Tag

Environment Variables

All articles tagged with #environment variables

Vercel Breach Linked to Context AI Hack Exposes Limited Customer Credentials
technology1 month ago

Vercel Breach Linked to Context AI Hack Exposes Limited Customer Credentials

Vercel disclosed a security incident linked to the Context.ai compromise that allowed an attacker to hijack an employee’s Google Workspace account and access some non-sensitive internal environments and environment variables; sensitive secrets remained encrypted, but a limited subset of customers reportedly had credential exposure, triggering immediate rotation and ongoing investigations with Mandiant and Context.ai, as the company rolls out dashboard updates and advises admins to review logs and rotate non-sensitive secrets.

technology7 months ago

Rethinking Environment Variables: Addressing the Legacy Challenges

The article discusses the drawbacks and security concerns of using environment variables for managing secrets and configuration in software systems, emphasizing the complexity, lock-in, and potential leaks associated with various methods like vaults, config files, and Kubernetes secrets, and advocates for more secure, modern approaches such as dedicated secret management tools and systemd-creds.