logoalt Hacker News

ZiiSyesterday at 10:06 AM2 repliesview on HN

Unrestricted API keys were always secrets. They are created on a page called "Keys & Credentials". The fact that Google even allows unrestricted keys to be created has been a long standing security problem. The fact their docs encouraged it remains unforgivable.


Replies

abustamamyesterday at 1:48 PM

I can maybe understand unrestricted keys (OK, I can't, to be honest).

But the fact that permissions are not hardened at time of creation is bonkers to me.

ceejayozyesterday at 11:22 AM

Public keys are a thing in computing, though?

Google Maps has one, even. And Stripe.

show 2 replies