Try English LT! for engineers 第10回
2024.03.18
WaTTson
Slide 2
Slide 2 text
2
Slide 3
Slide 3 text
3
Rookie
@senpai plz help me! I'm stuck at this step....
screenshot.png ▼
Slide 4
Slide 4 text
4
Rookie
@senpai plz help me! I'm stuck at this step....
screenshot.png ▼
Senpai
Oh, be careful! Your personal access token is visible in the screenshot
😱
secret:wJalrXUtnFEMI/K7MDEN
G/bPxRfiCYEXAMPLEKEY
Slide 5
Slide 5 text
5
Senpai
I dedicate this song for you:
"Do not Post Credentials on Slack" High School Song ▼
YouTube
Slide 6
Slide 6 text
"Do not post credentials on Slack" High School Song
2024.03.18
Slide 7
Slide 7 text
7
2022.4 joined freee K.K.
PSIRT: product security incident responce team
WaTTson
PSIRT
Takeshi Tokunaga
プロフィール画像の
トリミング⽅法
Slide 8
Slide 8 text
8
freee K.K.
Empower Small Businesses
to Take Center Stage
accounting HR Tax filing
Founding Workload
management
Smart
ordening
Slide 9
Slide 9 text
9
Information assets
accounting
HR
● financial information
● accounting journal
● bank account information
● credit card statement
● employee personal information
● attendance
● payroll information
Slide 10
Slide 10 text
10
Protect information assets: trust boundary
S A
× ×
trust boundary
● not allow information to go outside the
boundary
● strictly control access to the information
✓
✓ ×
✓
Slide 11
Slide 11 text
11
Credential information
● user id
● secret id
● password
● client token
● access token
● secret token
● access key
● private key
etc....
Credential information must be treated
as securely as the information assets
which you can access with it
user id
**********
LOGIN
Slide 12
Slide 12 text
12
Rookie
@senpai plz help me! I'm stuck at this step....
screenshot.png ▼
Senpai
Oh, be careful! Your personal access token is visible in the screenshot
😱
# public_channel
secret:wJalrXUtnFEMI/K7MDEN
G/bPxRfiCYEXAMPLEKEY