Google API Key Issue Allows Deleted Keys to Retain Access to Cloud Services
#1
Exclamation 
Quote:Google Cloud API keys may continue functioning for up to 23 minutes after deletion, exposing a significant security gap that could allow attackers to retain unauthorized access to cloud services even after credentials are revoked.

Google API Deleted Keys to Retain Access

Security researchers from Aikido, led by Joe Leon, discovered that deleted Google API keys do not immediately lose access as expected. Instead, revocation propagates gradually across Google’s distributed infrastructure, creating a “revocation window” during which the key remains intermittently valid.

In testing across 10 trials, researchers observed:
  • Maximum revocation delay of approximately 23 minutes
  • Minimum delay of around 8 minutes
  • Median revocation time of roughly 16 minutes
During this window, authentication behavior was inconsistent. Some requests failed instantly, while others continued to succeed depending on which backend servers processed them. This inconsistency allows attackers with a leaked API key to continue making requests until all systems fully recognize the deletion.

Continue Reading...
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Mozilla Publishes Firefox Roadmap With N...
Mozilla has releas...harlan4096 — 10:18
Sysinternals Suite 6.17.2026
Sysinternals Suite ...harlan4096 — 10:00
AxCrypt 3.1.1.0
AxCrypt 3.1.1.0: ...harlan4096 — 09:57
Tor Browser 15.0.16
Tor Browser 15.0.1...harlan4096 — 09:56
Bitdefender 27.0.60.338
Latest version of ...harlan4096 — 09:54

[-]
Birthdays
Today's Birthdays
avatar (39)biobdam
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>