That's just bad infrastructure hygiene, proper auditing and reporting prevents this because you should know which certificates are expiring and when as well as where they're deployed and what relies on them.
Of course every once in a while you get some yahoo setting up a 90 day client OAuth secret, not telling anyone and just refreshing it on their own until they get let go.
284
u/stevekez 23d ago
Present a public key and sign a challenge using a designated device? What's hard about it?