Elektrine lite

← Feed

@F30@chaos.social

Post #679469

2026-02-26 17:20 UTC

1. Tell everybody that your API keys aren‘t secret and it’s safe to publish them on your website. 2. Protect sensitive AI assistant content with the same kind of API keys. 3. Retroactively allow active API keys to access the sensitive content. 4. What could possibly be going wrong?! 🔥 Probably the worst vulnerability Google has ever deployed to prod: https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules

Replies (1)

  • @F30@chaos.social 2026-02-27 18:26

    I now created* and released a script to check a whole GCP Organization for API keys affected by this issue. Use at your own discretion: https://gist.github.com/F30/9fd4d4cbcfe11c6aabe44e5cc9d8358d (*) vibe-coded and manually reviewed

    Open ##2193099