Slashdot

News for nerds, stuff that matters

Google API Keys Remain Active After Deletion

Aikido Security found that deleted Google API keys can continue authenticating for a median of about 16 minutes and as long as 23 minutes, despite Google Cloud's UI claiming that once a key is deleted it can no longer make API requests. Dark Reading reports: Joe Leon, researcher at Belgian startup Aikido Security, recently analyzed the revocation window -- the time between a key's deletion and its last successful authentication -- for the cloud giant's API keys. In a blog post published today, Leon said Google Cloud Platform (GCP) customers expect API access to end immediately after the key is deleted, but this is not the case. In a series of tests, Leon found that the median revocation window was around 16 minutes, while the longest window was up to 23 minutes, "an incredibly long time" for API keys to continue authenticating successfully, he said.

And these windows have serious repercussions for organizations. "An attacker holding your deleted key can keep sending requests until one reaches a server that has not caught up. If Gemini is enabled on the project, they can dump files you have uploaded and exfiltrate cached conversations," Leon said. "The GCP console will not show the key, and it will not tell you the key is still working. You are trusting Google's infrastructure to eventually catch up."

[...] Leon tells Dark Reading the revocation windows for Google's API keys, as well as the unpredictable authentication success rates, complicate matters for incident response teams that are dealing with a potential breach. "This breaks the mental model IR teams have when responding to leaked credentials," he says. "It's assumed that when you click 'Delete' or 'Revoke' that the credential no longer works. Now IR teams need to remember that for GCP credentials, a window exists when that 'Deleted' credential still works for attackers."

To that end, Aikido recommended that security teams and IR personnel use a 30-minute window for Google API key deletions. Additionally, organizations should monitor their API requests by credential through the "Enabled APIs and services" portion of the GCP console, and review API requests by credential. "If you see unexpected usage from that credential after deletion, someone could be actively exploiting it," Leon wrote. Aikido reported the findings to Google, but the company closed the report as "won't fix," according to the blog post.

Read more of this story at Slashdot.

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Ukraine war briefing: Putin promises revenge after blaming Kyiv for Luhansk attack he says killed six

Ukraine dismisses Russian president’s claim, saying attack on dormitory in Russian-controlled region in the east ‘exclusively targeted the Russian war machine’. What we know on day 1,550

Russian President Vladimir Putin has blamed Ukraine for what he described as a deadly drone attack on a student dorm in Luhansk, a Russian-controlled region in eastern Ukraine, and has vowed to retaliate. Ukraine’s military denied the Russian accusations and said it had struck an elite drone command unit in the area. The Russian president said in a statement, carried by state TV on Friday, that he had ordered his military to prepare options to retaliate for the attack in Starobilsk that killed six people and wounded dozens, with 15 people still unaccounted for. He said Kyiv’s military must have known what it was targeting. At a UN security council emergency meeting called by Russia, Melnyk Andrii, the Ukrainian ambassador to the UN, rejeced his Russian counterparts’ accusations of war crimes, calling them a “pure propaganda show”. He added that the operations on Friday “exclusively targeted the Russian war machine” with strikes neutralising an oil refinery, “which was fuelling occupation forces, ammunition depots, air defence assets, and also command centres.”

The Czech president, Petr Pavel, has urged Nato to “show its teeth” in response to Russia’s repeated testing of the alliance’s resolve on its eastern flank, suggesting a range of options including switching off its internet, cutting off its banks from global financial systems and shooting down jets that violate allied airspace. Speaking to the Guardian in Prague, Pavel called for “decisive enough, potentially even asymmetric” responses to counter Moscow’s provocative behaviour against the alliance or risk the Kremlin intensifying its actions.

The UN’s nuclear watchdog said on Friday that Ukrainian authorities had advised that a fire had broken out at the Dniprovska 750-kilovolt electrical substation due to military activity, causing a nuclear power station to be partially disconnected from off-site power. The International Atomic Energy Agency said firefighters were tackling the fire but an operating nuclear power plant was partially disconnected from its off site power supplies at the request of the grid operator.

Falling debris from drones has triggered a fire at an oil terminal in Russia’s Black Sea port of Novorossiysk, injuring two people and damaging several technical and administrative buildings, officials said early on Saturday. The injured men had been in the street when the drones attacked the port and were being treated in hospital. Ukrainian forces on Friday also attacked a Russian oil refinery in Yaroslavl, about 700km from the border. The Ukrainian Defence Ministry said on X on Friday that Ukraine hit 11 Russian oil facilities this month as of 21 May, including Kirishi, one of Russia’s largest refineries.

Hundreds of Ukrainians have marched through Kyiv to demand that the government veto a bill they say could prematurely declare missing soldiers dead. The protest in Ukraine’s capital on Friday targeted Bill No. 13646 which addresses the legal status of missing persons. More than 90,000 people are listed as missing in Ukraine’s registry.

US troop numbers in Europe are expected to drop from 80,000 after a review reflecting wider commitments, US secretary of state Marco Rubio said on Friday. In Helsingborg, Sweden for a Nato foreign ministers meeting, Rubio said it was “well understood in the alliance that the United States’ troop presence in Europe is going to be adjusted … you know, we have obligations in the Indo-Pacific, we have obligations in the Middle East, we have obligations in the western hemisphere”. Last week, the Pentagon said it would halt the rotation of 4,000 more into Poland, only for Trump to apparently reverse that on Thursday night on social media, in a hasty announcement that appeared to catch the Pentagon by surprise.

A bipartisan group of US senators is pushing back on delays by the Department of Defense in sending about $600m in security aid to Ukraine and other allies in eastern Europe. They sent a letter to defense secretary Pete Hegseth on Friday that calls for the funding to be disbursed. Friction has grown between Congress and the Trump administration in recent weeks as lawmakers push for updates on what has happened to $400m in Ukraine aid and $200m more for defense programs in Estonia, Latvia and Lithuania that was allocated by Congress last year.

Continue reading...

ajpscs posted a photo:

the SQUARE
TOKYO DAY WALK
© ajpscs

Found Kodachrome Slide

Thomas Hawk posted a photo:

Found Kodachrome Slide

date stamped on slide August 1978

It Started Out With a Kiss

Thomas Hawk posted a photo:

It Started Out With a Kiss

I Did My Best

Thomas Hawk posted a photo:

I Did My Best

Formula 1 News

Formula 1® - The Official F1® Website

Russell ‘never doubted’ himself in return to Canada Sprint pole

George Russell secured pole position for the Sprint in Canada ahead of his Mercedes team mate Kimi Antonelli.

Lawson laments tough Friday in Canada after car issues

Liam Lawson admits that "I'm going to be playing catch-up" for the remainder of the Canadian Grand Prix weekend after mechanical issues prevented him from doing almost any running on Friday.

Norris reflects on Sprint Qualifying P3 after early worries

Lando Norris was pleased with his P3 result in Sprint Qualifying at the Canadian Grand Prix, with it coming just hours after McLaren appeared further off the pace during Free Practice 1.

Canada Sprint Qualifying ‘best I’ve felt all year’ – Hamilton

Lewis Hamilton ended Sprint Qualifying in Canada on a high despite losing out to McLaren at the last moment.