Live data from Hacker News

I have gained admin access to numerous GCloud Organizations by accident

news.ycombinator.com

91–100 of 132 posts

Re: I have gained admin access to numerous GCloud Organizations by accident

#91
post #32

Ex-Googler here. Try reporting it through the security disclosure program: https://www.google.com/appserve/security-bugs/m2/new You can also assume that by virtue of you having posted this here and being on the frontpage, it's probably made it to the internal Google SRE IRC chat by now and someone is trying to find a contact. This almost always works :) Maybe edit your OP with a way to contact you , so that someone c…

Internal SRE IRC? Too good for the laggy Slack/Teams/etc. CVEware?? I'd be jealous, but then I realized it prob has good uptime whereas using Slack is like a free day off every month with its SLA.

https://xkcd.com/1782/

Re: I have gained admin access to numerous GCloud Organizations by accident

#92

Isn't this a little like reaching out to Linus because someone changed their home directory permission to rwxrwxrwx? It sucks for them, but what could google do?

If it were happening a bunch, there might be a good case to be made for changing permission-granting UI. Maybe not kernel-level, but OS-level, at least.

In fact, lots of distros now warn when a user attempts certain sudo actions, for similar reasons—mistakes were being made, and adding a little or the right kind of friction could prevent them.

Re: I have gained admin access to numerous GCloud Organizations by accident

#93
I was successful in the past reaching out through this:

https://issuetracker.google.com/issues/new?component=187161&...

I was told "issuetracker" generates messages directly to support/engineering teams and they do look into it.

Submit a "defect" and they will answer.

Re: I have gained admin access to numerous GCloud Organizations by accident

#94
post #32

Ex-Googler here. Try reporting it through the security disclosure program: https://www.google.com/appserve/security-bugs/m2/new You can also assume that by virtue of you having posted this here and being on the frontpage, it's probably made it to the internal Google SRE IRC chat by now and someone is trying to find a contact. This almost always works :) Maybe edit your OP with a way to contact you , so that someone c…

I recently helped someone with google cloud web applications. They got a weird bug where the deployment with new code would just give old deployment logs. Turned out the account was somehow shadowbanned for a day or so to deploy anymore. The next day the logs pointed to a code checkin from previous day.

Eventually i got super fristrated and made a fresh azure trial account for them and boom everything works.

I cannot understand how gcp is so bad at ux and support. Most of the engineers i know at google are the absolute smartest people i know, how in the heck can it be the product experience at gcp is so lousy.

Re: I have gained admin access to numerous GCloud Organizations by accident

#95
post #39

Earlier quoted context omitted.

To your point, there should be some easy way to get a security incident report to the security team through an easily discoverable form or similar. This is as easy as "security incident" option in a support ticket drop down, and triage is required whether this is an ingest point or security@ email.

Fun times when it becomes common knowledge that to get attention if support isn’t working is to claim a security incident - and everyone starts doing it, hah.

That's pretty easy to deal with: respond with only "not a security issue" if it's not.

Or, actually have support, but that's not Google's style.

Re: I have gained admin access to numerous GCloud Organizations by accident

#97
Surely there should be a way for an owner of a group to revoke these permissions. I am not familiar with the tech though.

If it is not too much hassle I would create a new group, switch to it and delete the old one. This is just one of many reasons corps add prefixes to their naming conventions in the cloud.

I would not go down the path of contacting the companies. You have to see it from their point of view when it comes to security and legal processes. Just because you know that you have not done anything wrong does not mean anything for how they will proceed. They will start from the objectives. Somebody has access to our stuff.

Re: I have gained admin access to numerous GCloud Organizations by accident

#98

Even if you manage to reach out to Google, I doubt they will do anything like remove your group from those roles. From their POV you could be just trying to social engineer them into removing someone who has legitimate access. I think you have better chances contacting people in the org who added your group to those roles.

Agreed. I know Google is famously hard to get in touch with, but I don't understand how this fall on Google's plate or is really Google's fault at all. Maybe if they shared some more info about what IAM group they created that managed to trick people into adding it Google could create rules to ban group names like that from being created?

It's Google's fault because there's no "remove me from having access to this" button.

Re: I have gained admin access to numerous GCloud Organizations by accident

#99
post #45

At least twice I have left a review about a Business on Google Maps and ended up as an admin of their business profile. I don't know what's going on with Google.

Did you reply to your review at least, to complete the circle? /s

Re: I have gained admin access to numerous GCloud Organizations by accident

#100

A few months ago I stumbled upon a bug in a state machine that allowed me to obtain stuff without having to pay for it. It was a weird combination of steps and was kind of hard to explain. I submitted a ticket to the support team advising them in painstaking detail the steps needed to reproduce this vulnerability. They could also look at my account and see that I got stuff without paying. A couple days later I got a…

There are quite a few post on Raymond Chen's "The Old New Thing" blog about bogus security reports e.g. this one [1] from 2022 or this one [2] from 2006. They're often described as requiring you to already be "on the other side of this airtight hatchway" (a Hitchhiker's Guide to the Galaxy reference) because you already need admin rights in order to get admin rights. That seems to suggest that Microsoft takes all sec…

If MS really investigates all bug reports that is good. But, it seems like this should be expected?

From misc. articles I've seen (mainly posted here on HN; I don't buy MS products) MS dismisses bug reports as unimportant and sometimes takes an extremely long time to address known security vulnerabilities.

This VM escape was initially reported as an RDP bug that MS dismissed as unimportant, until it was used as a VM escape against their hypervisor.

https://www.bleepingcomputer.com/news/security/microsoft-ign...

The (in)famous pass-the-hash bug in windows is an example of MS not addressing serious security issues in a timely manner. Windows treats a password hash as equivalent to the password, so you don't even need to crack hashed passwords you've collected from e.g., the registry to authenticate to windows services (MS "protected" against this attack purely client-side). Microsoft acknowledged the issue was real more than a decade before even attempting to fix it.

Apparently it was a difficult bug that included design failures, but over 10 years and multiple versions of windows for an exploit this severe?

A couple days ago a Google Cloud container escape made HN front page. Comments on that article indicated Microsoft Azure had recently suffered the same, but while Google only allowed access to other containers owned by the same tenant, Microsoft's escape allowed access to all tenants on the same host. Google added a second layer of safety in case the first failed (a dedicated VM per host per customer to run each costumer's containers). Microsoft YOLO'd. I don't care enough to research these claims beyond noting that at the time I read them, no one had disputed them.

I don't know if Microsoft is overall still worse than its competitors WRT to security (I suspect it is true). But, Microsoft is certainly not an exemplar for how security should be done.

More on-topic with main thread, nonexistent support is kinda what Google is known for?

At least Google now uses abuse@gmail.com for reporting abuse from their infrastructure instead of forcing the reporting party to go through a god-awful web form (when I handled mail at past orgs, I didn't even bother reporting gmail abuse due to the hoops they made you jump through back then; I also used the RFC-Ignorant RBL to punish them and other sites that did not use the RFC mandated email addresses for reporting abuse with a higher bias toward triggering a SPAM tag on their mail).

Perhaps time for an RFC that mandates security contacts?

Post reply on HN