It's like AWS security defaults all over again... π€¦ββοΈ
Google Map API keys by default unrestricted, giving any visitor to your website with an embedded map also access to your other Google things, like the Gemini API! I can't image how confused I would've been had my bill ballooned due to visitors hammering Gemini with my, by design publicly exposed, Maps API key. π¬
https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules


Hacker News