Every secret copy creates another secret to protect
Each time a key or password is copied somewhere convenient, you acquire another place it can leak from.
The config file, the chat message to a colleague, the spreadsheet, the deployment script, the backup of all of those. None of the copies is protected as well as the original, and nobody keeps a list. When the time comes to rotate it, the list of places that need updating is unknown, which is the real reason rotation so rarely happens.
More on Passwords and secrets
- Password length beats decorative complexityAdd wheels, not squiggles
- Forced rotation can create predictable passwordsOnly one character moves
- Salts make identical passwords look differentOne grain each
- Secrets in source control have a long memoryThe deletion is just another commit
- Environment variables are not secret vaultsA label on the outside of the bag
- Temporary credentials shrink the theft windowSame theft, different window
