

Turns out Google Gemini will let you use any old Google API key from things like maps and firebase to access it. So, baddies can do key scanning in public repos and then charge LLM usage to anyone who has committed an API key to their repo!
So many layers of stupidity going on here!
https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules
This preprint just shared by Gary Marcus is interesting.
LLMs an addictive psychological hazard: confirmed?