|
|
|
|
|
by tekla
1000 days ago
|
|
> an audit should include scanning all files for passwords Please continue taking the security course. Scanning all files for passwords is madness. How do you differentiate "thisissupersecret" and "123fqfqlfni34235r4" and "git@somegitrepo.com" as passwords? You can't, they're all valid passwords for a majority of services. At some point, you need to trust developers to do the right thing, which is impossible. |
|