> you checked keys into git. Both horrible practices.
Hey! That's not very kind to disparage everyone using a text file in a git repo to manage their passwords/keys.
Putting keys into a git repo is fine! But be careful when publishing that repo, as something you thought was private could suddenly become public.