Coding4Food LogoCoding4Food
HomeCategoriesArcadeBookmarks
vi
HomeCategoriesArcadeBookmarks
Coding4Food LogoCoding4Food
HomeCategoriesArcadeBookmarks
Privacy|Terms

© 2026 Coding4Food. Written by devs, for devs.

All news
TechnologyIT Drama

Google API Keys: From "Public Flyers" to "Access-All-Areas" Nightmare thanks to Gemini

February 26, 20263 min read

Remember when Google said API keys weren't secrets? Well, Gemini just changed the rules, and now your billing account might be bleeding. Here's the tea.

Share this post:
cyber security, hacker, security, internet, protection, secure, padlock, firewall, protect, password, safety, lock, technology, computer, network, access, privacy, gray computer, gray technology, gray laptop, gray network, gray internet, gray security, gray safety, cybersecurity, cyber security, cyber security, cybersecurity, cybersecurity, cybersecurity, cybersecurity, cybersecurity
Nguồn gốc: https://coding4food.com/post/google-api-key-gemini-security-nightmare. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/google-api-key-gemini-security-nightmare. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/google-api-key-gemini-security-nightmareNguồn gốc: https://coding4food.com/post/google-api-key-gemini-security-nightmare. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/google-api-key-gemini-security-nightmare. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/google-api-key-gemini-security-nightmare
Nguồn gốc: https://coding4food.com/post/google-api-key-gemini-security-nightmare. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/google-api-key-gemini-security-nightmare. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/google-api-key-gemini-security-nightmareNguồn gốc: https://coding4food.com/post/google-api-key-gemini-security-nightmare. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/google-api-key-gemini-security-nightmare. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/google-api-key-gemini-security-nightmare
google api key leakgemini api securitylỗ hổng google geminibảo mật api keydrama công nghệhacker news discussion
Share this post:

Bình luận

Related posts

rocket, launch, blast, transparent, cutout, spaceship, spacecraft, rocket, blast, blast, blast, spaceship, spaceship, spaceship, spaceship, spaceship, spacecraft
TechnologyIT Drama

Jeff Bezos' New Glenn Rocket Explodes: Pushing Straight to Prod in Real Life

Blue Origin's highly anticipated New Glenn rocket blew up during a static fire test. What can developers learn from this multi-million dollar hardware bug?

May 293 min read
Read more →
cloud computing, cloud system, cloud, system, internet, cloud computing concept, communication, computing, technology, woman, it, network, organization, administrator, blue computer, blue technology, blue laptop, blue network, blue community, blue internet, blue communication, cloud computing, cloud computing, cloud computing, cloud computing, cloud computing
TechnologyIT Drama

End of an Era: Dropbox Founder Drew Houston Steps Down as CEO After 17 Years of Grinding

Drew Houston is handing over the CEO baton to Ashraf Alkarmi. Is this a strategic pivot for Dropbox or just a founder touching grass after 17 years?

May 273 min read
Read more →
law, gavel, justice, judge, auction, judgement, authority, legislation, penalty, attorney, law, gavel, gavel, gavel, gavel, gavel, judge, auction, judgement, judgement, legislation, legislation, penalty
IT DramaTechnology

Elon Musk vs. OpenAI: Judge Drops the Table on Billionaire's Lawsuit

Elon Musk tried to sue Sam Altman over OpenAI's shift away from open-source, but the judge threw an unhandled exception. Grab some popcorn and let's dive in.

May 193 min read
Read more →
gamestop, stock, chart, gme, wallstreetbets, graph, finance, trading, business, growth, market, stock market, investment, boom, bubble, crash, squeeze, stock market, stock market, stock market, stock market, stock market
IT DramaTechnology

Cloudflare Axes 1,100 Devs for AI, Stock Tanks 16%, and We Need to Talk About That Insane Severance Package

Cloudflare laid off 1,100 employees blaming AI, sending their stock plunging 16%. But their golden parachute severance package has everyone taking notes.

