the key as compromised and replace it.
