(no title)
alphalima | 4 days ago
You are also wrong in saying there are no projects that could reasonably have a safe api key made unsafe by this exploit.
One example, a service that has firebase auth must publish the key (Google's docs recommend). Later, you add gen ai to that service, managing access using IAM/service accounts (the proper way). You've now elevated the Firebase Auth Key to be a Gemini key. Really undeniably poor from Google.
Sophira|4 days ago
[Edit: It's likely that you intended to reply to this comment: https://news.ycombinator.com/item?id=47163147 ]