dwyl / dwyl/learn-security

How To Securely Store/Manage (and Share) App Secrets?

Open
#43 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
No language data
Stars
66
Forks
10
PR merge metrics
No merged PRs in 30d

Description

Using Environment Variables [dwyl/learn-environment-variables](https://github.com/dwyl/learn-environment-variables) is a _good_ start for keeping secrets safe,
but how the secrets are stored and shared between the team (_where appropriate_) is often overlooked.

Most of the apps we build have _several_ environment variables, and in the case of **`AWS_SECRET_ACCESS_KEY`**, if these are "_leaked_" it can lead to breaches of personal data, which can lead to identity theft and other traumatic consequences for the people affected.
Where the Data of EU citizens is concerned, breaches have to disclosed/reported to the European Data Protection Supervisor and can result in a fine; it's a headache _nobody_ wants! Also, data breaches destroy the reputation of the organisation (_though apparently not in the case of [Fb](https://github.com/dwyl/learn-react/issues/23#issuecomment-475548772) ..._ 🙄🤦‍♂️)

# Todo

+ [ ] Create a step-by-step example of how to use AWS KMS (Key Management Service) to encrypt, store and retrieve secrets for a Web Application.

This appears to be a good post on the subject of managing secrets with AWS KMS:
https://segment.com/blog/the-right-way-to-manage-secrets
also: https://blog.ruanbekker.com/blog/2018/04/04/using-aws-ssm-parameter-store-to-retrieve-secrets-encrypted-by-kms-using-python/

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.