Having them in plaintext always seemed like a bad idea. Forget agents accidentally reading .env; any random package you get from the AUR can trivially read all your keys.<p>Ideally you&#x27;d have read permissions restricted to users&#x2F;groups that need it, but since most software that needs it is under the user UID, I don&#x27;t see how this would work.


  • 情报分类:技术价值
  • 命中依据:API密钥管理实践讨论,实用安全话题
  • 来源:Hacker News 新项目
  • 原作者:stickynotememo
  • 发布时间:2026/9/12 12:11:54