Live data from Hacker News

Hacking Google's HVAC Systems

cylance.com

21–30 of 46 posts

Re: Hacking Google's HVAC Systems

#21
> [Pic: After hours button]

> (We don’t know what this button does… and we were afraid to test it :-))

How do you hack HVACs and not know what an after hours button does?

(it extends operation of the system so if you're working after hours, you won't freeze/boil to death, without wasting energy running the HVAC out of hours when no-one is there.)

Re: Hacking Google's HVAC Systems

#22

> [Pic: After hours button] > (We don’t know what this button does… and we were afraid to test it :-)) How do you hack HVACs and not know what an after hours button does? (it extends operation of the system so if you're working after hours, you won't freeze/boil to death, without wasting energy running the HVAC out of hours when no-one is there.)

I hacked the most prevalent hotel locks, but the latch on my gate constantly outsmarts me. Limited domain knowledge is a thing!

Re: Hacking Google's HVAC Systems

#24
post #5

This is not a part of the vulnerability rewards program? Why?

It's not in scope, because it's not a "Google operated web service." http://www.google.com/about/appsecurity/reward-program/ (I work for Google.)

Well, not something they meant to operate as a web service.

Re: Hacking Google's HVAC Systems

#25
Posting the complete details of your felonious actions on the internet = not bright.

Note that it doesn't matter whether Google is cool with your actions, after the fact. What matters is whether the local prosecutor is cool with your actions, or whether he needs an extra easy slamdunk conviction.

Kids: do not do this at home.

Re: Hacking Google's HVAC Systems

#26
I know some of the guys @ Cylance, they're good people. They've done a lot of good work regarding embedded and grid security awareness. It is pretty funny to see what people leave unprotected on the internet when they usually have pretty good security practices.

In a situation like this, I'm going to guess that "facilities" was run as a fiefdom and its network presence was obfuscated from infosec staff. Or in the worst case, infosec was told to leave it alone...

Re: Hacking Google's HVAC Systems

#27

Posting the complete details of your felonious actions on the internet = not bright. Note that it doesn't matter whether Google is cool with your actions, after the fact. What matters is whether the local prosecutor is cool with your actions, or whether he needs an extra easy slamdunk conviction. Kids: do not do this at home.

It probably helps that "Wharf 7" is in Australia [1] and the access was from the US. I can't imagine any officer in Pyrmont Police Station being too keen on the paperwork involved in following up an incident of this magnitude!

[1] http://maps.google.com.au/maps?ll=-33.867302,151.198268

Re: Hacking Google's HVAC Systems

#28
Unfortunately this is far from an isolated issue. There are a multitude of BMS's and control systems out there where security has had next to zero consideration. Traditionally these systems have sat on isolated networks and favoured serial communication. Unfortunately many of the people who have spent the majority of their lives designing, installing and deploying these systems have very little exposure to even the most basic network security principles.

When you consider these system have complete control over many environments - signal distribution, HVAC, occupancy sensing, motor control for things such as dropping 3 tonne screens from roofs, even occasionally extending to physical access control - this is a very scary thought.

Re: Hacking Google's HVAC Systems

#29
post #10

You don't need a "custom exploit" or a "custom developed tool" to access a public file called config.bog and base64 decode the user:pass. This Tridium exploit was well publicized in the past year but too many people (including this contractor who installed it) failed to upgrade the security or install the patches.

Running on Windows on the developer's workstation, no less...

Let me quickly clarify that I'm not anti-Windows, it was just a double-take to see it used as a workstation for security research like this (though I'm using the word 'research' lightly). Strange article all around, lots of it caught my eye.

Post reply on HN