Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

https://help.github.com/articles/remove-sensitive-data/

That said, as the article points out, you need to consider them compromised once they've been pushed and rotate the creds.



To add to this, this is not just good paranoid practice. Don't just think you're safe because you fixed it 5 minutes later and probably no one noticed. There are sites that monitor the global github commit feed looking for things like AWS credentials and SSH keys. If it's been pushed to a public github repo for even a moment, it's been grabbed.


Even slightly more obscure things, like the config file for Sublime SFTP (`sftp-config.json`) have been personally observed as a target of crawling.


It's still useful to know how to use e.g. BFG for e.g. Situations where you push a password to private git / GH :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: