Cloud keys
Long-lived cloud credentials leak through repositories, logs, build artefacts, screenshots and laptops.
They are valuable, portable and often over-permissioned, which is why scanning public code for them is an automated industry. The durable fix is not protecting them better but removing them: short-lived credentials issued to a workload leave nothing to find.
Checked against the primary source.
