Couldn't auto-revokation be used for a "DOS" attack of sorts by generating a lot of randomized tokens and pushing them to any repo?
I realize that the search space is huge for many tokens types, but it seems viable.
I realize that the search space is huge for many tokens types, but it seems viable.
Other partner's secrets may be more susceptible.
Edit: I did not consider the paired access key which is another 70 or so bits. I think you'd need to collide on both to make someone have a bad day.
Writing millions of generated tokens to a text file and pushing them to Github is easy.
There is obviously no meaningful benefit to doing this, except potentially breaking some random deployments until they can replace the keys.