Live data from Hacker News

How we got read access on Google’s production servers

blog.detectify.com

41–50 of 197 posts

Re: How we got read access on Google’s production servers

#41
post #2

... And this is why you want to discontinue products and services your engineers can't be motivated to maintain. Amazing. This should scare anyone who has ever left an old side project running; I could see a lot of companies doing a product/service portfolio review based on this as a case study.

Or just move it to some cheap VPS where it cannot damage other services or your infrastructure.

Most of the time projects are not neatly encapsulated like that.

Re: How we got read access on Google’s production servers

#42

Earlier quoted context omitted.

Or just move it to some cheap VPS where it cannot damage other services or your infrastructure.

Or your reputation or your ethical and possibly legal duty to protect your clients?

Compartmentalization is part of that.

Re: How we got read access on Google’s production servers

#43
post #8

So, when you have read access to googles prod servers, what else would be fun to do besides reading /etc/passwd ? Getting the source?

The source is not generally accessible from prod servers - only binaries and supporting data, and only the ones running on that computer.

I guess it's possible you could find a computer that hosted both search and the codebase. But, since search is for external and the codebase is for internal, I'd be that they don't share clusters.

Re: How we got read access on Google’s production servers

#44
post #20
post #15

Just $10k? This sells for at least 10 times more on the black market. Why would one rationally chose to "sell" this to google instead of the black market. Some people don't break the law because they are afraid to get caught, but I like to believe that most people don't break the law because of the moral aspect. To me at least, selling this on the black market poses no moral questions, so, leaving aside "I'm afraid t…

If you want to look at it rationally you have to factor in the risks you are taking by selling it on the black market. These risk include: - How will you whitewash the money? Alternatively how will you spend them on the black market? You can't buy houses, cars or stocks with black money. - Will you get paid? - Secure anonymous payments that are guaranteed are not trivial. I don't know if there are escrow services for…

Bitcoin would be the preferable way to get payed in this situation.

Re: How we got read access on Google’s production servers

#45
post #39
post #22

Earlier quoted context omitted.

[...] why would one not sell this on the black market? Because it is wrong to harm others for personal benefit?

I agree with you however companies are completely the void of morality their only purpose is profit and they will hire shady lawyers to interpret the law in their favor fire people without giving it a second thought or collude with other big companies to keep their employees wages low so why would i treat them differently. In business morality is a luxury that some companies can't afford and most choose not to have s…

I would never consider selling it on the black market. That others are lacking moral principles is not a justification to go the same route.

Re: How we got read access on Google’s production servers

#46
post #15

Just $10k? This sells for at least 10 times more on the black market. Why would one rationally chose to "sell" this to google instead of the black market. Some people don't break the law because they are afraid to get caught, but I like to believe that most people don't break the law because of the moral aspect. To me at least, selling this on the black market poses no moral questions, so, leaving aside "I'm afraid t…

"Why would one rationally chose to "sell" this to google instead of the black market."

Exactly because of that. One is legal the other is not

Re: How we got read access on Google’s production servers

#47
post #39
post #22

Earlier quoted context omitted.

[...] why would one not sell this on the black market? Because it is wrong to harm others for personal benefit?

I agree with you however companies are completely the void of morality their only purpose is profit and they will hire shady lawyers to interpret the law in their favor fire people without giving it a second thought or collude with other big companies to keep their employees wages low so why would i treat them differently. In business morality is a luxury that some companies can't afford and most choose not to have s…

>I agree with you however companies are completely the void of morality their only purpose is profit and they will hire shady lawyers to interpret the law in their favor fire people without giving it a second thought or collude with other big companies to keep their employees wages low so why would i treat them differently.

Perhaps, but even so, when you sell a vulnerability to the "black market" you don't just harm Google. You also harm people the vulnerability will be used against (to fish their credit card details, compromise their servers, etc).

(Perhaps in this case, for technical reasons you can only harm Google with this thing, not sure. But still, talking in general).

Re: How we got read access on Google’s production servers

#49
post #30
post #21

Earlier quoted context omitted.

I don't agree with you that "selling this on the black market poses no moral questions"; this gives access to Google's production servers, which can really harm Google in very bad ways. Unless Google has done specific very bad things to you and you want retribution, why would you do that to them? But I agree with you that $10,000 doesn't sound like much, for such an exploit, and for a company like Google. Edit: corre…

It's $10,000, not $10. Detectify is based in Europe where they use . to group digits.

Yeah, it was a typo; I meant $10k, which does seem quite low, no?

Re: How we got read access on Google’s production servers

#50
post #20

Earlier quoted context omitted.

If you want to look at it rationally you have to factor in the risks you are taking by selling it on the black market. These risk include: - How will you whitewash the money? Alternatively how will you spend them on the black market? You can't buy houses, cars or stocks with black money. - Will you get paid? - Secure anonymous payments that are guaranteed are not trivial. I don't know if there are escrow services for…

Bitcoin would be the preferable way to get payed in this situation.

How would you escrow it so that you can be sure to actually get the funds? Sure they're not going to pay up front and it would be over-trusting to give a crack away on the promise of later funds, so ...
Post reply on HN