Attention: You are using an outdated browser, device or you do not have the latest version of JavaScript downloaded and so this website may not work as expected. Please download the latest software or switch device to avoid further issues.

News > Attacks & Threats > Google API Keys Remain Active After Deletion

Google API Keys Remain Active After Deletion

A security researcher discovered the API keys can still be used for up to 23 minutes after deletion, even though the cloud provider claims deletion is immediate.

Google API keys aren't completely inactive after users delete them, giving attackers a small but significant window to continue abusing them.

Joe Leon, researcher at Belgian startup Aikido Security, recently analyzed the revocation window — the time between a key's deletion and its last successful authentication — for the cloud giant's API keys. In a blog post published today, Leon said Google Cloud Platform (GCP) customers expect API access to end immediately after the key is deleted, but this is not the case. More here

Similar Stories

Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face. More...

New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents. More...

A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are … More...

Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective. More...

A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning atta… More...

Have your say

 

News Categories

Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face. More...

New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents. More...

A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are … More...

Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective. More...

A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning atta… More...

image

Contact Us

Security Interest Group Switzerland
c/o Bridge Head AG
Sulzbergstrasse 34
5430 Wettingen
Switzerland

Follow Us

This website is powered by
ToucanTech