DEV Community

Discussion on: What actually happens when you leak credentials on GitHub: The experiment

Collapse
 
jankapunkt profile image
Jan Küster

Check out this great resource for API best practices to help prevent a data breach in the future.

It's not listing two-factor authentication. Is there a reason why?

Collapse
 
advocatemack profile image
Mackenzie • Edited

I guess 2FA more fall towards credentials and not so much API tokens. But if you consider other objectives from a zero-trust framework IP whitelisting is considered in the article.