'You have no way to revoke it faster or confirm when it stops working': Experts find Google API keys are still…

https://cdn.mos.cms.futurecdn.net/F8GmZXNJTQZttVhvkvgpp9-2560-80.jpg
  • Aikido researchers find Google API keys remain usable for up to 23 minutes after deletion
  • Success rates varied across trials, with Gemini‑enabled projects especially vulnerable to stolen files and cached conversations
  • Google dismisses issue as propagation delay, but Aikido advises treating deletion as a 30‑minute window and monitoring for unexpected usage

If, when you delete a Google API key, expect it to no longer work - effective immediately - we have a surprise for you.

Researchers from Aikido found users can successfully authenticate up to 23 minutes after deletion, creating a gigantic security risk and a major opportunity for threat actors.

The worst part is that users have almost no way of knowing when the authentication window closes and can do absolutely nothing to speed it up.

"False statements"

In its report, Aikido described running 10 trials over two days, creating and deleting API keys while sending 3-5 authenticated requests...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more