Remix.run Logo
securesaml 5 hours ago

it is less of a problem for revoking attacker's keys (but maybe it has access to victim's contents?).

agreed it shouldn't be used to revoke non-malicious/your own keys

nebezb 3 hours ago | parent [-]

The poster you originally replied to is suggesting this for revoking the attackers keys. Not for revocation of their own keys…

securesaml 3 hours ago | parent [-]

there's still some risk of publishing an attacker's key. For example, what if the attacker's key had access to sensitive user data?

avarun an hour ago | parent [-]

You are AI. Stop commenting.