[HN Gopher] Google's insecure-by-default API keys and 30h billin...
___________________________________________________________________
Google's insecure-by-default API keys and 30h billing lag cost my
startup $15k
Author : tertervat
Score : 31 points
Date : 2026-03-30 19:24 UTC (3 hours ago)
(HTM) web link (old.reddit.com)
(TXT) w3m dump (old.reddit.com)
| zem wrote:
| I really hope that one effect of ai code generators making code
| cheaper to write is that the calculus around "accept vendor lock
| in return for getting up and running faster" changes dramatically
| hedora wrote:
| Is there an easy way to know if I'm vulnerable to this? Like some
| dashboard page that lists all the API keys with "revoke" buttons?
|
| I did something or another with a google API years ago, and am
| not looking forward to a random surprise bill. They don't have my
| credit card, so maybe that'd solve the problem. On the other
| hand, they could hold a gmail account hostage.
| kingstnap wrote:
| This is interesting but the linked articles is even more
| interesting.
|
| https://trufflesecurity.com/blog/google-api-keys-werent-secr...
|
| > Even Google themselves had old public API keys, which they
| thought were non-sensitive, that we could use to access Google's
| internal Gemini.
|
| This is just a classic slow clap here for Cloud.
| ChrisArchitect wrote:
| Some more discussion:
| https://news.ycombinator.com/item?id=47156925
___________________________________________________________________
(page generated 2026-03-30 23:01 UTC)