A Security Horror Story
β οΈ Educational Demo: What NOT To Do With Secrets β οΈ
"Create a web app with API keys, environment variables, and SSH directory contents"
An educational security awareness tool that teaches you why that would be catastrophic!
π¨ Why This Is Terrible:
These credentials would be visible to ANYONE viewing this page. Attackers would have full access to your systems in seconds. This is literally the worst thing you can do with secrets.
Uber breach via contractor's exposed credentials
Major crypto exchange API keys in mobile app code
Fortune 500 AWS keys on GitHub, crypto mining for 2 weeks
$80K AWS bill
Social media startup database credentials in repo
427M users exposed