Google Apps Loophole, Let You Access Other’s Domain Login Details
jajodia-saket.sjbn.co
jajodia-saket.sjbn.co
I also know of the number of serious Google bugs we've run into that we just didn't report because, quite frankly, we gave up on any bug reporting process having any effect.
Contrast this to Amazon where our rep can put us in contact with engineers in a few minutes, and who are of the caliber that they can e.g. help us recover a database where the RAID volume Amazon hosted it on was damaged in a power outage.
I have absolutely no faith in them to actually sort something out in a reasonable amount of time.
Conversely, we used Office365 in the end and it blew up(ironically with a similar issue) during the trials. We had someone useful on the phone helping us in under 20 minutes!
I've not had much luck with Amazon, particularly S3 as we had a number of issues with the .Net client and they weren't very helpful. Stackoverflow was far more useful but I don't want to trust stackoverflow as a long term support option!
Google is a little weird. They've insisted on e.g. a conference calls with a half-dozen guys from Google, including one executive-level. That call was entirely one-sided. They told us about all sorts of features they were building because they thought our market segment needed them (zero of which were actually useful to us, and which they could have discovered with even very minimal market research). In that conference call, they didn't listen to any of our bugs or feature requests. Whenever we've submitted support requests through official channels, they went into what was effectively a black hole (sometimes, we'd get a slightly derogatory response from someone clearly powerless and clueless). Things we submit to through high-level contacts get handled -- roughly as well although slightly slower than normal, paid contacts at Amazon. The culture at Google is a little weird, at least with respect to dealing with large customers.
We do use Google Apps internally. It's imperfect and has showstoppers, but in my experience, corporate IT departments are even more imperfect, and have even more showstoppers. Based on our experiences, I'd be absolutely terrified of using Google for anything customer-facing.
They should probably give him the maximum reward just to attempt to save face on this.
Anyways, from now on (from http://www.google.com/about/company/rewardprogram.html):
>If you have found a vulnerability, please contact us at security@google.com. Feel free to be succinct: the mailbox is attended by security engineers, and a short proof-of-concept link is more valuable than a video explaining the consequences of an XSS bug. Oh: if necessary, you can use this PGP key.
Well done Saket, thanks for waiting for the bug to get fixed before posting your article.
Then again, you'd need to buy your domain through Google Apps to notice this. Maybe not many people buy their domain through Google Apps?
I'm interested to know how long this bug was out in the wild before it was found. Months? Days?
Good find Saket and great story.
He's a better man than me. I probably would have hung up and posted directly to here instead.
Very scary. But what stellar alternatives exist for startups?