Watched a guy pull a client's API key out of a frontend JS file at a coffee shop in Austin
Was sitting next to a dev at a coffee shop on South Congress last Tuesday and he was screen sharing, and I could see an API key just sitting in the page source of their checkout flow. He laughed it off, but three weeks later that same key was used to scrape 40,000 customer records, per the incident report his company posted. I'm not a security guy at all, I just build houses, but now I ask every contractor I hire how their booking tool handles keys before I hand over my info. Has anyone else started poking at the network tab on sites before typing in a card number?