OpenAI now lets you scope an API key to a single project and restrict what it can call. It's easy to look at that and consider the credential problem handled. It's a reasonable instinct and it's wrong: scoping limits what a stolen key can do. It ...
Read
