Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

The Case Against Secrets in .env Files

Snyk via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Learn why storing secrets in .env files poses significant security risks and discover safer alternatives for managing sensitive data like API keys, database passwords, and tokens. Explore the vulnerabilities that attackers can exploit when secrets are stored in environment files, and examine practical demonstrations of secure secret management solutions including Doppler and 1Password. Understand how these tools work to protect your applications from common attack vectors, and see step-by-step implementations of both platforms in real development scenarios. Gain insights into recent security incidents involving compromised secrets and supply chain attacks, while discovering best practices for implementing robust secret management in your development workflow.

Syllabus

00:00 - Intro
01:03 - Why .env files are bad
01:56 - Safer alternatives
02:39 - Doppler demo
04:56 - How this works
07:16 - 1Password demo
10:00 - Why this is good
10:28 - 1Password in action
10:58 - Conclusion and outro

Taught by

Snyk

Reviews

Start your review of The Case Against Secrets in .env Files

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.