3 ms·
Thank you for this. I will do that ASAP
by iyanuashiri 8y ago
Thank you for this. I will do that ASAP
- dwightgunning 8y agoJust a heads up (since I work at getstream.io) that you can easily and quickly rotate the Stream app key/secret via the dashboard. Feel free to contact our support or myself directly - dwight@getstream.io - if you need a hand.
- mynewtb 8y agoDo you have no process ready to rotate a user's exposed credentials? It's what I would expect from any service provider once they become aware of an exposure.
- patrickbolle 8y agoIsn't this exactly what he explained? The user has a easy toggle on their dashboard to rotate credentials - and if he needs a hand with it, contact their support for some help.
- detaro 8y agoI think the parents question was why they wait for the customer to do something instead of blocking/rotating the compromised credentials once they became aware of their existence. E.g. I remember reading that Amazon even scans Github for AWS credentials proactively now, since this happened all the time.
- badestrand 8y agoObviously they don't want to break their customer's production system without asking.
- e12e 8y agoTrue. It should be in the TOS that exposed api keys are subject to being revoked to prevent abuse. At least for certain services, and certain types of tokens.