Live data from Hacker News

Google API keys weren't secrets, but then Gemini changed the rules

trufflesecurity.com

141–150 of 326 posts

Re: Google API keys weren't secrets, but then Gemini changed the rules

#141

ChatGPT writing a blog post attacking Gemini security flaws. It's their world now, we're just watching how it plays out.

How do you know that this blog post was written by ChatGPT?

It's far longer than it needs to be because the writing process was too cheap.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#142
post #120

Earlier quoted context omitted.

First of all, Google is a shell of the company it used to be. That said, I’d actually argue there’s an evolutionary explanation behind this where at a certain size, and more importantly complexity, an oversight like this becomes even more likely, not less.

> First of all, Google is a shell of the company it used to be. Isn't that squarely at odds with Google's supposed AI prowess? Is the rot really so severe that their advances in AI (including things they've yet to make public) are insufficient to overcome it? Or are the capabilities of Gemini and AI systems in general being oversold?

… Of course they are being oversold.

But also, I don’t think even Google would claim that their LLM stuff can solve problems like this.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#143

Earlier quoted context omitted.

How do you know that this blog post was written by ChatGPT?

It's too well structured and the message is too clear. HN (and the whole internet) is allergic to proper writing. We praise human sloppiness now. No, I'm not being sarcastic. People have given up em-dash, which is an official punctuation you use in proper writing. And it's all a downhill from there.

Strongly disagree. The post is really poorly structured and circles the drain a few times getting to the thesis.

The issues of style are annoying, but I find it much worse to wade through these 3000 word posts which are far longer than they need to be just because they're so damn cheap to compose.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#144
post #138
post #83

In Google AI Studio, Google documentation encourages to deploy vibecoded apps with an open proxy that allow equivalent AI billing abuse - giving the impression that the API key were secure because it is behind a proxy. Even an app with 0 AI features exposes dollars-per-query video models unless the key is manually scoped. Vulnerable apps (all apps deployed from AI Studio) are easily found by searching Google, Twitter…

[flagged]

Sure, after 6 years in court you may get a settlement, 95% of which will go towards paying your legal fees.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#145
post #138
post #83

In Google AI Studio, Google documentation encourages to deploy vibecoded apps with an open proxy that allow equivalent AI billing abuse - giving the impression that the API key were secure because it is behind a proxy. Even an app with 0 AI features exposes dollars-per-query video models unless the key is manually scoped. Vulnerable apps (all apps deployed from AI Studio) are easily found by searching Google, Twitter…

[flagged]

Not illegal enough to worry about. nothing a peace board donation can’t fix.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#146

This is mind-blowing, and it defies all security common sense. Changing global API keys permissions? Come on! We’re accustomed to seeing issues like this from Redmond but didn’t expect it from Google.

Out of all of the cloud providers, I find Microsoft's authentication stack to be the most legible and stable. Everything else really sucks though.

You know things are bad when Microsoft is the most stable...

Re: Google API keys weren't secrets, but then Gemini changed the rules

#147

Earlier quoted context omitted.

First of all, Google is a shell of the company it used to be. That said, I’d actually argue there’s an evolutionary explanation behind this where at a certain size, and more importantly complexity, an oversight like this becomes even more likely, not less.

Another takeaway: if Google can become a shell of what it once was (in terms of institutional competence, I assume you mean; Alphabet market cap seems to be doing just fine), so can your organization. As such: making something that isn't supposed to be part of your security strategy, look like it could be , is actually a long-term security risk . Sooner or later a new team will not read your own documentation, and ju…

A thing I’ve learned about market cap in tech recently is that actually very little needs to get done on the core product. The momentum behind the brand is what carries the stock through time. The brand becomes its own compounding monetary instrument. Google had built a very very strong brand over the last 25 years or so. Only now is that starting to shift away from them. Because of that, I think we’ll start seeing them take more bold risks or they’ll be crushed by the weight of their own bureaucracy. This also tends to be the same reason startups can disrupt so swiftly.

An oversimplified version is this: So there are two core very critical components to the mid/late-phase tech megacorp strategy, you need to protect the core money printing product at all cost first and sustain that fiercely over a long period of time (decade+), then use any and all profits to find/fund the next cash cow, looking for optionality. While doing that, grow the market or consume a larger share of market. Google benefited from mainly the latter two and all while the internet blew up globally, funneling even more money into the machine.

It’s no secret that nearly every Google product that wasn’t search, lost them money. They were searching for the next big thing. They likely were some of the first to see AI as exactly that but moved too slowly to commercialize. Likely because of bureaucracy risk and also perhaps some sense of altruism in knowing the cataclysmic impacts AI could have. There have been plenty of former Google employees confirming this.

They also used to do things just to be cool, but those days have been long gone since Larry Page tapped out (and probably a few years before that, about a decade). Since then they’ve almost completely lost sight of what made them so successful that nobody even knows their vision or identity as a company today. These don’t correlate to market cap but they do silently lead to stagnation.

Their brand protects them from quite a lot but it’s not invincible.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#148
post #138

Earlier quoted context omitted.

[flagged]

Sure, after 6 years in court you may get a settlement, 95% of which will go towards paying your legal fees.

> 95% of which will go towards paying your legal fees

laughs in European

Re: Google API keys weren't secrets, but then Gemini changed the rules

#150

Earlier quoted context omitted.

Sure, after 6 years in court you may get a settlement, 95% of which will go towards paying your legal fees.

> 95% of which will go towards paying your legal fees laughs in European

I laughed. No in europe when you win a case like this the judge usually forces the losing party to pay the legal expenses of the winner. Especially if the losing party is a big corporation.
Post reply on HN