back
▲ 1 points

Ask HN: Has an API key issuer ever leaked their own customers’ API keys

by mathewpregasen·3y ago·1 comments·view on hn ↗
There’s been plenty of examples where API keys were leaked due to poor API key management, such as the Algolia or Mailgun report.

There are also examples where user data was compromised due to bad authentication rules or logic of an API

However, I’m curious if an API developer / issuer ever has leaked their own customers’ API Keys while their APIs security is otherwise airtight, I.e. Stripe leaking Stripe API Keys.

1 comments
Anything can end up in logs, then it depends on getting access to hosted splunk via employee creds, for a hypothetical breach.