Chrome's geolocation fails daily due to API limit
bugs.chromium.org
bugs.chromium.org
Google serves web pages and adds rate limits to keep people from taking their servers down (or, at least, from making them use way more servers than normal, which would make providing the services too expensive, which would force them to take the servers down). If their servers go down, then users can no longer use their web pages properly. But, here we see the rate limiting is itself keeping users from using web pages properly. So the rate limiting is effectively disabling services even though the whole point of the rate limit is to protect them!
I wonder if there are other feedback loops in Chrome where, in order to be able to keep serving web pages, Google could sometimes accidentally prevent Chrome users from viewing web pages?
This is amusing and all because it comes from the same company, but Google is a huge company, and it's unlikely that the Chromium team's relationship with the geolocation API team is that much different than any other enterprise customers'.
One might imagine that an evil user has done exactly that, and started sending billions of requests to the API, exhausting the quota.
It is better to have the quota exhaust, effectively blocking all Chrome users, than have the service fail due to overload which would block all users (for example, maps.google.com, and iOS and Android)
The long term fix is probably to issue temporary per-user keys to each signed in user, so that anyone who misuses the key will only block themselves. Since Chrome allows non-signed in users, there will be considerable complexity and difficulty with that approach.
If you want to test POSITION_UNAVAILABLE, IE 11 always fails after the first request.
For anyone interested, the location emulation in Chrome Dev Tools is also buggy, Chrome also fires two callbacks on failure, TIMEOUT and POSITION_UNAVAILABLE https://bugs.chromium.org/p/chromium/issues/detail?id=542923
the thing with chromium is: it is open source (you can find the credentials), it is meant to be used on any computer via any IP (you can't whitelist API requests)
No, you have to get your own API keys via Google Cloud API Manager before building chromium. That's the reason why Chromium on Windows doesn't let you log in.
I presume Chromium on linux distros will use an API key of the package maintainer.
Also, in most closed source binaries (which chrome is a part because it has binary blobs not present in Chromium - see Google Cast, etc) you will have to sign a EULA where you agree to no disassemble and use that API key, so doing so is illegal too.
https://developers.google.com/maps/documentation/javascript/...
https://developers.google.com/maps/faq#keysystem
The most secure approach is to get a premium plan with a cryptographic key and sign your requests serverside. This is complicated/not feasible for some APIs and client-side applications though.
Disclaimer: Googler, used to work on Google Maps, nothing to do with Chrome.
Maybe you dynamically provision API keys, but the binary needs a baked in permission to access that API to start with...