logoalt Hacker News

Google's insecure-by-default API keys and 30h billing lag cost my startup $15k

45 pointsby tertervatyesterday at 7:24 PM5 commentsview on HN

Comments

kingstnapyesterday at 9:39 PM

This is interesting but the linked articles is even more interesting.

https://trufflesecurity.com/blog/google-api-keys-werent-secr...

> Even Google themselves had old public API keys, which they thought were non-sensitive, that we could use to access Google’s internal Gemini.

This is just a classic slow clap here for Cloud.

show 1 reply
hedorayesterday at 9:33 PM

Is there an easy way to know if I'm vulnerable to this? Like some dashboard page that lists all the API keys with "revoke" buttons?

I did something or another with a google API years ago, and am not looking forward to a random surprise bill. They don't have my credit card, so maybe that'd solve the problem. On the other hand, they could hold a gmail account hostage.

show 1 reply
zemyesterday at 9:22 PM

I really hope that one effect of ai code generators making code cheaper to write is that the calculus around "accept vendor lock in return for getting up and running faster" changes dramatically

cumshitpissyesterday at 8:46 PM

[dead]

opsduyesterday at 7:51 PM

[dead]