I have gained admin access to numerous GCloud Organizations by accident
41–50 of 132 posts
Re: I have gained admin access to numerous GCloud Organizations by accident
#42A few months ago I stumbled upon a bug in a state machine that allowed me to obtain stuff without having to pay for it. It was a weird combination of steps and was kind of hard to explain. I submitted a ticket to the support team advising them in painstaking detail the steps needed to reproduce this vulnerability. They could also look at my account and see that I got stuff without paying. A couple days later I got a…
To your point, there should be some easy way to get a security incident report to the security team through an easily discoverable form or similar. This is as easy as "security incident" option in a support ticket drop down, and triage is required whether this is an ingest point or security@ email.
For example: https://www.google.com/.well-known/security.txt
Re: I have gained admin access to numerous GCloud Organizations by accident
#43I would have thought that being "added" to anything is a two-way confirmation: 1. One from the party wanting to add the group to their account. Based on a prior comment, sounds like you are prompted to confirm an external group being added as admin. 2. One from the party administering/owning an external google group being requested to be added. Is there any confirmation here? Without the 2nd confirm, I start imaginin…
Re: I have gained admin access to numerous GCloud Organizations by accident
#44Isn't this a little like reaching out to Linus because someone changed their home directory permission to rwxrwxrwx? It sucks for them, but what could google do?
They could make the default such that you couldn't grant anyone outside your organization any particular role, unless principals associated with that domain are explicitly whitelisted (by domain). (And, in the other direction, there should be a request/response flow when you're added to some random project/org you have no interest in, which can make you vulnerable both to legal attacks by the org mistakenly adding yo…
Re: I have gained admin access to numerous GCloud Organizations by accident
#45Re: I have gained admin access to numerous GCloud Organizations by accident
#46Re: I have gained admin access to numerous GCloud Organizations by accident
#47Re: I have gained admin access to numerous GCloud Organizations by accident
#48Earlier quoted context omitted.
To your point, there should be some easy way to get a security incident report to the security team through an easily discoverable form or similar. This is as easy as "security incident" option in a support ticket drop down, and triage is required whether this is an ingest point or security@ email.
Like security.txt? https://securitytxt.org For example: https://www.google.com/.well-known/security.txt
I understand some scrappy startups like Google don't have the resources to have someone review security incident reports that come through a web form, but maybe they should if they want to be a legit cloud provider?
Googling "report google cloud security issue" does not turn up productive results. Compare to what you get when you google "report aws security issue."
Re: I have gained admin access to numerous GCloud Organizations by accident
#49Ex-Googler here. Try reporting it through the security disclosure program: https://www.google.com/appserve/security-bugs/m2/new You can also assume that by virtue of you having posted this here and being on the frontpage, it's probably made it to the internal Google SRE IRC chat by now and someone is trying to find a contact. This almost always works :) Maybe edit your OP with a way to contact you , so that someone c…
In that case no point in following up at all right? Just post on HN and hope someone in the right spot sees it?
> This almost always works :)
That’s the type of SLA one can rely on!
> Maybe edit your OP with a way to contact you, so that someone can reach out.
Having to break online anonymity so that a company can impose the Hollywood rule, “don’t call us, we’ll call you!”, is a truly lousy support structure.