请鹿晗张艺兴代言升咖的蜜雪,“穷哥们”还喝得起吗?

· · 来源:tutorial导报

tl;dr Google spent over a decade telling developers that Google API keys (like those used in Maps, Firebase, etc.) are not secrets. But that's no longer true: Gemini accepts the same keys to access your private data. We scanned millions of websites and found nearly 3,000 Google API keys, originally deployed for public services like Google Maps, that now also authenticate to Gemini even though they were never intended for it. With a valid key, an attacker can access uploaded files, cached data, and charge LLM-usage to your account. Even Google themselves had old public API keys, which they thought were non-sensitive, that we could use to access Google’s internal Gemini.

Lex: FT’s flagship investment column

主题为科技与美学。业内人士推荐新收录的资料作为进阶阅读

I tag these not just for my own reference, but so that anyone

Copyright © 1997-2026 by www.people.com.cn all rights reserved

比尔·盖茨创立的核能

В России допустили «второй Чернобыль» в Иране22:31

关于作者

张伟,资深编辑,曾在多家知名媒体任职,擅长将复杂话题通俗化表达。

分享本文:微信 · 微博 · QQ · 豆瓣 · 知乎

网友评论

  • 好学不倦

    已分享给同事,非常有参考价值。

  • 资深用户

    这篇文章分析得很透彻,期待更多这样的内容。

  • 行业观察者

    关注这个话题很久了,终于看到一篇靠谱的分析。

  • 深度读者

    作者的观点很有见地,建议大家仔细阅读。

  • 知识达人

    干货满满,已收藏转发。