Live data from Hacker News

Google API keys weren't secrets, but then Gemini changed the rules

trufflesecurity.com

161–170 of 326 posts

Re: Google API keys weren't secrets, but then Gemini changed the rules

#161

Earlier quoted context omitted.

I had the same thought. I guess a lot of those keys may belong to dormant/deleted accounts and only a % of people who have enabled Gemini (presumably it required user action)

[flagged]

I did. Specifically the part about "When you enable the Gemini API". This doesn't take into account that people may have had years old forgotten about other services they use.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#162
post #114

Someone on the Google subreddit did report getting a 80k bill yesterday from a Gemini key. I’m very careful with Google and co since they’re so intent on infinite scaling access to your wallet

> Someone on the Google subreddit did report getting a 80k bill yesterday from a Gemini key.

Do you have a link?

Re: Google API keys weren't secrets, but then Gemini changed the rules

#163
post #114

Someone on the Google subreddit did report getting a 80k bill yesterday from a Gemini key. I’m very careful with Google and co since they’re so intent on infinite scaling access to your wallet

This and problematic Gemini pro availability are why I pay for two other ai services and won’t pay google.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#164

Earlier quoted context omitted.

> 95% of which will go towards paying your legal fees laughs in European

I laughed. No in europe when you win a case like this the judge usually forces the losing party to pay the legal expenses of the winner. Especially if the losing party is a big corporation.

It's the same in the US

Re: Google API keys weren't secrets, but then Gemini changed the rules

#165
post #114

Someone on the Google subreddit did report getting a 80k bill yesterday from a Gemini key. I’m very careful with Google and co since they’re so intent on infinite scaling access to your wallet

This and problematic Gemini pro availability are why I pay for two other ai services and won’t pay google.

About 10 years ago I got $100 for free to use on AdSense. I used it for fun not realizing it keeps going and then billed me. Since then I basically don't use any Google paid products. Hope that $250 was worth it.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#166

Earlier quoted context omitted.

Isn't there a limit to the number of projects you can make and then you have to ask support to increase it?

There is, yes. The rumor mill suggests that the default limit is 30. At $DAYJOB, we had a (not very special) special arrangement with GCP, and I never heard of anyone who was unable to create a project in our company's orgs [0]. Given how Google never, ever wants to have a human do customer support, I expect a robot will quickly auto-approve requests for "number of projects" quota increases. I know that's how it work…

Many products using the Cloud APIs auto-create projects. I know of AI Studio and Google Script (including scripts embedded in Docs, Sheets, etc)

So many organizations have the IAM "Project creator" role assigned to everyone at the org level. I think it's even a default.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#167
post #162
post #114

Someone on the Google subreddit did report getting a 80k bill yesterday from a Gemini key. I’m very careful with Google and co since they’re so intent on infinite scaling access to your wallet

> Someone on the Google subreddit did report getting a 80k bill yesterday from a Gemini key. Do you have a link?

https://www.reddit.com/r/googlecloud/comments/1reqtvi/82000_...

It’s pretty much a daily occurrence in all three of the big cloud subs that people still learning get wiped out because the clouds refuse to provide appropriate safeguards

Re: Google API keys weren't secrets, but then Gemini changed the rules

#168

Earlier quoted context omitted.

It's too structured and consistent. Imo. Has that AI smell to it, but I guess humans will eventually also start writing more like the AIs they learn from.

This is the first time I've seen people accuse AI text of being "too structured and consistent" compared to human text. Usually it's about specific patterns or tons of repetition or outright mistakes.

Patterns = consistent?

Re: Google API keys weren't secrets, but then Gemini changed the rules

#169
post #158

Earlier quoted context omitted.

It is not actually locked to a site is just based off the host header. Which is public information an attacker can use to make the requests.

Sure, but the practical form of this attack is limited. You can't maliciously embed it in a site you control to either steal map usage or run up their bill because other people's web browsers will send the correct host header. That means you can use a botnet or similar to request it using a a script. But if you are botnetting Google will detect you very quickly.

> But if you are botnetting Google will detect you very quickly.

They don't do anything against that.

Post reply on HN