Live API keys sitting in old .env files: a confession thread
A confession-style thread asked how many developers have live API keys and OAuth tokens sitting in .env files across old projects. The discussion exposes a gap in agent tutorials, which teach 'put your key in .env' and move on. Practical takeaways: rotate exposed keys immediately, use one key per project, and add pre-commit hooks to keep secrets out of git.