private keys leaked?
miguelangel-dev opened this issue · 2 comments
miguelangel-dev commented
Even if these keys were used in the pilot, they should not be committed.
- RadarCovid/Supporting: pinning certs, and private keys are exposed here.
- RadarCovid/Config: endpoints together hardcoded pre/pro keys.
They have been compromised, so:
.gitignore
should be updated accordingly, adding these 2 rules, and removing the current ones.- Certs rotation should be done after reviewing Android app.
alvaro-octal commented
Both directories only contain public keys
miguelangel-dev commented
Yep, you are right, I have reviewed it again, and it seems to be public.