https://www.algolia.com/security.txt 404
I found 39 Algolia admin keys exposed across open source documentation sites
41–50 of 62 posts
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#42the wildest part is algolia just not responding. you email them saying "hey 39 of your customers have admin keys in their frontend" and they ghost you? thats way worse than the keys themselves imo. like the whole point of docsearch is they manage the crawling FOR you, but then the "run your own crawler" docs basically hand you a footgun with zero guardrails. they could just... not issue admin-scoped keys through that…
Why contact Algolia when it is the users' responsibility to handle their keys? Contact all the users.
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#43Twenty years ago every PHP website had search. We forgot how to do it.
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#44Twenty years ago every PHP website had search. We forgot how to do it.
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#45the wildest part is algolia just not responding. you email them saying "hey 39 of your customers have admin keys in their frontend" and they ghost you? thats way worse than the keys themselves imo. like the whole point of docsearch is they manage the crawling FOR you, but then the "run your own crawler" docs basically hand you a footgun with zero guardrails. they could just... not issue admin-scoped keys through that…
Why contact Algolia when it is the users' responsibility to handle their keys? Contact all the users.
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#46I have been developing an OpenClaw-like agent that automates exactly this type of attack.
Why? This is just regex search and there are plenty of tools that do this perfectly fine.
https://timesofindia.indiatimes.com/technology/tech-news/acc...
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#47Re: I found 39 Algolia admin keys exposed across open source documentation sites
#48Earlier quoted context omitted.
Yes, and in the real world where Grice's Maxim of Relevance is in force, then when the secrets issuer that is the subject of the discussion isn't one of those partners, then an informative "reminder" that GitHub "has a secret scanning program" with a bunch of other partners is not actually informative. It's as superfluous and unhelpful as calling to let someone know you're not interested in the item they've posted fo…
It's more useful than telling someone that their statement is a tautology in formal logic.
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#49the wildest part is algolia just not responding. you email them saying "hey 39 of your customers have admin keys in their frontend" and they ghost you? thats way worse than the keys themselves imo. like the whole point of docsearch is they manage the crawling FOR you, but then the "run your own crawler" docs basically hand you a footgun with zero guardrails. they could just... not issue admin-scoped keys through that…
Why contact Algolia when it is the users' responsibility to handle their keys? Contact all the users.
Re: I found 39 Algolia admin keys exposed across open source documentation sites
#50Earlier quoted context omitted.
It's more useful than telling someone that their statement is a tautology in formal logic.
No it's not.