Google has a main problem now as once benign API keys to work with Maps and Firebase now also allow Gemini access and can expose a whole lot of user data they didn't previously had access to
Almost 3k of these are exposed online
Google API Keys Weren't Secrets. But then Gemini Changed the Rules. ◆ Truffle Security Co.
Google spent over a decade telling developers that Google API keys (like those used in Maps, Firebase, etc.) are not secrets. But that's no longer true.
(trufflesecurity.com)


