Live data from Hacker News

€54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

discuss.ai.google.dev

81–90 of 325 posts

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#81

> We had a budget alert (€80) and a cost anomaly alert, both of which triggered with a delay of a few hours. By the time we reacted, costs were already around €28,000. I had a similar experience with GCP where I set a budget of $100 and was only emailed 5 hours after exceeding the budget by which time I was well over it. It's mind boggling that features like this aren't prioritized. Sure it would probably make Google…

Which cloud provider actually prioritises features that cut off your money supply? Because AWS sure as shit doesn't either.

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#82

> We had a budget alert (€80) and a cost anomaly alert, both of which triggered with a delay of a few hours. By the time we reacted, costs were already around €28,000. I had a similar experience with GCP where I set a budget of $100 and was only emailed 5 hours after exceeding the budget by which time I was well over it. It's mind boggling that features like this aren't prioritized. Sure it would probably make Google…

[deleted]

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#83
It's terrible that giant cloud providers such as Google or AWS doesn't allow for hard cap at project levels or prepaid. And that especially because alerts are delayed as author stated "We had a budget alert (€80) and a cost anomaly alert, both of which triggered with a delay of a few hours. By the time we reacted, costs were already around €28,000.".

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#84

Can you pre-load money into your account and have that be used until it's zero, at which time you have to load more? Deepseek does it this way.

There's a brand-new, Gemini-specific feature for that (as new as March 23), but historically the answer has tended to be "no" from all the cloud providers. Most giants and indies alike have always been strongly opposed to implementing this feature for business reasons. (When you run across something that does let you do things that way, it's one of a handful of exceptions.) Their response is to tell you to set up budget alerts, which is not a solution, as described in this post.

https://en.wikipedia.org/wiki/The_purpose_of_a_system_is_wha...>

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#85

[flagged]

This reads like 100% an LLM comment. by design -- the enforcement Nothing new here - what is new is the A thing before anyone noticed - another thing, billing in hours, damage in minutes. has the signal, doesn't expose the control Every one of those "exposes the signal" to me.

Do not get hung up? Sounds like English ESL rewrote some insights for language. Content > Form.

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#86
post #21

I said this when this finding was originally posted and I'll say it again: This is by far the worst security incident Google has ever had, and that's why they aren't publicly or loudly responding to it. It's deeply embarrassing. They can't fix it without breaking customer workflows. They really, really want it to just go away and six months from now they'll complete their warning period to their enterprise contracts…

It's not a security incident because it makes Google money. It's extra revenue. They are embarrassed all the way to the bank. At some point, when it appeared 2 months ago on HN and they still did nothing about it, intentionality can be assumed.

This is exactly it - and the normal "resolution" is a class-action lawsuit but no doubt their terms and conditions forbid that.

However, anyone affected should probably pollute their docket with lawsuits anyway.

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#87

I think the logistics of calculating cost in real time is something that is extremely hard. I don't think there is one big cloud service provider that has hard limits instead of alerts. As long as they revert the charge when notified of scenarios like this , and they have historically done so for many cases, it's fine. It's an acceptable workaround for a hard problem and the cost of doing business ( just like Credit…

Ridiculous. They are clearly not trying at all. A hard wall preventing going over budget by 100x in a couple hours is not some devilishly complicated decentralized system problem.

Don't tote the party line.

Same reason why Azure AI only has easy rate limits by minute, not by day or week or month. Open source proxy projects do it easily tho. Think about the incentives.

Going over a hard cap by 3% would be a reasonable failure to make, not by 30000%.

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#88
Forgive my ignorance - but what's the payoff for fraudsters in getting access to a generative AI service for a short-ish period of time, before they get cut off?

With EC2 / GCC credentials, I could understand going all out on bitcoin mining - but what are they asking the AI to do here that's worth setting up some kind of botnet or automation to sift the internet for compromised keys?

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#89

Considering the amount of repositories on public GitHub with hard-coded Gemini API tokens inside the shared source code ( https://github.com/search?q=gemini+%22AIza%22&type=code ), this hardly comes as a surprise. Google also has historically treated API keys as non-secrets, except with the introduction of the keys for LLM inference, then users are supposed to treat those secretly, but I'm not sure everyone got that…

> Google also has historically treated API keys as non-secrets, except with the introduction of the keys for LLM inference, then users are supposed to treat those secretly This was reported a long time ago, and was supposed to be fixed by Google via making sure that these legacy public keys would not be usable for Gemini or AI. https://news.ycombinator.com/item?id=47156925 https://ai.google.dev/gemini-api/docs/troubl…

the topic is cost overruns. they still allow for cost overruns. What's so hard to comprehend ?

Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

#90
> We had a budget alert (€80) and a cost anomaly alert, both of which triggered with a delay of a few hours

> By the time we reacted, costs were already around €28,000

> The final amount settled at €54,000+ due to delayed cost reporting

So much for the folks defending these three companies that refused to provide hard spending cap ("but you can set the budget", "you are doing it wrong if you worry about billing", "hard cap it's technically impossible" etc.)

Post reply on HN