If Heroku\'s .netrc file can be accessed by simply running
cat ~/.netrc
and exposing the tokens, how do they ensure that the tokens can\'t be