Hacker News new | ask | show | jobs
by Groxx 616 days ago
You'd hopefully have access records to show which ones were accessed... but yea, all accessed secrets need to be rotated, not just the gateway-secret. And without that kind of record you need to assume "all".