Live data from Hacker News

Google API keys weren't secrets, but then Gemini changed the rules

trufflesecurity.com

11–20 of 326 posts

Re: Google API keys weren't secrets, but then Gemini changed the rules

#12
Is the implication at the end that Google has not actually fixed this issue yet? This is really bad; a massive oversight, very clearly caused by a rush to get Gemini in customers' hands, and the remediation is in all likelihood going to nuke customer workflows by forcing them to disable keys. Extremely bad look for Google.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#13

Earlier quoted context omitted.

How do you know that this blog post was written by ChatGPT?

It's too structured and consistent. Imo. Has that AI smell to it, but I guess humans will eventually also start writing more like the AIs they learn from.

> guess humans will eventually also start writing more like the AIs they learn from.

With the AI feedback loop being so fast and tight for some tasks, the focus moves on to delivery than learning. There is no incentive, space or time for learning.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#14
post #13

Earlier quoted context omitted.

It's too structured and consistent. Imo. Has that AI smell to it, but I guess humans will eventually also start writing more like the AIs they learn from.

> guess humans will eventually also start writing more like the AIs they learn from. With the AI feedback loop being so fast and tight for some tasks, the focus moves on to delivery than learning. There is no incentive, space or time for learning.

Won't be well received here, but this is the truth.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#15
post #6

> Leaked key blocking. They are defaulting to blocking API keys that are discovered as leaked and used with the Gemini API. There are no "leaked" keys if google hasn't been calling them a secret. They should ideally prevent all keys created before Gemini from accessing Gemini. It would be funny(though not surprising) if their leaked key "discovery" has false positives and starts blocking keys from Gemini.

Yeah its tremendously unclear how they can even recover from this. I think the most selective would be: they have to at minimum remove the Generative Language API grant from every API key that was created before it was released. But even that isn't a full fix, because there's definitely keys that were created after that API was released which accidentally got it. They might have to just blanket remove the Generative Language API grant from every API key ever issued.

This is going to break so many applications. No wonder they don't want to admit this is a problem. This is, like, whole-number percentage of Gemini traffic, level of fuck-up.

Jesus, and the keys leak cached context and Gemini uploads. This might be the worst security vulnerability Google has ever pushed to prod.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#16

Earlier quoted context omitted.

How do you know that this blog post was written by ChatGPT?

It's too structured and consistent. Imo. Has that AI smell to it, but I guess humans will eventually also start writing more like the AIs they learn from.

AI was trained on human writing.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#18

Earlier quoted context omitted.

It's too structured and consistent. Imo. Has that AI smell to it, but I guess humans will eventually also start writing more like the AIs they learn from.

AI was trained on human writing.

And now humans are trained on AI writing.

Like what happens to YouTube videos that go through the compression algorithm 20 times.

Post reply on HN