2 ms·
The person who leaked it and the person/team that can rotate it might be in different silos or timezones etc. Rewriting the history is prudent but not sufficien
by gghffguhvc 1y ago
The person who leaked it and the person/team that can rotate it might be in different silos or timezones etc. Rewriting the history is prudent but not sufficient.
- orthoxerox 1y agoThat's why key revocation, like credit card blocking, should be a separate service that is available 24x7. Like, if you know the value of an AWS token, this should be sufficient data for you to call an AWS API that revokes it.
- badmintonbaseba 1y agoThat doesn't help if revocation, without renewal means immediate outage.