HN user

AlwaysNewb23

201 karma
Posts47
Comments58
View on HN
www.doppler.com 1y ago

Why software engineers are resistant to change

AlwaysNewb23
2pts0
www.doppler.com 1y ago

Write Better Blog Content for Software Engineers

AlwaysNewb23
2pts0
www.doppler.com 1y ago

Secrets Management Mistakes Developers Make

AlwaysNewb23
2pts0
news.ycombinator.com 1y ago

Ask HN: What software dev skill has helped you the most?

AlwaysNewb23
3pts5
news.ycombinator.com 1y ago

Ask HN: What's the most unique job perk you've had?

AlwaysNewb23
26pts27
www.doppler.com 1y ago

How to Create Good Documentation

AlwaysNewb23
1pts0
news.ycombinator.com 1y ago

Ask HN: What does engineering leadership typically do wrong?

AlwaysNewb23
13pts17
news.ycombinator.com 2y ago

Ask HN: What developer tool has the best website?

AlwaysNewb23
1pts3
news.ycombinator.com 2y ago

Ask HN: Could Cloudstrike ever regain customer trust?

AlwaysNewb23
2pts2
news.ycombinator.com 2y ago

Ask HN: Do you review the security of imported code?

AlwaysNewb23
3pts0
news.ycombinator.com 2y ago

Ask HN: How do you balance security with fast development?

AlwaysNewb23
2pts2
withinboredom.info 2y ago

Classifying Pull Requests to Enhance Effectiveness

AlwaysNewb23
1pts0
news.ycombinator.com 2y ago

Ask HN: Does Compliance Equate with Security?

AlwaysNewb23
3pts3
theconversation.com 2y ago

Self-healing material for cosmic ray damaged satellites

AlwaysNewb23
3pts0
www.scmp.com 2y ago

Can we preserve the first footprint on the moon?

AlwaysNewb23
5pts0
www.doppler.com 2y ago

A Developer Cheat Sheet for GDPR

AlwaysNewb23
1pts0
www.florianbellmann.com 2y ago

If Processes Don't Create Ownership, What Does?

AlwaysNewb23
1pts0
news.ycombinator.com 2y ago

Ask HN: How do you explain LLMs to those *still* unfamiliar?

AlwaysNewb23
10pts20
www.codium.ai 2y ago

Navigating Roles and Responsibilities in a Good Software Testing Team

AlwaysNewb23
1pts0
research.ibm.com 2y ago

IBM Open Sources Its Granite AI Models

AlwaysNewb23
2pts1
www.doppler.com 2y ago

Good Things to Know Before Using Open-Source Software

AlwaysNewb23
1pts1
www.doppler.com 2y ago

Best Practices for Source Control

AlwaysNewb23
1pts0
www.doppler.com 2y ago

Fixing Our Broken Backlog Process

AlwaysNewb23
1pts0
www.doppler.com 2y ago

Should You Use Comment Prefixes for Code Reviews?

AlwaysNewb23
1pts0
www.doppler.com 2y ago

Using Narrative Commits for Better Code Reviews

AlwaysNewb23
1pts1
www.doppler.com 2y ago

Improving Code Reviews with Storytelling

AlwaysNewb23
2pts0
news.ycombinator.com 2y ago

Ask HN: What would make you trust a cloud solution over on-prem?

AlwaysNewb23
2pts3
readfromdisk.substack.com 2y ago

Parasitic Engineers Among Us

AlwaysNewb23
1pts0
news.ycombinator.com 2y ago

Ask HN: How do you get developers to trust your product?

AlwaysNewb23
2pts6
www.doppler.com 2y ago

Mobile Devs – Stop leaking your API keys: There's a better way

AlwaysNewb23
4pts2
[dead] 2 years ago

Good point. I'm going to trim some of the fluff off of that tldr.

We've been using commit messages to tell a story using our git history and it's improved our code review process. By doing this, we've created a commit history that clearly details all the steps leading up to each change. By organizing our commits this way, we’re making our PRs easier for others to understand and giving ourselves a chance to refine our work. We also often spot opportunities to simplify or improve the code that we might have missed the first time around.

I've always liked this model for my own projects. However, I'm not sure it really builds trust, especially from a security standpoint. Open sourcing could mean more eyes on the code, potentially leading to better security through community audits. Yet, it also means exposing the inner workings to everyone, including those with malicious intent. A hosted version does offer a layer of professional oversight, which is reassuring, but I wonder about the implications for users who opt for the self-hosted route. How would you ensure they feel confident in the security and reliability of the software, knowing that they have the same access to the code as anyone else?

I would love to hear more thoughts on balancing these aspects to build and maintain trust with users.

Tracking for you and your team. So if a developer on your team goes rogue, you know when and what happened, just like how you can see who committed when and what on GitHub.

Your backend is as secure as you make it. The critical point is that if designed properly, this method is better than directly storing and using API keys from within your app.

I can assure you that another Software Engineer at Doppler and I wrote this blog - not AI. Feel free to ask anything. Thank you for the feedback.

Doppler (https://doppler.com) is my preferred tool for storing API keys. It centralizes where you manage all of your environmental variables and makes it so you never risk exposing your API keys in a code repo. There's a CLI tool that makes it easy to use all of your environment variables while you're developing and a ton of integrations for wherever you prefer to deploy your code. Feel free to ask me anything about Doppler or secrets management - I'm a developer advocate at Doppler.

Are you familiar with the recent Mercedes-Benz Source Code Exposure [1]? It's a good example of why you should consider a secrets manager for any serious project. Environment variables come with a lot of risks and are difficult to manage as teams grow. 1) ENV files are easy to accidentally push to a repo. 2) It's easy for environment variables to get out of sync among developers. 3) In the case of exposure, it's often difficult to rotate secrets quickly. A secrets manager removes this risk - but you do need to trust whatever service you decide to use, as well as make sure it's compatible with your infrastructure/cloud environment.

[1] https://www.doppler.com/blog/lessons-from-mercedes-benz-sour...)

A secrets management service would be most convenient. Documentation makes them easy to set up without having to build anything extra yourself. A secrets manager like Doppler (https://Doppler.com) or AWS Secrets Manager (https://aws.amazon.com/secrets-manager/) has the advantage of protecting your secrets in a secure place and the advantage of minimizing exposure of those secrets - even to your own developers. That way, you don't end up with a data breach that could have easily been avoided. These types of leaks can cost companies everything and are becoming way more common.

Yes- More people need to know secrets managers exist and the types of problems they solve. I'm passionate about helping people discover and understand what secrets managers do. Using any secrets manager would be better than none at all - it does not need to be our solution as there are plenty to consider.

It seems like they made a lot of assumptions that something like this wouldn't happen. They assumed employees would never leak secret information, and that their GitHub repos would never be exposed. They could've used https://doppler.com or AWS Secrets Manager (https://aws.amazon.com/secrets-manager/) and never had this problem. It's a little too easy to get comfortable thinking things work well the way they are. This should be a warning to other companies to seriously evaluate how they're storing and managing application secrets and credentials.