Live data from Hacker News

Addressing Antigravity Bans and Reinstating Access

github.com

81–90 of 230 posts

Re: Addressing Antigravity Bans and Reinstating Access

#81
post #78

> Using third-party software, tools, or services to harvest or piggyback on Gemini CLI's OAuth authentication to access our backend services is a direct violation of Gemini CLI’s applicable terms and policies. It's been 2 months since these bans have started, first Anthropic, then Google. And their wording is still so confusing that I can't get a simple answer to a simple question: Is piggybacking on headless 'gemini…

I think the issue is people are using tools in an automated fashion and running up a compute bill for free when they were only meant to be used by humans in a more limited capacity (for companies to gather data on how to improve their products for humans). I think the correct way to use these models in an automated fashion is via the APIs and even then they might also worry about things like abuse/distillation type attacks still if the volume is too high. I think the lack of transparency might actually be by design so that people abusing their services don't figure out what triggers them losing their accounts. I could be wrong of course, this is just speculation on my part.

Re: Addressing Antigravity Bans and Reinstating Access

#82
post #38
post #8

Way too risky to use Google services like this tied to your primary account. There’s too much risk of cross damage. Imagine losing access to your Gmail because some Gemini request flags you as an undesirable. The digital death sentence of losing access to your email with a company that notoriously has no way for the average human to contact a human is not worth the risk.

Use a custom domain and don't use google for email. And if you do use your gmail address just forward it and start to transition to something else. With time everything of importance has been transferred.

There was a time back when we could get generic LoginWIth OAUTH butons along with the social media roster , allowing one to use whichever provider they wanted.

Current state of OIDC should be pretty much standard across most providers - it put it that devs need too make the push to support alt login providers for preventing vendor lockin in identity like were currently barreling towards in hardware/software.

Re: Addressing Antigravity Bans and Reinstating Access

#83
post #81
post #78

> Using third-party software, tools, or services to harvest or piggyback on Gemini CLI's OAuth authentication to access our backend services is a direct violation of Gemini CLI’s applicable terms and policies. It's been 2 months since these bans have started, first Anthropic, then Google. And their wording is still so confusing that I can't get a simple answer to a simple question: Is piggybacking on headless 'gemini…

I think the issue is people are using tools in an automated fashion and running up a compute bill for free when they were only meant to be used by humans in a more limited capacity (for companies to gather data on how to improve their products for humans). I think the correct way to use these models in an automated fashion is via the APIs and even then they might also worry about things like abuse/distillation type a…

> I think the issue is people are using tools in an automated fashion

But that's the sole reason why all of the tools have headless modes. Headless mode is textbook definition of supporting automation.

From gemini docs: [1]

> Headless mode allows you to run Gemini CLI programmatically from command line scripts and automation tools without any interactive UI.

And claude code:

> Use the Agent SDK to run Claude Code programmatically from the CLI, Python, or TypeScript

Why does headless mode exist if using it is a bannable offense?

[1] https://google-gemini.github.io/gemini-cli/docs/cli/headless...

[2] https://code.claude.com/docs/en/headless

Re: Addressing Antigravity Bans and Reinstating Access

#84
post #8

Way too risky to use Google services like this tied to your primary account. There’s too much risk of cross damage. Imagine losing access to your Gmail because some Gemini request flags you as an undesirable. The digital death sentence of losing access to your email with a company that notoriously has no way for the average human to contact a human is not worth the risk.

[deleted]

Re: Addressing Antigravity Bans and Reinstating Access

#85
post #11

Earlier quoted context omitted.

This wasn't due to some random Gemini request. Users were using sketchy antigravity auth plugins to use their antigravity tokens on things like OpenClaw, clearly against ToS. It's great that Google is giving these users a second chance.

It’s be great if Google just revoked antigravity access if terms were violated. No need to disable the entire account.

No Google account has been banned for this. People just keep spreading this lie because no one agrees that they have the right to steal the OAuth token.

Re: Addressing Antigravity Bans and Reinstating Access

#86

Earlier quoted context omitted.

Yes, our masters once again embarrass us unworthy peons with their endless grace, generosity and forebearance. How lucky we are to entrust our data and our lives to them!

Anyone can buy the tokens via the API and do whatever they want with them. Its not evil of Google to say "Here is an allotment of steeply discounted tokens, but you can only use them with our services."

It is evil to block your email and hold your photos hostage over it though :)

Re: Addressing Antigravity Bans and Reinstating Access

#87
post #11
post #8

Way too risky to use Google services like this tied to your primary account. There’s too much risk of cross damage. Imagine losing access to your Gmail because some Gemini request flags you as an undesirable. The digital death sentence of losing access to your email with a company that notoriously has no way for the average human to contact a human is not worth the risk.

This wasn't due to some random Gemini request. Users were using sketchy antigravity auth plugins to use their antigravity tokens on things like OpenClaw, clearly against ToS. It's great that Google is giving these users a second chance.

Telling your users they can't use certain software to access your HTTP API is exactly the same as telling people they can't use certain browsers to load https://google.com.

Re: Addressing Antigravity Bans and Reinstating Access

#88
post #45

Earlier quoted context omitted.

How do you even pull away from a Gmail address? I'm nearly twenty years into that service. Getting banned would be absolutely devastating...

Use your own domain to sign up for a paid email service, provided by a company that focuses on email. I use Fastmail, but there are many other options. Set up forwarding in Gmail to your new address. Then, whenever you log in to a website or app with your Gmail, take a moment to change it to your new address. In a few weeks, most of your important accounts will be covered. In a few months, almost everything you still…

Same here but ~8 years.

You can mitigate/speed the process using your password manager too.

I still use a filter in my email so that if something comes in under my Gmail, it gets a special tag that I can filter on and treat those as a todo list. Rarely happens beyond the occasional Google Meet connection.

Re: Addressing Antigravity Bans and Reinstating Access

#89

Earlier quoted context omitted.

It’s be great if Google just revoked antigravity access if terms were violated. No need to disable the entire account.

No Google account has been banned for this. People just keep spreading this lie because no one agrees that they have the right to steal the OAuth token.

It's their OAuth token, it's not being stolen. It's just being copied from one place on their computer to another. This is no different than a competing browser importing your localStorage and cookies from Chrome on first launch.

Re: Addressing Antigravity Bans and Reinstating Access

#90
The problem is that Google treats its customers as college kids who can be banned from a college maker lab for using too much 3D filament rather than entrepreneurs who are trusting their livelyhood to a service provider that promises to be reliable. If War Department uses too many Gemini tokens, do they cut them off, make them go through recertification process and permaban the next time around?

Which means that anyone serious about AI and not going local route should be using a provider with better reputation. I don't know if Alibaba, Z.ai or moonshots AI are also known for hair trigger responses, could be decent options for coding AI otherwise? If not, time to look for smaller providers with good reputation?

Post reply on HN