PSA ICYMI if you use any Google API keys incl Maps.
TLDR: "Public" Google API keys (like the ones used for Maps, Firebase, Google's URL shortener etc.) allowed access to Gemini by default (if you didn't specifically take action to limit access the API key has), and thus access to practically everything the account can acccess.
Recommend: Check & limit all your old API keys. Roll them if possible, and limit their access to only what they need.
Excellent work by TruffleSec
👇👇👇
https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules
Now I wonder, how goes CoPilot hold up as MSFT shoves it into everything.... 🤔
