Retroactively changing the role of a token or key is a very bad idea.
https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules
Retroactively changing the role of a token or key is a very bad idea.
https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules
@harrysintonen I keep going back to @soatok's stance of "if you say it's not a vulnerability then I publish immediately"
Their incompetent triage team should not be the security researchers' problem.