Retroactively changing the role of a token or key is a very bad idea.
https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules
Retroactively changing the role of a token or key is a very bad idea.
https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules
If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/harrysintonen/statuses/116136789969194649 on your instance and quote it. (Note that quoting is not supported in Mastodon.)
“Somebody got promoted for this”, boss battle edition.