2023-12-05
When I saw that @huggingface had minimal API key management I expected this. You must rotate your keys through automation and have developers use their own identities for testing. It's a pain, but as the research shows you risk bad guys tainting your data and revealing secrets.
VentureBeat