Search

Home > Talk Python To Me - Python conversations for passionate developers > #418: How To Keep A Secret in Python Apps
Podcast: Talk Python To Me - Python conversations for passionate developers
Episode:

#418: How To Keep A Secret in Python Apps

Category: Technology
Duration: 01:07:11
Publish Date: 2023-06-02 08:00:00
Description: Think about the different APIs and databases your application works with. Every one of them requires either an API key or a database connection string that itself contains a password. How do you let your application access this sensitive information without storing it in source code or putting in other compromising locations? We have Glyph Lefkowitz on the show to share his security fable as well as just good advice for keeping secrets out of Python code.

Links from the show

Glyph on Mastodon: @glyph@mastodon.social
ShhGit: github.com
Encrust: github.com
GitHub Security Alerts: github.com
CIA Triad: fortinet.com
pinpal: github.com
XKCD Authorization: xkcd.com
Tokenring: github.com
AWS Vault: github.com
Gimme-AWS-creds: github.com
Secrets in GitHub Actions: github.com
Python Client for HashiCorp Vault: python-hvac.org
Pomodouroboros app: github.com
DateType: pypi.org
Haveibeenpwned: haveibeenpwned.com
PEP 541: peps.python.org
Glyph's security talk at PyCon: us.pycon.org
Watch this episode on YouTube: youtube.com
Episode transcripts: talkpython.fm

--- Stay in touch with us ---
Subscribe to us on YouTube: youtube.com
Follow Talk Python on Mastodon: talkpython
Follow Michael on Mastodon: mkennedy

Sponsors
PyCharm
RedHat
Talk Python Training
Total Play: 0

Users also like

400+ Episodes
Lean Startup 700+     60+
5K+ Episodes
NHKラジオ .. 3K+     700+
200+ Episodes
Philosophize .. 1K+     70+
1K+ Episodes
Podcast Fran .. 1K+     100+
100+ Episodes
The React Po .. 20+     3

Some more Podcasts by Michael Kennedy

400+ Episodes
Python Bytes 60+     5