This implies the API calls originated in the client, suggesting the client may have had they API key.
€54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
11–20 of 325 posts
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#12i have seen this so many times... i'm thinking it's time we replaced api keys. some type of real time crypto payment maybe?
Prepaid only is a fantastic idea, especially for dumb-ass startups. Limiting your liability to $100 or so sound like a big-ass W.
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#13Considering that the author didn't share what website this is about, I'd wager they either leaked it accidentally themselves via their frontend, or they've shared their source code with credentials together with it.
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#14i have seen this so many times... i'm thinking it's time we replaced api keys. some type of real time crypto payment maybe?
Prepaid only is a fantastic idea, especially for dumb-ass startups. Limiting your liability to $100 or so sound like a big-ass W.
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#15[flagged]
And why do you need to use AI to tell us that. How much shorter could the prompt have been?
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#16That's fucking bonkers that nothing in the system could see this as unusual and worthy of throttling. The embarrassment of this -- that a company LITERALLY SELLING machine learning services and expertise -- cannot spot such a thing... This should have led them to deal with this internally and refund it. Just... Wow Google.
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#17It's super frustrating that this is the only option to realistically deal with this issue, since all stories end up the same way: The cloud company just saying "f* you, we don't care, pay up." and legal fees are always expensive :(
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#18i have seen this so many times... i'm thinking it's time we replaced api keys. some type of real time crypto payment maybe?
Prepaid only is a fantastic idea, especially for dumb-ass startups. Limiting your liability to $100 or so sound like a big-ass W.
No need to retire API keys.
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#19Earlier quoted context omitted.
Prepaid only is a fantastic idea, especially for dumb-ass startups. Limiting your liability to $100 or so sound like a big-ass W.
Prepaid only is a fantastic idea, until your site goes (desirably) viral and then gets shut off right as traffic is picking up, or you grow steadily and forget to increase your deposit amount and suddenly production is down. Billing alerts are a much better solution IMHO.
If you have per key limits, this is not possible, and even in a wild situation you should b able to expect that your firebase key will not use 50k.