Earlier quoted context omitted.
How do you know that this blog post was written by ChatGPT?
> The Core Problem > What You Should Do Right Now > Bonus: Scan with TruffleHog. > TruffleHog will verify whether discovered keys are live and have Gemini access , so you'll know exactly which keys are exposed and active, not just which ones match a regular expression. I don't know exactly, but I'm sure. The cadence, the clarity, the bolding, the italics, it's all just crisp and clean structured and actionable in a w…
Google API keys weren't secrets, but then Gemini changed the rules
191–200 of 326 posts
Re: Google API keys weren't secrets, but then Gemini changed the rules
#192I'm a bit surprised by the timeline which seems to say that: - 6 weeks ago Google said they would fix it - 3 weeks ago Google said they were working on it ...but we're publishing the info anyway, so everyone can go nuts with it.
Re: Google API keys weren't secrets, but then Gemini changed the rules
#193Earlier quoted context omitted.
It's too structured and consistent. Imo. Has that AI smell to it, but I guess humans will eventually also start writing more like the AIs they learn from.
This is the first time I've seen people accuse AI text of being "too structured and consistent" compared to human text. Usually it's about specific patterns or tons of repetition or outright mistakes.
Re: Google API keys weren't secrets, but then Gemini changed the rules
#194Earlier quoted context omitted.
I laughed. No in europe when you win a case like this the judge usually forces the losing party to pay the legal expenses of the winner. Especially if the losing party is a big corporation.
It's the same in the US
Re: Google API keys weren't secrets, but then Gemini changed the rules
#195Earlier quoted context omitted.
Really? I make multiple GCP projects per app. One project for the (eg) Maps API, one for Drive, one for Mail, one for $THING. Internal corp-services might have one project with a few APIs enabled - but for the client-app that we sell, there are many projects with one or two APIs enabled only.
If you ever have to enable public OAuth on such a project, you'll need to provide a list of all the API projects in use with the application, and Google Trust and Safety will pressure you to merge them together into a single GCP project. I've been through it. You can do what you're describing but it's not the model Google is expecting you to use, and you shouldn't have to do that. It seems what happened here is that…
Like deciding ATM cabinets should be default open to make it easier for people to withdraw cash.
No, there must be more behind this than overzealotry.
Re: Google API keys weren't secrets, but then Gemini changed the rules
#196Re: Google API keys weren't secrets, but then Gemini changed the rules
#197Earlier quoted context omitted.
That's... pretty much how every free trial works? Try signing up for a free month of Amazon Prime or Netflix and see what happens. The entire point of the promotion is retention.
AdSense doesn't present itself as a permanent service you stay subscribed to. (Or at least didn't at the time I've tried to use it. That may have changed, but we don't know when the GP tried it either.)
Re: Google API keys weren't secrets, but then Gemini changed the rules
#198Earlier quoted context omitted.
Another takeaway: if Google can become a shell of what it once was (in terms of institutional competence, I assume you mean; Alphabet market cap seems to be doing just fine), so can your organization. As such: making something that isn't supposed to be part of your security strategy, look like it could be , is actually a long-term security risk . Sooner or later a new team will not read your own documentation, and ju…
A thing I’ve learned about market cap in tech recently is that actually very little needs to get done on the core product. The momentum behind the brand is what carries the stock through time. The brand becomes its own compounding monetary instrument. Google had built a very very strong brand over the last 25 years or so. Only now is that starting to shift away from them. Because of that, I think we’ll start seeing t…
Re: Google API keys weren't secrets, but then Gemini changed the rules
#199Earlier quoted context omitted.
First of all, Google is a shell of the company it used to be. That said, I’d actually argue there’s an evolutionary explanation behind this where at a certain size, and more importantly complexity, an oversight like this becomes even more likely, not less.
Seems like they ought to be dedicated security teams monitoring for exactly this: does a key to X give users access to not-X. Even more bizarre is their VDP team not immediately understanding the severity of the issue.
Re: Google API keys weren't secrets, but then Gemini changed the rules
#200Earlier quoted context omitted.
[flagged]
I think the fact that it is not possible to put hard spending caps on API keys might be ruled illegal by some EU court soon enough, at least when they sell to consumers (given the explosion of vibecoding end-users making some apps). When I use OpenAI, Openrouter etc., I can put 10 $ on my API key, and when the key leaks, someone can use these 10 $ and that's it. With Google, there is no way to do that - there are ext…
On that note, I'll just mention that I had discovered over the last while that when you prepay $10 into your Anthropic account, either directly, or via the newer "Extra usage" in subscription plans, and then use Claude Code, they will repeatedly overbill you, putting you into a negative balance. I actually complained and they told me that they allow the "final query" to complete rather than cutting it off mid-process, which is of course silly, because Claude Code is typically used for long sessions, where the benefit of being cut off 52% into the task rather than 51% into it is essentially meaningless.
I ended up paying for these so far, but would hope that someone with more free time sues them on it.