Stop Putting Secrets in .env Files

20 points by gaffneyc


WilhelmVonWeiner

I hate that I'm responding to an LLM, but these sorts of secrets shouldn't be on your machine if possible. If you have 1Password on your computer you will inevitably have it set to stay unlocked for as long as possible, because unlocking your password store is annoying.

jkachmar

A few weeks ago my friend Harrison and I did our yearly Tesla FSD cruise around the Bay Area — seven hours of letting the car drive while we talk about whatever comes to mind. This was the first year we never had to take over the wheel, which meant even more time for conversation.

why would i take security advice from someone with this sort of threat model?