Sharing .env files is so 2019.

Vancouver
"I'll sort out security when people start using it." You don't need to solve everything before launch. Start with one question: Which of my keys can access real data or spend real money?
7
Frontend = code running in your visitor's browser. Backend = code running on your server. Your OpenAI secret key belongs on the backend, not in the browser. That's the distinction to understand before connecting your first AI feature.
7
Your app works. Your payments work. Your AI feature works. But if someone asked where your secret keys are stored, could you answer? That's a useful thing to figure out before sharing the link.
5
Vibecoders: I built the app in an afternoon. Also Vibecoders: I would like an adult to explain the 14 API keys I collected along the way.
1
10
Appreciate people sharing mistakes like this. If a key reaches GitHub, revoke or rotate it first. Removing it from the latest file isn't enough to deal with copies in Git history. Fix the credential, then clean up the code.
This is too funny not to share. Back in 2018, just before the @OSHCutInc instant quoting app went live, I accidentally pushed our API keys to our private Github repo. I must have fixed it shortly thereafter, but the keys remained in our Git history. Anyway, our much more experienced software team just ran some security scans and it found the keys, with this commit message showing where the breach originated. "Switched to LIVE API KEYS!!!" lol Glad to have actual professionals running the team now. :-)
1
44
Before giving an AI tool access to your project, ask three questions: What can it read? What does it upload? Can you turn that off? Those answers should be clear before you connect it, not after someone investigates.
2
35
What recent breaches teach us about the new security reality: LiteLLM proved that AI gateways and proxies are prime targets for credential harvesting. Public Postman collections proved that testing tools leak live production keys daily. AI coding agents proved that fast prototyping leads to admin keys shipped in frontend bundles. You don't need a zero-day exploit to get breached. You just need one unencrypted credential in the wrong place.
5
5
105
Here's your daily reminder to never hand real credentials to prompt inputs.
1
4
67
28% of secret leaks don't even happen in git. They happen in slack, discord, telegram, and notion DMs. Stop sending production keys in chat. Share encrypted environment access instead: capy.sc
1
134
Over 1.27M model keys were pushed straight to public github in 2025. Stop pasting raw API tokens into local config files. Inject them with capy.sc
22
AI coding agents leak secrets at 3.2% of commits, which is more than double the 1.5% human baseline. Your agent is optimized to make the build pass, not keep your keys safe. Keep your backend credentials out of the prompt context : capy.sc
1
2
39
"we'll add proper secrets management before launch" Nobody has ever done this. Not once. Not in the history of software. Unless you actually remember. You add it now or you add it after the incident.
1
25
Happy Friday, here's our first edition of The Leak Report 🦫 What leaked this week, and what it should teach you. A thread ↓ 🧵
1
52
6/ what to actually do about it, in order of effort: - turn on github secret scanning + push protection (free, 5 min) - audit every key in every .env you own, rotate anything older than a year - stop keeping live credentials in files agents can read - give every credential a TTL oh btw, capy does the last two: capy.sc 😉
1
9
7/ This is the end of the thread. Only trust links posted by Capy.sc directly.
2