8 ms·
it is less of a problem for revoking attacker's keys (but maybe it has access to victim's contents?). agreed it shouldn't be used to revoke non-malicious/your
by securesaml 8mo ago
it is less of a problem for revoking attacker's keys (but maybe it has access to victim's contents?).
agreed it shouldn't be used to revoke non-malicious/your own keys
- nebezb 8mo agoThe poster you originally replied to is suggesting this for revoking the attackers keys. Not for revocation of their own keys…
- deleted 8mo ago[deleted]
- securesaml 8mo agothere's still some risk of publishing an attacker's key. For example, what if the attacker's key had access to sensitive user data?
- avarun 8mo ago[flagged]
- throwawaysleep 8mo agoAll the more reason to nuke the key ASAP, no?