API integrations are making the internet less secure (opinion piece)
evervault.com
evervault.com
Anyone have a good measure for how frequently this should be done? Too frequently is too much toil and infrequently is a security risk.
All keys should at least be refreshed once a year. At least.
It's worth mentioning that refreshing keys could also introduce security risks if you don't have a defined process. For instance, if an engineer is consistently emailing new keys to another engineer, that's probably (most definitely) a bad idea.