|
|
|
|
|
by progbits
54 days ago
|
|
If they had SSO sign in to their admin panel (trusted device checks notwithstanding) the oauth access would be useless. Vercel is understandably trying to shift all the blame on the third party but the fact their admin panel can be accessed with gmail/drive/whatever oauth scopes is irresponsible. |
|
If you can only fix one thing (ideally you'd do both, but working in infosec has taught me that you can usually do one thing at most before the breach urgency political capital evaporates), fix the Google token scope/expiry, or fix the environment variable storage system.