alt.hn

3/30/2026 at 7:24:53 PM

Google's insecure-by-default API keys and 30h billing lag cost my startup $15k

https://old.reddit.com/r/googlecloud/comments/1s7v5x9/how_googles_insecurebydefault_api_keys_and_a/

by tertervat

3/30/2026 at 9:33:07 PM

Is there an easy way to know if I'm vulnerable to this? Like some dashboard page that lists all the API keys with "revoke" buttons?

I did something or another with a google API years ago, and am not looking forward to a random surprise bill. They don't have my credit card, so maybe that'd solve the problem. On the other hand, they could hold a gmail account hostage.

by hedora

3/30/2026 at 11:01:02 PM

You should definitely log in to Google Cloud Console and roll all the keys you see in there if you're unsure. I just did the same thing after I realized I had a lot of surface area with these keys.

by drewnick

3/30/2026 at 9:22:16 PM

I really hope that one effect of ai code generators making code cheaper to write is that the calculus around "accept vendor lock in return for getting up and running faster" changes dramatically

by zem

3/31/2026 at 5:41:03 AM

[dead]

by thestack_ai

3/30/2026 at 8:46:41 PM

[dead]

by cumshitpiss

3/30/2026 at 7:51:43 PM

[dead]

by opsdu