Live data from Hacker News

Hacking Google's HVAC Systems

cylance.com

41–46 of 46 posts

Re: Hacking Google's HVAC Systems

#41
post #35

Earlier quoted context omitted.

What is it that led you to believe Google hosts web servers out of the Sydney office building?

Google Sydney has servers on site, but they may well just be to be local productivity aids (mirrors for development etc). Google generally don't publicise where their servers are or what they're for. Even if the servers are just like any standard office's servers, this exploit could result in some serious issues. When I was at Google Sydney a few years ago for an internship, the AC died prompting an interesting respo…

I wonder if that was a similar time to when I visited that office ~feb 2011.

The aircon was clearly over capacity then, and there were portable air conditioners scattered around the floor I was on, with flexible ducting feeding up to the return ducts in the ceiling.

I assume they've fixed that by now, I know they've gone through at least on remodel since.

Re: Hacking Google's HVAC Systems

#43

If Google can fall victim to an ICS attack, anyone can. Did Google write this software? If not, it's kind of like writing "Google locks vulnerable to lock picks". Well yeah, just like every other pin tumbler lock ever made.

No they didn't. This is actually run by a third party as Google does not own these offices. FWIW Google has a pretty decent security team, although for some reason most of them are arrogant assholes (e.g. Tavis Ormandy)

Re: Hacking Google's HVAC Systems

#44
post #31
post #23

Earlier quoted context omitted.

Presumably because addressing it does not meaningfully improve the security of Google's customers and users.

Well, it's actually a bit more complicated than that. The bug is definitely something we wanted to know about, and we're thankful for the report. That said, there are some constraints that we put in place for the reward program to protect researchers from harm. For example, we don't want physical security or the police second-guessing the intent of someone trying to sneak into one of our buildings - so we set a very…

I can definitely see the reasoning behind not wanting to encourage people to don their black ski mask and attempt to weasel their way into the building beneath the cloak of "security researcher." You are absolutely right, the police are not going to split hairs attempting to decipher the intentions of the individual and will act swiftly to neutralize the threat.

However, this case is different. While it was absolutely an attack on Google's infrastructure, it was discovered through a vulnerable external web service. Even though the control panel application is not a Google product, it stores user passwords in clear text as decoding it seems to be trivially simple. At the very least, Google should be responsible for picking third party vendors that store passwords using one-way hashes ;).

If you ask me, this should be one of those special cases!

Post reply on HN