Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There's no mention of handling with regard to costs inappropriately incurred - wouldn't access to the secrets let people call APIs and run up costs?

Or is this purely about theft of data/code?



It could be both. In my case my keys were used to call OpenAI, almost certain they were leaked from my Spaces secrets




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: