Earlier quoted context omitted.
Not if its publicly called from Javascript, as your user's browser will make those requests. You neither know their IP addresses, nor is the referer or origin header a safe choice as it can be spoofed outside of a browser.
If it's called from Javascript in the browser, it's not a secret API key....
€54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
161–170 of 325 posts
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#162Earlier quoted context omitted.
This should be illegal. If a contractor your hired to swap out a tile on your bathroom floor billed you for remodelling your back garden, you would obviously have the legal right to refuse that.
Not if your contractor had you first sign a 15 page contract that commits you to whatever costs they dream up and requires forced arbitration by a corporate friendly firm when any dispute arises. Because that's somehow normal in today's tech world.
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#163We managed to catch it somewhat early through alerting, so the damage was only $26k.
We asked our Google cloud support rep for a refund - they initially came back with a no but now the case is under further consideration.
I’d escalate this up the chain as much as possible.
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#164With AI there is NO justification in NOT DOING IT BY YOURSELF. Why use firebase or if you can generate by yourself and deploy to hardware you own or rent.
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#165Considering the amount of repositories on public GitHub with hard-coded Gemini API tokens inside the shared source code ( https://github.com/search?q=gemini+%22AIza%22&type=code ), this hardly comes as a surprise. Google also has historically treated API keys as non-secrets, except with the introduction of the keys for LLM inference, then users are supposed to treat those secretly, but I'm not sure everyone got that…
> Google also has historically treated API keys as non-secrets, except with the introduction of the keys for LLM inference, then users are supposed to treat those secretly This was reported a long time ago, and was supposed to be fixed by Google via making sure that these legacy public keys would not be usable for Gemini or AI. https://news.ycombinator.com/item?id=47156925 https://ai.google.dev/gemini-api/docs/troubl…
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#166Earlier quoted context omitted.
> The Gemini API supports monthly spend caps at both the billing account tier and project levels. These controls are designed to protect your account from unexpected overages, and the ecosystem to ensure service availability https://ai.google.dev/gemini-api/docs/billing#project-spend-...
Why is the default uncapped then other than the hopes of billing people who screw up or get exploited.
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#167> We had a budget alert (€80) and a cost anomaly alert, both of which triggered with a delay of a few hours > By the time we reacted, costs were already around €28,000 > The final amount settled at €54,000+ due to delayed cost reporting So much for the folks defending these three companies that refused to provide hard spending cap ("but you can set the budget", "you are doing it wrong if you worry about billing", "ha…
Yet another good reason to use a pre-paid service. There are many to choose from now, like Openrouter.com, PPQ.ai, and routstr.com.
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#168Earlier quoted context omitted.
Why is the default uncapped then other than the hopes of billing people who screw up or get exploited.
See also: Why is the default cap so low? I lost €78bojillion because my API stopped working.
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#169Earlier quoted context omitted.
I'm with you. And what do you even do when the quota is breached, nuke the resources? People will complain about that just as much as overspends. I don't buy the 'evil corp screwing people' angle either. They are making farrr too much legit money to care about occasionally screwing people out of 20k and 50k.
If I set a limit, and you cut off my service because I reached the limit, I would definitely not "complain just as much" as if I set a limit and you allowed me to spend past it. We're not talking about an EC2 or EBS volume here, this is access to an API.
Why aren't we talking about an EC2 - is that not a cloud compute service? People have been complaining about cloud billing since long before LLMs.
Anything to say about the technical problem of constantly monitoring many services against a project or account-level limit?
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#170> We had a budget alert (€80) and a cost anomaly alert, both of which triggered with a delay of a few hours > By the time we reacted, costs were already around €28,000 > The final amount settled at €54,000+ due to delayed cost reporting So much for the folks defending these three companies that refused to provide hard spending cap ("but you can set the budget", "you are doing it wrong if you worry about billing", "ha…
Yeah, that the main reason I never use services like Google Cloud if I don't have to, it's impossible to have a hard cap, and anyone pretending to be an expert, is just off. Google says that they can't provide a hard cap because that would mean shutting down all your services..bla bla, but at least give users the option.
By default, new Tier 1 paid accounts can only spend $250 in a given month.