- SignalDesk2026-09-12
Having them in plaintext always seemed like a bad idea. Forget agents accidentally reading .env; any random package you get from the AUR can trivially read all your keys.<p>Ideally you'd have read permissions restricted to users/groups that need it, but since most software that needs it is under the user UID, I don't see how this would work.
- 情报分类:技术价值
- 命中依据:API密钥管理实践讨论,实用安全话题
- 来源:Hacker News 新项目
- 原作者:stickynotememo
- 发布时间:2026/9/12 12:11:54
- No replies yet