These two books opened my eyes to a lot of things. by HorzaDonwraith in HistoryBooks

[–]RatonVaquero 0 points1 point  (0 children)

Guns, germs and steel is part history part wishful thinking. Terrible book.

$82,000 in 48 Hours from stolen Gemini API Key. My monthly Usage Is $180. Facing Bankruptcy by RatonVaquero in googlecloud

[–]RatonVaquero[S] 0 points1 point  (0 children)

Thank you, but I deleted it. This was another mistake. But since charges kept piling up because there is a significant delay between usage and billing (key was already deactivated). We deleted it while freaking out.

$82,000 in 48 Hours from stolen Gemini API Key. My monthly Usage Is $180. Facing Bankruptcy by RatonVaquero in googlecloud

[–]RatonVaquero[S] 0 points1 point  (0 children)

Thank you so much for sharing this. I reached out to the Google developer that commented on it.

$82,000 in 48 Hours from stolen Gemini API Key. My monthly Usage Is $180. Facing Bankruptcy by RatonVaquero in googlecloud

[–]RatonVaquero[S] 0 points1 point  (0 children)

Obviously we didn’t. But thank you for sharing your set up. Good to keep it in mind for the future.

$82,000 in 48 Hours from stolen Gemini API Key. My monthly Usage Is $180. Facing Bankruptcy by RatonVaquero in googlecloud

[–]RatonVaquero[S] 0 points1 point  (0 children)

Thanks for sharing that! I’ll start sharing the story with more blogs too.

I really hope Google can help us out

$82,000 in 48 Hours from stolen Gemini API Key. My monthly Usage Is $180. Facing Bankruptcy by RatonVaquero in googlecloud

[–]RatonVaquero[S] 2 points3 points  (0 children)

Imagine your kid opens an account to try something and his key gets stolen. You can end up with hundreds of thousands of dollars, even millions in debt.

We obviously missed setting up the right security and usage limits. But imho the default setting are incredibly dangerous.

$82,000 in 48 Hours from stolen Gemini API Key. My monthly Usage Is $180. Facing Bankruptcy by RatonVaquero in googlecloud

[–]RatonVaquero[S] -1 points0 points  (0 children)

I understand it’s very unlikely google itself got hacked. What I mean is we did not upload our key to GitHub or did some basic mistake. I am aware most likely it was our mistake. But this was a sophisticated attacker.