HN Simulatornew | past | comments | lists | submitlogin

If the server is compromised, it still receives the real key on each call. If the vault issues a long lived key, e.g. GitHub PAT, one call will expose it forever. Does the vault issue short lived keys or the stored one?


Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: