# A Simple Threat Model — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/sh-threat-model

> Ask who could get a secret and how, then apply least privilege and short lifetimes.

## Three questions

For each secret ask: who needs it, where is it stored, and what is the damage if it leaks? Then reduce the answers: fewer people, fewer copies, smaller permissions, and a shorter lifetime.

## A hotel key card

A hotel card opens only your room and stops working after checkout. That is least privilege plus expiry. A master key that opens every door forever is what an over-powered API key looks like.

## Scope every token

Create keys with the minimum permissions, for one environment only. A read-only key for a staging database is a much smaller risk than an admin key shared by everyone.

**Quiz:** Which practice best limits the damage of a leaked key?

- [ ] One admin key shared with the whole team
- [x] Giving the key narrow permissions and an expiry
- [ ] Using the same key in every environment
- [ ] Storing the key in the README

*Answer:* Giving the key narrow permissions and an expiry. Narrow scope and short life reduce what an attacker can do and for how long.
