Live data from Hacker News

Google API keys weren't secrets, but then Gemini changed the rules

trufflesecurity.com

281–290 of 326 posts

Re: Google API keys weren't secrets, but then Gemini changed the rules

#281

Earlier quoted context omitted.

This is the first time I've seen people accuse AI text of being "too structured and consistent" compared to human text. Usually it's about specific patterns or tons of repetition or outright mistakes.

Patterns = consistent?

Patterns like heavy use of certain words or dashes or bullet points don't change how consistent the overall post is.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#282

Earlier quoted context omitted.

A good writer knows when to use literary techniques.

They work just fine in this post.

No, it’s unpleasant to read. To be clear, it’s possible a person wrote this, and that would not change it being unpleasant.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#283

Earlier quoted context omitted.

let's hope it happens soon, I'm pretty sick of this reality where companies get to charge you whatever they want and it's designed to always be your fault

> I'm pretty sick of this reality where companies get to charge you whatever they want and it's designed to always be your fault But have you considered it from the companies POV? Charging whatever you like and its always the customers fault is a pretty sweet deal. Up next in the innovation pipeline is charging customers extra fees for something or other. It'll be great!

This is just the utility model. It's nothing particularly nefarious. Consider what your electric utility, your water utility, etc. do. If you use more, you pay more. If someone comes around and hooks up a garden hose to your outside faucet and steals your water, or plugs an extension cord into your outside outlet and steals your electricity, you still pay. Unless you can catch the thief and make him pay.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#284
post #271

The headline really undersells the point and reads like clickbait. "Things were fine, then she turned the tables. Watch what happens next." I avoided even opening this article several times out of distaste for the headline. It should be something like "Google leaves your Gemini data vulnerable to non-secret API key exploit."

The headline states a plain fact that is critically important. It's not the writer's fault that the fact is outrageous.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#285

This seems so… obvious? How can a company of this size, with its talent and expertise, not have standardized tests or specs preventing such a blatant flaw?

Google does have a security review process on literally everything it launches. Which is what makes this so notable. Did the security review not catch this, or did they choose to launch anyways because it was too hard to fix and speed was of the essence?

Maybe the experienced security reviewers were laid off.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#286

Earlier quoted context omitted.

AdSense doesn't present itself as a permanent service you stay subscribed to. (Or at least didn't at the time I've tried to use it. That may have changed, but we don't know when the GP tried it either.)

It wasn't a subscription. My expectation was that it would simply stop once it hit $0. Not really here to argue about it. The tldr is I don't trust Google with this stuff anymore.

I wonder what you thought putting your credit card on file was for.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#287
post #229

Earlier quoted context omitted.

That is a nice excuse, do you work at Google? :) I get the idea of not slowing down requests or risking availability, but don’t tell me a company as big as Google can’t design an asynchronous accounting system robust enough to handle this. We’re not talking about penny-perfect precision - blocking at 110% or even 150% of the set cap would be enough. Right now, though, there’s nothing to prevent a $5k, 20k or even hig…

That’s exactly what the cloud function does

Yes but each admin has to use their product (cloud function), configure IAM and do that for every project. This is clearly just a work-around.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#288

What's frustrating is that a lot of these keys were generated a long time ago with a small amount of GCP services that they could connect to. (Ex. Firebase remote config, firestore, etc.) When Gemini came around, rather than that service being disabled by default for those keys, Gemini was enabled, allowing exploiters to easily utilize these keys (Ex. a "public" key stored in an APK file)

[dead]

Re: Google API keys weren't secrets, but then Gemini changed the rules

#289

Earlier quoted context omitted.

> I'm pretty sick of this reality where companies get to charge you whatever they want and it's designed to always be your fault But have you considered it from the companies POV? Charging whatever you like and its always the customers fault is a pretty sweet deal. Up next in the innovation pipeline is charging customers extra fees for something or other. It'll be great!

This is just the utility model. It's nothing particularly nefarious. Consider what your electric utility, your water utility, etc. do. If you use more, you pay more. If someone comes around and hooks up a garden hose to your outside faucet and steals your water, or plugs an extension cord into your outside outlet and steals your electricity, you still pay. Unless you can catch the thief and make him pay.

Funny enough, the utility business broadly wants to move away from this model to more of a cap-based prepaid model. Where I live, to get on the standard payment system may require a quite hefty deposit up front, but the prepaid payment option does not. I get the impression that, if not for customer sentiment and inertia, this would be the default option.

Re: Google API keys weren't secrets, but then Gemini changed the rules

#290
post #73

Earlier quoted context omitted.

If you've never worked in a large corporate environment you don't know how stupid things become. In a perfect bureaucracy nobody thinks.

I work at a Fortune 10. Things get stupid for sure. But I have never once seen “hey let’s do away with access controls for high-COGS services”.

It's never that explicit, it's more the things that nobody takes care of, because it's nobody's job. The bigger the company, the more jobs fall through the cracks, that should be taken care of, but lack an explicit role in the hierarchy.

There's usually a small handful of people that care more than they should, keeping the company afloat, but it's despite the company's policies, not because of them.

Post reply on HN