|
|
|
|
|
by ncallaway
749 days ago
|
|
Which, like, if posting random keys has any realistic plausibility of collision, malicious revoking of keys is the least of your concerns. People could just hit important data fetch endpoints with random keys, until they find one that’s good, and then have a compromised account. |
|