🧑💻🐴 
¯\_(ツ)_/¯ Just another n00b background pony. Mostly cybersec/infosec/tech related ramblings, and trying to build better - tech, community, & future.
Opinions mine. Duh - I'm a pony.
Helps runs OWASP Melbourne, SecTalks Melbourne, DCG 11613, ComfyCon, etc.
Previously, AppSec Day Australia, OWASP How to Get into AppSec project, member of OWASP Education Committee, etc.
PSA ICYMI if you use any Google API keys incl Maps.
TLDR: "Public" Google API keys (like the ones used for Maps, Firebase, Google's URL shortener etc.) allowed access to Gemini by default (if you didn't specifically take action to limit access the API key has), and thus access to practically everything the account can acccess.
Recommend: Check & limit all your old API keys. Roll them if possible, and limit their access to only what they need.
Excellent work by TruffleSec
👇👇👇
https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules
Now I wonder, how goes CoPilot hold up as MSFT shoves it into everything.... 🤔