|
|
|
|
|
by noodletheworld
33 days ago
|
|
There is no such thing as please be careful when revoking tokens. What does that mean? Dont revoke them? Look at them carefully before revoking them? And what? Just let the actor just keep using them to spread to other people? Always rotate your tokens immediately if they're compromised. If it hurts, well, that sucks. …but seriously, not revoking the tokens just makes this worse for everyone. A fair comment would have been: “it looks like the payload installs a dead-mans switch…” Asking the maintainers not to revoke their compromised credentials deserves every down vote it receives. |
|