So, what happened with GitHub, Heroku, and those raided private repos?

Compromised AWS API key the root?

So, are we to read into this that somewhere in a repo on GH, someone had stored the AWS creds IN THE CODE?

Of course this happens all the time, even accidentally. Been there done that, got t-shirt.

Now, I feel I spend half my time barracking my fellow colleagues not to hardcode anything. AND THEY STILL DO IT.

We even got compromised because the creds were hardcoded somewhere.... AND THEY STILL DO IT!!

You can lead a horse to water, but you can't force it to drink,,,,,,,,