May 93 min read
Read more →
robot, character, cartoon, robotics, future, technology, futuristic, toy, happy, robot, robot, technology, technology, technology, technology, technology
IT DramaTechnology

Coinbase Nukes 14% of Workforce, CEO Brags: 'Non-Tech Folks Now Shipping Production Code with AI'

Coinbase lays off 14% of its staff while the CEO claims AI allows non-technical teams to push code to production. Reddit goes absolutely feral. What's next?

May 63 min read
Read more →
seo, sem, marketing, optimization, web, internet, search engine, website, web traffic, strategy, content, advertising, online, www, analysis, service, seo, seo, seo, seo, seo
TechnologyAI & Automation

Google Claims 'Everyone Loves AI Search', Users Promptly Crash DuckDuckGo Servers

Google forces AI Overviews on users, claiming high satisfaction. The plot twist? DuckDuckGo traffic spikes 28%. Let's dive into the ultimate search engine drama.

May 283 min read
Read more →

Once upon a time, Google told us that API keys (for Maps, Firebase, etc.) were for identification, not authentication. Basically, they said: "It's cool if you put these in your APKs or frontend code. We don't care, they aren't secrets."

Developers, being the trusting souls we are, littered these keys everywhere. Then Gemini walked into the room and turned those "public" keys into VIP passes for hacker exploitation. Plot twist of the century, right?

The Great Google Switcheroo

The security wizards at Truffle Security dropped a bombshell report. Here’s the TL;DR for you busy beavers:

  1. The Legacy: Historically, Google API keys were embedded in mobile apps and web clients. Google said this was fine. We believed them.
  2. The Event: Google launches the Gemini API. The catch? Many GCP (Google Cloud Platform) projects are monoliths containing Maps, Firebase, and now... AI.
  3. The Exploit: If a project owner enables the Gemini API (intentionally or by accident), those ancient, dusty API keys floating around in public APKs suddenly gain the ability to query Gemini.
  4. The Damage: Bad actors scrape these keys and use Gemini for free (on your dime). Or worse, they access private data, tuned models, or cached context associated with the key.
  5. The Irony: Google is now trying to block "leaked" keys. But wait, didn't they spend years telling us these keys weren't secrets? Now they're punishing us because they are "leaked"? That's some mental gymnastics.
  6. The Dilemma: How do you fix this? Revoke all old keys? You'll break thousands of legacy apps. Don't revoke them? Enjoy your bankruptcy. Talk about being stuck between a rock and a hard place.

The Community Reacts: Dumpster Fire or User Error?

Hacker News, as always, is absolutely roasting the situation:

  • Team "Google Messed Up": One user called this "the worst security vulnerability Google has ever pushed to prod." Allowing a historically public key to access private data/context is a design flaw of monumental proportions. It's like leaving your front door open because you have nothing to steal, then buying a gold bar and leaving it on the coffee table.
  • Team "Skill Issue": The senior devs are sipping their coffee and saying: "This is why you don't reuse projects, kids." Segregate your environments. Maps go here, AI goes there. If you mix them, that's on you.
  • The Conspiracy Theorists: Someone actually suggested the blog post exposing this was written by ChatGPT to trash Gemini. I mean, it's 2024, so who knows? But the vulnerability is very real.
  • The Consensus: Fixing this is going to be a nightmare. Blanket removing permissions will break production apps. Google has backed themselves into a corner, and they're dragging us with them.

The C4F Takeaway: Trust No One

Alright, let's wrap this up before your billing alert goes off.

  1. Security 101: Even if a Big Tech giant says "it's not a secret," treat it like one. Proxy your requests. Hide your keys. Don't be lazy.
  2. Scope It Out: Go to your GCP console right now. Check your API key scopes. If your Maps key has access to "All APIs," you're playing Russian Roulette with your credit card.
  3. Audit Time: Separate your concerns. Don't let your frontend keys touch your backend AI services. It's not rocket science, it's survival.

Code breaks, but bank accounts shouldn't. Stay safe out there, folks.

Sources

  • Original Blog: Truffle Security
  • Discussion: Hacker News