Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
Don't Commit Your Secrets
Search
Nicholas Henry
June 17, 2014
Programming
7.6k
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Don't Commit Your Secrets
How to keep your application secrets safe
Nicholas Henry
June 17, 2014
More Decks by Nicholas Henry
See All by Nicholas Henry
Mise en Place for Ecto
nicholasjhenry
0
49
Beyond Mocks - Messing with Our Preconceptions of Testing
nicholasjhenry
0
48
Preventing Brain Freeze: Onboarding New Developers with Living Documentation
nicholasjhenry
0
140
The Upside Down Dimension of Elixir - ElixirConf
nicholasjhenry
0
36
The Upside Down Dimension of Elixir - An introduction to metaprogramming
nicholasjhenry
1
260
Building the Montreal Elixir Community
nicholasjhenry
0
64
How Elixir is Transforming My Mind
nicholasjhenry
1
6.7k
Modeling on the Right Side of the Brain
nicholasjhenry
1
9.8k
Other Decks in Programming
See All in Programming
設計次第でAIコードの読む量は減らせる / designing-for-code-reading
minodriven
29
13k
AWSに止められる覚悟してますか?
morizo_1984
2
490
JPUG勉強会 OSSデータベースの内部構造を理解しよう(第2回)
oga5
0
280
thread_parallel_with_free-threaded_Python_and_NumPy.pdf
riku_sakamoto
0
370
Augmenting AI with the Power of Jakarta EE
ivargrimstad
0
350
iOSDC Japan 2026 - Swiftで作って学ぼう!データベース自作入門
kaseken
2
410
大喜利で理解するLLM as a Judge / Understanding LLM-as-a-Judge through Ogiri
rockname
0
180
IBM Bob Dojo #1 仕様駆動開発入門
oniak3ibm
PRO
0
320
KiroのSpecで「五目並べ」を作ってみる
satoshi256kbyte
1
310
App Intentsのビルドプロセスを支える技術
kntkymt
0
480
AgentCore CLI で進化した AWS での AI エージェントの作り方 : 必要な機能を必要な時に
icoxfog417
PRO
4
400
iOSDCのペンライトを自動制御したい!
akkeylab
0
230
Featured
See All Featured
AI Search: Implications for SEO and How to Move Forward - #ShenzhenSEOConference
aleyda
1
1.4k
Building AI with AI
inesmontani
PRO
1
1.3k
KATA
mclloyd
PRO
35
16k
個人開発の失敗を避けるイケてる考え方 / tips for indie hackers
panda_program
123
22k
Ruling the World: When Life Gets Gamed
codingconduct
0
380
A Modern Web Designer's Workflow
chriscoyier
699
190k
ラッコキーワード サービス紹介資料
rakko
1
5.1M
HTML-Aware ERB: The Path to Reactive Rendering @ RubyCon 2026, Rimini, Italy
marcoroth
5
750
XXLCSS - How to scale CSS and keep your sanity
sugarenia
250
1.3M
The Language of Interfaces
destraynor
162
27k
New Earth Scene 8
popppiees
4
2.6k
Amusing Abliteration
ianozsvald
1
320
Transcript
Don’t Commit Your Secrets How to keep your application
secrets safe ! Nicholas Henry
Your secrets are everywhere • Passwords • Credentials • API
Keys • Database • Amazon S3 • Stripe • Mail Chimp Examples Synonyms
None
• Repository is shared among multiple parties • Increases your
risk for a security exploitation Why is this a bad practice?
• application is open source • application requires a high
level of governance e.g. financial, healthcare • application involves transient contractors e.g. agency • application located on multiple services e.g. CodeClimate When is this a bad practice?
When is this a bad practice? ALWAYS!
• Environment Variables • Configuration files Your options
Environment Variables # setting environment variable export STRIPE_API_KEY=07bfb7a5487dc6df" # retrieving
from Ruby ENV[‘STRIPE_API_KEY’] # =>07bfb7a5487dc6df
1 # config/application.yml" 2 " 3 production:" 4 secret_key_base: 33619eed953400c0e58695"
5 stripe_api_key: 07bfb7a5487dc6df Configuration File
• Rails 4.1 application • Deploy to Heroku Platform as
a Service (PaaS) • Configure Stripe with an API key Payment Gateway Demo
• configuration file / environments variables • config/secrets.yml" • Rails.application.secrets.your_api_key
Rails helps us keep secrets safe
None
Review 1 # config/secrets.yml" 2 " 3 production:" 4 secret_key_base:
<%= ENV[‘SECRET_KEY_BASE’] %>" 5 stripe_api_key: <%= ENV[‘STRIPE_API_KEY’] %> 1 2 3 heroku config:add STRIPE_API_KEY=montreal.rb-prod 1 # config/initializers/stripe.rb" 2 " 3 Stripe.api_key = " 4 Rails.application.secrets.stripe_api_key
• Don’t commit your secrets • If you have committed
your secrets: • setup your application to use environment variables or a configuration file • reset your API keys and other secrets Remember
nicholas@firsthand.ca @nicholasjhenry Nicholas Henry http://blog.firsthand.ca