this post was submitted on 03 Mar 2026
147 points (96.8% liked)

Technology

82227 readers
4334 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

Original Reddit post, which the article almost exclusively pulls from: https://old.reddit.com/r/googlecloud/comments/1reqtvi/82000_in_48_hours_from_stolen_gemini_api_key_my/

all 16 comments
sorted by: hot top controversial new old
[–] purplemonkeymad@programming.dev 14 points 14 hours ago

This is why I've never taken up the "free tiers" of these big cloud hosting. I looked in to it and there was absolutely no way to limit billing. There is reports and some people say, "setup automation," but that is something they should have done. Why do I have to code features into their platform?

The lack of control is intentional, the business is happy when this happens as they can extract more money from people.

[–] FUCKING_CUNO@lemmy.dbzer0.com 55 points 1 day ago (2 children)

One of the developers argued on Reddit that cloud providers should implement stronger safeguards

Uh, stronger safeguards like LIKE ENABLING TWO FACTOR AUTHENTICATION YOU FUCKING IDIOTS.

[–] Appoxo@lemmy.dbzer0.com 3 points 4 hours ago

I wasnt aware of 2FA on API keys.

Is that something new?
And here I thought that's why they tell you to never share it because the API key can't be protected by 2FA (And no, IAM or SSO is not something I will count)

[–] dhork@lemmy.world 75 points 1 day ago (1 child)

The developers said they did not believe they made any "obvious" operational mistake. After discovering the compromised key, they attempted to secure their system by deleting exposed keys, disabling Google Gemini API access, and enabling two-factor authentication across their accounts.

I'm no "cloud developer", but there seem to be a few obvious operational mistakes described just in that paragraph alone....

[–] FauxLiving@lemmy.world 44 points 1 day ago

After discovering the robbery, the bank installed doors and locks.

[–] MedicPigBabySaver@lemmy.world 20 points 1 day ago (1 child)

Fuck Reddit and Fuck Spez.

[–] Kolanaki@pawb.social 1 point 4 hours ago

Also fuck news sites that get 100% of their info from Reddit without verifying if any of it is even true.

[–] MountingSuspicion@reddthat.com 27 points 1 day ago (1 child)

Google is a bad company with bad policies, but I'd love to have them explain what caused the compromise. They dispute that it was uploaded publicly to GitHub, but don't seem to provide any information as to what happened. They also didn't have 2fa on, which is strange to hear because AWS (they're using Google) required 2fa on all accounts at least a year ago, regardless of permissions if memory serves. Really sorry to hear this happened to them, and the fact you can't set a hard cap on spend makes Google the party ultimately responsible here, but I'd appreciate having more information on the actual cause.

[–] XLE@piefed.social 23 points 1 day ago (2 children)

Google also changed the rules on API key security after years of precedent.

https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules

I'm sure they have a reason for everything they do, but rarely are they good reasons.

Yes, I saw that, I just didn't see them say that's what happened to them. If that's what happened then this should be an open and shut case. Like I said initially, Google is a bad company doing bad things and this change was an objectively greedy and evil thing.

[–] ace_garp@lemmy.world 14 points 1 day ago (1 child)

'Turned $180 billion into $82,000 in two days'

Wait, I thought this story was about Google AI, not OpenAI.

[–] 13igTyme@piefed.social 6 points 1 day ago

It all the same garbage.

[–] Reygle@lemmy.world 7 points 1 day ago