|
|
|
|
|
by pfg
3526 days ago
|
|
Revocation is also possible using the certificate's private key, but I agree that the risk of keeping the account key is not worth the hassle of deleting it straight away. As it stands, authorizations are valid as long as certificates, so the worst case is you're compromised on the 89th day of validity and get another certificate valid for the next 90 days. Soon, that'll be ~7 days, so even less of a concern. |
|
Why we were surprised (and we don't say the implementation is necessarily wrong!) is that I can use the account key anywhere. If the genuine user keeps refreshing authz's, it will keep the stolen account key operational as well.
That's my understanding. I may be wrong, but if so, I don't quite yet understand the logic behind authz.