Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Very briefly, secrets should have maximum lifetimes. This is for multiple reasons - someone could be brute-forcing it; algorithms are regularly found to be less secure than initially thought; keys leak over time.

Any secret protecting anything you care about should be rotated. The schedule is dictated by specifics.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: