PulseAugur
EN
LIVE 13:47:11

Google API keys remain active for 23 minutes after deletion

Security researchers have discovered a vulnerability in Google's API key management system. Deleted API keys can remain active for up to 23 minutes, potentially allowing unauthorized access. This loophole was identified by Aikido Security, who found that the keys continue to authenticate despite the Google Cloud UI indicating they have been removed. AI

IMPACT This vulnerability could expose sensitive data and systems to unauthorized access if not properly managed.

RANK_REASON Security researchers identified a vulnerability in a widely used cloud platform's API key management. [lever_c_demoted from research: ic=2 ai=0.4]

Read on The Register — AI →

AI-generated summary · Google Gemini · from 3 sources. How we write summaries →

Google API keys remain active for 23 minutes after deletion

COVERAGE [3]

  1. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    📰 Google API Keys Remain Active After Deletion Aikido Security found that deleted Google API keys can continue authenticating for a median of about 16 minutes a

    📰 Google API Keys Remain Active After Deletion Aikido Security found that deleted Google API keys can continue authenticating for a median of about 16 minutes and as long as 23 minutes, despite Google Cloud's UI claiming that once a key is dele... 📰 Source: Slashdot 🔗 Link: https…

  2. The Register — AI TIER_1 English(EN) ·

    Threat hunters find Google API keys still usable 23 minutes after deletion

    Plenty of time for bad actors to grab data or hit you with a giant bill

  3. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    A new study shows deleted Google Cloud API keys remain active for up to 23 minutes. Google closed the bug report as a "won't fix" system property. # Tech # Cybe

    A new study shows deleted Google Cloud API keys remain active for up to 23 minutes. Google closed the bug report as a "won't fix" system property. # Tech # CyberSecurity # GoogleCloud # AI # Development https:// blazetrends.com/google-api-key s-stay-active-23-minutes-after-deleti…