Stop Putting Your Passwords Into Random Websites (Yes, Seriously, You Are The Problem)

31 points by rw-rw-rw-


FiloSottile

tl;dr online JSON formatting tools have a share feature that makes the content public (?!) and there are a lot of secrets in there and evidence bad actors are scanning them.

Incredibly grating prose, suggested rant.

gthm

Infosec is such a toxic sinkhole. Most of it is like this, berating people who don't know better without offering any solutions. It is the place for the worst persons among us.

ancienthero

The authors don't even question why these sites would have a public registry of shared links. Yes, users should have mental alarm bells ringing before saving secrets on a third party site, but surely a "Recent Links" page is just a silly feature to have?

loldot

To be frank; if you don't have the instinct not to do this, you should be disqualified from ever operating or developing software solutions again.