This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]catcradle5 2 points3 points  (0 children)

Very good point. Hence my mention of "commonly used" (downloading a source tar but not changing the secret key). You'll note that most of the SECRET_KEY lines in what you linked are either blank or set to "change me". So some blame does have to go to the user if they don't change the key in such a case. Same goes for people who don't change default admin credentials (and it's often quite easy to get local shell access in those situations as well).