Lesson 3 / 24

A Simple Threat Model

Ask who could get a secret and how, then apply least privilege and short lifetimes.

Three questions

For each secret ask: who needs it, where is it stored, and what is the damage if it leaks? Then reduce the answers: fewer people, fewer copies, smaller permissions, and a shorter lifetime.

A hotel key card

A hotel card opens only your room and stops working after checkout. That is least privilege plus expiry. A master key that opens every door forever is what an over-powered API key looks like.

Scope every token

Create keys with the minimum permissions, for one environment only. A read-only key for a staging database is a much smaller risk than an admin key shared by everyone.

Quick check: Which practice best limits the damage of a leaked key?

  • One admin key shared with the whole team
  • Giving the key narrow permissions and an expiry
  • Using the same key in every environment
  • Storing the key in the README
Answer

Giving the key narrow permissions and an expiry — Narrow scope and short life reduce what an attacker can do and for how long.