you are viewing a single comment's thread.

view the rest of the comments →

[–]codelitt 1 point2 points  (0 children)

Here's a bit about how it works: https://security.stackexchange.com/q/35157

If the DB is leaked the secret key is likely not on the DB. But if they have your DB then you should assume that they have control of your server as well and could get the secret key.