logoalt Hacker News

pcj-githubtoday at 2:59 AM2 repliesview on HN

Absolutely insane. Security so weak, it seems like you discovered an intentional backdoor.


Replies

cookiengineertoday at 3:33 AM

My NSL detector is off the charts here.

show 1 reply
otabdeveloper4today at 5:02 AM

> impersonation tokens, called “Actor tokens”, that Microsoft uses in their backend for service-to-service (S2S)

Literally every single "security" framework uses God-mode long-lived tokens for non-human identities.

(Except for SPIFFE, but that's a niche thing and used only for Kubernetes bullshit.)

The whole field of "security" is a farce staffed by clowns.

show 1 reply