Despite countless frameworks, best practices, blog posts... so many developers still hardcode credentials into their code.