Live data from Hacker News

I have gained admin access to numerous GCloud Organizations by accident

news.ycombinator.com

41–50 of 132 posts

Re: I have gained admin access to numerous GCloud Organizations by accident

#42

A few months ago I stumbled upon a bug in a state machine that allowed me to obtain stuff without having to pay for it. It was a weird combination of steps and was kind of hard to explain. I submitted a ticket to the support team advising them in painstaking detail the steps needed to reproduce this vulnerability. They could also look at my account and see that I got stuff without paying. A couple days later I got a…

To your point, there should be some easy way to get a security incident report to the security team through an easily discoverable form or similar. This is as easy as "security incident" option in a support ticket drop down, and triage is required whether this is an ingest point or security@ email.

Like security.txt?

https://securitytxt.org

For example: https://www.google.com/.well-known/security.txt

Re: I have gained admin access to numerous GCloud Organizations by accident

#43

I would have thought that being "added" to anything is a two-way confirmation: 1. One from the party wanting to add the group to their account. Based on a prior comment, sounds like you are prompted to confirm an external group being added as admin. 2. One from the party administering/owning an external google group being requested to be added. Is there any confirmation here? Without the 2nd confirm, I start imaginin…

Hah, probably wouldn’t work well though. The types of folks who have money AND would be fooled by something like that would almost never have the time or curiosity to go poking around.

Re: I have gained admin access to numerous GCloud Organizations by accident

#44
post #34

Isn't this a little like reaching out to Linus because someone changed their home directory permission to rwxrwxrwx? It sucks for them, but what could google do?

They could make the default such that you couldn't grant anyone outside your organization any particular role, unless principals associated with that domain are explicitly whitelisted (by domain). (And, in the other direction, there should be a request/response flow when you're added to some random project/org you have no interest in, which can make you vulnerable both to legal attacks by the org mistakenly adding yo…

Many folks have contract admins, it would add a lot of friction for the normal case just to try to prevent something that should be transparently dumb anyway.

Re: I have gained admin access to numerous GCloud Organizations by accident

#46
Just ignore it move on. There's no winning there. In the worst case, the company may try to file charges against you for computer abuse/fraud. In the best case, an otherwise harmless association is removed from your account. It is impossible to get ahold of anyone at Google if you are not an enterprise customer. Just forget about it and do nothing.

Re: I have gained admin access to numerous GCloud Organizations by accident

#48
post #42

Earlier quoted context omitted.

To your point, there should be some easy way to get a security incident report to the security team through an easily discoverable form or similar. This is as easy as "security incident" option in a support ticket drop down, and triage is required whether this is an ingest point or security@ email.

Like security.txt? https://securitytxt.org For example: https://www.google.com/.well-known/security.txt

You and I know this, but if you're not a security practitioner, you might not know. It might as well then be behind a door for a room with a sign that says "Beware of the Leopard."

I understand some scrappy startups like Google don't have the resources to have someone review security incident reports that come through a web form, but maybe they should if they want to be a legit cloud provider?

Googling "report google cloud security issue" does not turn up productive results. Compare to what you get when you google "report aws security issue."

Re: I have gained admin access to numerous GCloud Organizations by accident

#49
post #32

Ex-Googler here. Try reporting it through the security disclosure program: https://www.google.com/appserve/security-bugs/m2/new You can also assume that by virtue of you having posted this here and being on the frontpage, it's probably made it to the internal Google SRE IRC chat by now and someone is trying to find a contact. This almost always works :) Maybe edit your OP with a way to contact you , so that someone c…

> You can also assume that by virtue of you having posted this here and being on the frontpage, it's probably made it to the internal Google SRE IRC chat by now and someone is trying to find a contact.

In that case no point in following up at all right? Just post on HN and hope someone in the right spot sees it?

> This almost always works :)

That’s the type of SLA one can rely on!

> Maybe edit your OP with a way to contact you, so that someone can reach out.

Having to break online anonymity so that a company can impose the Hollywood rule, “don’t call us, we’ll call you!”, is a truly lousy support structure.

Post reply on HN