#tijs_api

1 messages ¡ Page 1 of 1 (latest)

civic ledgeBOT
#

👋 Welcome to your new thread!

⏲️ We'll be here soon! Typically we respond in a few minutes, but sometimes we might take a bit longer if the server is busy or if you have a particularly tricky question.

⏱️ We close idle threads, which makes them read-only. Once a thread is closed it won't be reopened, but you can always start a new thread if you have another question.

🔗 This thread will always be available, even after it's closed. You can find it again using Discord's search, or you can save this link: https://discord.com/channels/841573134531821608/1464261357854654671

📝 Have more to share? Add more details, code, screenshots, videos, etc. below.

thorn wind
#

Additional information: we received a similar email fro OpenAI 20min before the email from Stripe.

quartz meteor
#

Hey there, there are a number of source we check for this, both public and non-public and I can't say right now where this might have originated. I do see the email you're referring to so i suggest rolling the key ASAP.

#

If you find this does not resolve your issue, you can write in to support for guidance and investigation on the specific source we detection the leak from.

thorn wind
#

Thank you for your response. I saw the IP pointed to LA police departement, but i don't think they are trying anything :p

quartz meteor
#

I should hope not

thorn wind
#

the fact that somebody used the key might mean it was leaked publicly i suppose.
I'll look further into it. Thanks.

quartz meteor
#

Yes the email indicates we detected it publicly in this case, but I cannot see the source of that currently.

#

Most commonly this happens through accidental git commits in public repos

#

But there are other paths like insecure endpoints revealing env variable etc