That doesn't really sound like security best-practices would be applied. Why don't they use a credential store?
That doesn't really sound like security best-practices would be applied. Why don't they use a credential store?
- Too much red tape/risk assessments/effort/time required to set up a credential store
- Devs working there may not know/understand the importance of it, and may not be up-to-date with modern software development practices.
- Assumption that Github repo will always be private, correctly configured, never leaked.
- Assumption that employee computers with code checked out will always be full disk encrypted and source code never read by a malicious program/transmitted somewhere else.
If you work in a company that makes software for a living, it's worth bearing in mind you are probably nearer the forefront of modern best practices and there are many companies in other industries that do some software as part of, but not the main part of the product, and these do not necessarily focus on software development and therefore may be "as hot" with best practices, to put it mildly.
For what it's worth, there's some peace of mind in that this software is probably tested much more thoroughly than the average piece of Web software or whatever. Version control / security best practices / clean code may be too abstract for these old companies, but testing isn't. You'd hope.