Live data from Hacker News

€54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

discuss.ai.google.dev

121–130 of 325 posts

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#121
post #105

Earlier quoted context omitted.

The problem is it's specific to that API and defaults to uncapped so people who aren't using it and haven't heard about the issues with the Firebase API keys probably won't have set them.

Except that Google's own statements are extremely clear that "leaked" (i.e. public) API keys should not be able to access the Gemini API in the first place: "We have identified a vulnerability where some API keys may have been publicly exposed. To protect your data and prevent unauthorized access, we have proactively blocked these known leaked keys from accessing the Gemini API . ... We are defaulting to blocking API…

There are other vectors, e.g. a compromised GCP key leading to $13k in Gemini charges (posted 3 days ago) https://www.reddit.com/r/googlecloud/comments/1sjzat3/api_ke...

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#122

I think the logistics of calculating cost in real time is something that is extremely hard. I don't think there is one big cloud service provider that has hard limits instead of alerts. As long as they revert the charge when notified of scenarios like this , and they have historically done so for many cases, it's fine. It's an acceptable workaround for a hard problem and the cost of doing business ( just like Credit…

> I think the logistics of calculating cost in real time is something that is extremely hard.

What makes you think that?

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#123
post #118

Earlier quoted context omitted.

I know you're well within your rights to post this, but would you consider replacing your comment with something like "It's easy to find working keys on github if you search the appropriate terms"? Think of it this way: although you're not to blame, HN drives a lot of traffic to your preconfigured github search. There are also bad actors who browse HN; I had a Firebase charge of $1k from someone who set up an automat…

I'm not opposed to even removing the comment outright. That being said, GitHub does not even offer a time sorted search. Meaning that most of the results are going to be quite old and useless. Second, API keys being shared on GitHub is quite an old problem. People setup automated scans for this sort of stuff. Me removing my comment isn't going to help anyone who already posted their API key online.

I tried several dozen keys and they're all invalid, so I'm inclined to agree with you for this particular case. Thank you anyway for considering.

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#124

Forgive my ignorance - but what's the payoff for fraudsters in getting access to a generative AI service for a short-ish period of time, before they get cut off? With EC2 / GCC credentials, I could understand going all out on bitcoin mining - but what are they asking the AI to do here that's worth setting up some kind of botnet or automation to sift the internet for compromised keys?

Early Generative AI was popular with spammers before it became mainstream because it could be used to write infinite variations of spam messages. Making each message unique is more likely to bypass spam filters.

There are also a lot of AI use cases that require a lot of token spend to brute force a problem. Someone might want to search for security exploits in a codebase but they don’t want to spend the $50,000 in tokens from their own money. Finding someone’s key and using it as hard as possible until getting locked out could move these projects forward.

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#125
post #81

Earlier quoted context omitted.

Which cloud provider actually prioritises features that cut off your money supply? Because AWS sure as shit doesn't either.

Amazon, Microsoft and Google don't offer hard cap. Most other/smaller public cloud providers do. The reasons are quite obvious.

we love Amazon, Microsoft and Google being altruistic and making sure your not burdened with too much money

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#126

I think the logistics of calculating cost in real time is something that is extremely hard. I don't think there is one big cloud service provider that has hard limits instead of alerts. As long as they revert the charge when notified of scenarios like this , and they have historically done so for many cases, it's fine. It's an acceptable workaround for a hard problem and the cost of doing business ( just like Credit…

Cutting off at the exact cent is difficult, but a hard limit that triggers within one dollar of the actual limit should really be possible

If for some resources you can't sample measurements fast enough you could weaken it to "triggers within one dollar or five minutes after cost overrun, whichever comes later". But LLM APIs are one of those cases where time isn't a factor, your only issue is that if you only check quota before each inference a given query might bring you over

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#128
post #113
post #59

Earlier quoted context omitted.

Google's world. They explicitly tell you that API keys are not secrets. https://trufflesecurity.com/blog/google-api-keys-werent-secr...

API keys for Firebase . While Google really messed up here, I doubt they ever published anything claiming that no Google API keys at all are secrets.

Google Maps is not Firebase.

And "Firebase AI Logic" sure sounds like something easy to confuse with a Firebase service...

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#130

Can you pre-load money into your account and have that be used until it's zero, at which time you have to load more? Deepseek does it this way.

Google doesn't allow disconnecting credit card from account unless you close it. That includes situation when you are just trying out free tier.

Does Google allow a privacy card that you can control whether an account is connected to it or not? That wouldn't help if someone racked up a ton of charges and Google bills daily, though.
Post reply on HN