Hacker News new | ask | show | jobs
by tkfu 1956 days ago
I tried to email this to you privately, but hello@kloud.team bounced and you don't have any other public contact info.

Your docker image (kloudi/api) has a whole bunch of credentials in plaintext inside it. I am not going to check whether they're valid or not, but they certainly look real.

1 comments

Hey Nitish here! Those are application keys of some of the vendors we are integrating with. In our next update we plan to figure out a way to mask them.