A public apology to everyone in @onelovedtube. (Lesson to all open source developers)
First of all, a huge thank you to the leaders here at #onelovedtube for the swift action of securing our accounts, and an apology of what I have done lately.
Here's the story:
A few days ago I was working to get the !feedback command to work flawlessly. When I was fixing the emoji issue that caused an error when saving to our MySQL database, I had to fix one line of code in the config file.
Here comes my huge silly mistake:
I made the changes right on our live curation bot, and pushed the commit to GitHub straight from our server.
I did not realise that I have committed all the passwords and private keys involved that make the curation bot work. The keys were literally out there on the GitHub repo for 2 days before I noticed my mistake and took appropriate action to change the keys (plus our database password and Discord curation bot token).
A message to all open source developers
As you saw above, this was a massive key leak. So please (especially when you are working on a repo that involves keys/auth tokens/passwords), every time you make a commit to any open source repositories, always check if anything sensitive have been accidentally included in the commit before pushing it to a remote git repository. Or else you could have your funds stolen or even compromise the entire account.
Luckily no damages have been noticed so far from this leak, so we're safe at least for now.
As always, thank you for your love and support that you have kindly provided here on the Steem blockchain. All rewards from this post will be powered up in full to @onelovedtube account.
@techcoderx
Administrator at #onelovedtube