Keep Secrets Out of Code
Store credentials safely, not in plain text.
What Counts as a Secret
WiFi passwords, API tokens, and private keys are all secrets. Anything that grants access must never sit in plain sight inside your sketch. 🔑
The Danger of Plaintext Keys
Flash memory can be read back over the wire. A plaintext key in your code is one chip dump away from being copied by anyone.
String apiKey = "AKIA12345SECRET"; // visible to anyone who reads the flashAll lessons in this course
- Common IoT Attack Surfaces
- Keep Secrets Out of Code
- Encrypt with TLS & Verify Certs
- Sign & Lock Down Firmware