DevSec Station

← DevSec Station18 Jun · 7 min

Secrets Management: Stop Playing Whack-a-Mole

Secrets Management: Stop Playing Whack-a-Mole18 Jun7 min

If you've ever committed an API key, password, token, certificate, or other secret to a repository, you're not alone. Most secret leaks don't happen because developers don't care about security. They happen because the easiest place to put a secret is inside the code that uses it. This episode is sponsored by Maze. In this episode of DevSec Station, Tanya Janca explains why secrets leak, why "just be careful" isn't an effective security strategy, and how developers can stop playing whack-a-mo...