Live data from Hacker News

I have gained admin access to numerous GCloud Organizations by accident

news.ycombinator.com

101–110 of 132 posts

Re: I have gained admin access to numerous GCloud Organizations by accident

#101
post #32

Ex-Googler here. Try reporting it through the security disclosure program: https://www.google.com/appserve/security-bugs/m2/new You can also assume that by virtue of you having posted this here and being on the frontpage, it's probably made it to the internal Google SRE IRC chat by now and someone is trying to find a contact. This almost always works :) Maybe edit your OP with a way to contact you , so that someone c…

I filed a bug bounty! If this is working as expected then so be it…

I didn’t even know this hit front page till you said something

I’m just gonna leave the other orgs alone and not doing anything in there until I can figure out a strategy to delete this google group (which I am actually using to manage my own accounts) my accounts are just hobby accounts more than anything, it’s crazy I logged in and found these full-blown business accounts lol

Just insane to me that I don’t have to confirm on my end that I should be the admin, or billing role lol, they can just one way add you…

I think they meant to add their service account and instead added my google group, the URLs are kind of similar

Re: I have gained admin access to numerous GCloud Organizations by accident

#102
GCloud security is horrible. It's like they designed the whole thing to be insecure by default. Coming from AWS, the amount of permissions they give by default in the most commonly-used roles is insane. They also seem to lack some functionality necessary to make fine-grained access permissions to access some of their advertised features. It's really crazy.

Re: I have gained admin access to numerous GCloud Organizations by accident

#103
post #60
post #20

Earlier quoted context omitted.

They outsource it. I'm on the U.S. East Coast. My last GCP support ticket ended up in Romania.

And nothing against Romanians! I work with a ton of brilliant folks there. Outsourcing inevitably creates a firewall between engineering and support that shouldn't exist though. In a properly functioning org, support has a way to escalate quickly to engineering if it's confirmed "This is broken." Engineering in turn uses those incoming requests to recognize flaws in their own products. Outsourcing creates "Hide behin…

At Basho engineers would often spend time working support to get a better view into customer pain points. Outsourcing support sounds like a giant middle finger to customers.

Re: I have gained admin access to numerous GCloud Organizations by accident

#105

I'm the SRE oncall for Cloud IAM. Can you send me a message on linkedin (link in my profile)? I'll give you my Google corp account email address.

FYI there's no such thing as direct messages on HN.

You need to put a means of contact in your profile, or edit your comment to add it. It can be a disposable e-mail (like https://temp-mail.org/en/) if you want to enable a short-term communication like in this case.

(Side note, I've seen this crop up so much that it kind of seems like it would be good to have a DM functionality in HN, even if messages were auto-deleted after 7 days or something, or if it just forwarded to a non-public e-mail address.)

Re: I have gained admin access to numerous GCloud Organizations by accident

#106
post #60

Earlier quoted context omitted.

And nothing against Romanians! I work with a ton of brilliant folks there. Outsourcing inevitably creates a firewall between engineering and support that shouldn't exist though. In a properly functioning org, support has a way to escalate quickly to engineering if it's confirmed "This is broken." Engineering in turn uses those incoming requests to recognize flaws in their own products. Outsourcing creates "Hide behin…

At Basho engineers would often spend time working support to get a better view into customer pain points. Outsourcing support sounds like a giant middle finger to customers.

I'm biased, because I came up through support before I went into engineering.

But to me, the question has always been "Do I think I'm omniscient as an engineer? Do I think I can imagine every way the customer is going to try and use this product? Every way it can interact with other systems? Every quirk of a specific customer environment/dataset/etc.?"

Well, if not, then good news! The support org should be capturing, categorizing, documenting, and forwarding all those cases to me.

And each case is an opportunity to make the product better!

Re: I have gained admin access to numerous GCloud Organizations by accident

#107
post #49

Earlier quoted context omitted.

> You can also assume that by virtue of you having posted this here and being on the frontpage, it's probably made it to the internal Google SRE IRC chat by now and someone is trying to find a contact. In that case no point in following up at all right? Just post on HN and hope someone in the right spot sees it? > This almost always works :) That’s the type of SLA one can rely on! > Maybe edit your OP with a way to c…

Apples anonymous emails may work for this purpose.

Or Firefox Relay.

Re: I have gained admin access to numerous GCloud Organizations by accident

#109
post #32

Ex-Googler here. Try reporting it through the security disclosure program: https://www.google.com/appserve/security-bugs/m2/new You can also assume that by virtue of you having posted this here and being on the frontpage, it's probably made it to the internal Google SRE IRC chat by now and someone is trying to find a contact. This almost always works :) Maybe edit your OP with a way to contact you , so that someone c…

Google already know about this one, fat lot of good it's done for the last 12 years: https://issuetracker.google.com/issues/35889152

Person abandons old account attached to a group/project, account then hacked, et voila!

It's also probably in breach of GDPR regs that say you should be able to update your own information if it's incorrect.

Re: I have gained admin access to numerous GCloud Organizations by accident

#110

I'm the SRE oncall for Cloud IAM. Can you send me a message on linkedin (link in my profile)? I'll give you my Google corp account email address.

FYI there's no such thing as direct messages on HN. You need to put a means of contact in your profile, or edit your comment to add it. It can be a disposable e-mail (like https://temp-mail.org/en/ ) if you want to enable a short-term communication like in this case. (Side note, I've seen this crop up so much that it kind of seems like it would be good to have a DM functionality in HN, even if messages were auto-dele…

Thanks, I added my linkedin to my profile because I already treat that as spam :)
Post reply on HN