Live data from Hacker News

Hacking Google's HVAC Systems

cylance.com

11–20 of 46 posts

Re: Hacking Google's HVAC Systems

#11

Interesting related story from July 2012: http://www.washingtonpost.com/investigations/tridiums-niagar... “We’re not going to say Niagara is secure” What I find most worrisome about this is that it can enable attackers to access internal video feeds. Seems like an excellent vector to grab someone's credentials. Also, ironically, one of the people mentioned in the WaPo article who discovered these vulnerabilities used…

That same guy [Billy Rios] is the one who wrote the blog post.

Re: Hacking Google's HVAC Systems

#12

Interesting related story from July 2012: http://www.washingtonpost.com/investigations/tridiums-niagar... “We’re not going to say Niagara is secure” What I find most worrisome about this is that it can enable attackers to access internal video feeds. Seems like an excellent vector to grab someone's credentials. Also, ironically, one of the people mentioned in the WaPo article who discovered these vulnerabilities used…

That same guy [Billy Rios] is the one who wrote the blog post.

ah, good catch. I edited my post accordingly.

Re: Hacking Google's HVAC Systems

#13
I'm impressed that they had the balls to actively compromise the device before reporting it to Google... under normal circumstances, wouldn't most companies go after you in court for a CFAA violation or somesuch?

You certainly see lots of examples of lawsuits over changing numbers in URLs, so you'd figure downloading configuration info from a machine and then reversing a password would definitely provide grounds for a suit.

Nice to see Google not overreact here.

Re: Hacking Google's HVAC Systems

#14
post #5

This is not a part of the vulnerability rewards program? Why?

It's not in scope, because it's not a "Google operated web service." http://www.google.com/about/appsecurity/reward-program/ (I work for Google.)

And potentially shutting down the HVAC for the web servers has no relation?

Re: Hacking Google's HVAC Systems

#15
Just a reminder to anyone interested in doing this kind of research, what Billy did here is illegal under CFAA. As we've seen from recent cases, he could be prosecuted and imprisoned even if Google declined to press charges.

Re: Hacking Google's HVAC Systems

#16
post #5

Earlier quoted context omitted.

It's not in scope, because it's not a "Google operated web service." http://www.google.com/about/appsecurity/reward-program/ (I work for Google.)

And potentially shutting down the HVAC for the web servers has no relation?

What is it that led you to believe Google hosts web servers out of the Sydney office building?

Re: Hacking Google's HVAC Systems

#19
post #5

Earlier quoted context omitted.

It's not in scope, because it's not a "Google operated web service." http://www.google.com/about/appsecurity/reward-program/ (I work for Google.)

And potentially shutting down the HVAC for the web servers has no relation?

There's a photo and a floor plan - please point to the production servers :) (hint: it's an office building, not a datacenter)

Re: Hacking Google's HVAC Systems

#20

I'm impressed that they had the balls to actively compromise the device before reporting it to Google... under normal circumstances, wouldn't most companies go after you in court for a CFAA violation or somesuch? You certainly see lots of examples of lawsuits over changing numbers in URLs, so you'd figure downloading configuration info from a machine and then reversing a password would definitely provide grounds for…

It's not a big surprise that they didn't overreact. Billy Rios has a long relationship with Google.

He worked there for almost 3 years: http://www.linkedin.com/pub/billy-rios/3/a7a/5b1

Before that, he was recognized for "ongoing and sustained contribution to the security of Google's applications": http://www.google.com/about/appsecurity/hall-of-fame/archive...

Post reply on HN