The Django documentation suggests keeping the SECRET_KEY in environmental variables rather than in the settings.py file.
Why is this considered safer? The environmental variables are plain text-files which offer the same level of protection as settings.py. Even if the file rw permissions are set to root-only, I assume that this is not hard to break.
My question is: which other options are there to store the SECRET_KEY?
Or the master key used for encryption. From django-encrypted-secrets:
django-encrypted-secrets works by using a key (stored locally in master.key file or read from the environment variable DJANGO_MASTER_KEY) and reading/writing secrets to the encrypted file secrets.yml.enc.
If there is no other option than a plain text-file or environmental variable stored locally. How can this one be protected properly?