Google API Key Issue Allows Deleted Keys to Retain Access to Cloud Services
#1
Exclamation 
Quote:Google Cloud API keys may continue functioning for up to 23 minutes after deletion, exposing a significant security gap that could allow attackers to retain unauthorized access to cloud services even after credentials are revoked.

Google API Deleted Keys to Retain Access

Security researchers from Aikido, led by Joe Leon, discovered that deleted Google API keys do not immediately lose access as expected. Instead, revocation propagates gradually across Google’s distributed infrastructure, creating a “revocation window” during which the key remains intermittently valid.

In testing across 10 trials, researchers observed:
  • Maximum revocation delay of approximately 23 minutes
  • Minimum delay of around 8 minutes
  • Median revocation time of roughly 16 minutes
During this window, authentication behavior was inconsistent. Some requests failed instantly, while others continued to succeed depending on which backend servers processed them. This inconsistency allows attackers with a leaked API key to continue making requests until all systems fully recognize the deletion.

Continue Reading...
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Kaspersky\VPN\KSOS 21.26 (MR26) & KES 1...
harlan4096 — 07:05
Audacity 3.7.8
Audacity 3.7.8 ...harlan4096 — 07:02
Google Chrome 149.0.7827.114/.115
Google Chrome 149....harlan4096 — 07:00
Microsoft Windows 11 Low Latency Profile...
Windows 11 June up...harlan4096 — 06:52
Microsoft: Windows 11 KB5094126, KB50939...
Windows June 2026 ...harlan4096 — 06:29

[-]
Birthdays
Today's Birthdays
avatar (40)Julioagopy
avatar (50)aolaupitt2558
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu
avatar (32)horancos

[-]
Online Staff
There are no staff members currently online.

>