It happened

I knew I had a Google Maps API key in a Microsoft Github repository publicly viewable, so I’ve been meaning to rotate it. Since 2017. Procrastination, eh?

But it didn’t really seem that urgent because I had a $10 spending limit on the key, so eh whatevs — I have more important things to do. Like washing my hair! Reading comics! I’m a busy man!

After nine years, it finally happened: Somebody started using it and ran up a $6 bill, so I disabled the key (and I guess I now have to push a new version of the CSID app; the map portions no longer work).

Eh, tant pis. But I’m idly wondering whether there’s any way to tell what the IP addresses of the API calls were? It would have been amusing if the usage came from some Openai LLM or something…

Leave a Reply