Live data from Hacker News

Capital One Says Breach Hit 100M Individuals in U.S

bloomberg.com

291–300 of 319 posts

Re: Capital One Says Breach Hit 100M Individuals in U.S

#291

> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.

Kind of like the AT&T "hack" wherein just changing the url leaked other customers info. They were still successfully prosecuted though. And AT&T received no punishment. When a company says jump the USG asks how high.

No way...I don't remember hearing about this. You mean changing the URL from like /data/customer/1 to /data/customer/2 ? And the person who did this was prosecuted? Jeez.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#292

Earlier quoted context omitted.

Is there enough space in an S3 bucket access policy to include DENY rules for every known Tor IP address?

By the sounds of it, the s3 bucket was internally accessible only. But attacker connected through the corp's Web Application Firewall after grabbing the credentials to login to the S3 bucket.

"Internally accessible only" just means you have to have credentials to access it.

You can also add IP address restrictions to a bucket access policy; this was obviously not done here because once she had the credentials, it didn't matter where she was accessing from.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#293

Earlier quoted context omitted.

The whole point of moving to a cloud provider it allow the quick setup and deployment of new projects/products as well as trying to limit your costs. With that sort of open-ended system, unless everyone is always thinking security first and okay with the inevitable slow downs associated with a highly locked down system then you will more than likely always run the risk of this sort of situation.

> The whole point of moving to a cloud provider it allow the quick setup and deployment of new projects/products There is nothing approaching quick setup and deployment at large banks. Not Citibank, but previously worked for a financial firm that sold a copy of it's back office fund administration stack. Large, on site deployment. It would take a month or two to make a simple DNS change so they could locate the servi…

Yep, sounds like a bank to me. I worked at one of the big 4 for 6 years (way too long, I know) and the experience was horrible. It once took us a full year (no exaggeration) to get a single server allocated...and my group was actually one of the well funded teams

Re: Capital One Says Breach Hit 100M Individuals in U.S

#294

Earlier quoted context omitted.

The whole point of moving to a cloud provider it allow the quick setup and deployment of new projects/products as well as trying to limit your costs. With that sort of open-ended system, unless everyone is always thinking security first and okay with the inevitable slow downs associated with a highly locked down system then you will more than likely always run the risk of this sort of situation.

Having everything locked down by default on AWS/Azure/GCP would go a long way to improving the security of the internet. Centralisation isn't healthy, but at least these companies could make a credible impact on data security by pushing the mentality.

All AWS APIs are deny-by-default. Only if a pertinent policy (IAM or resource policy) grants access is it allowed.

IME, the usual mistake many implementors make is that they inadvertently grant too many privileges and often to the wrong audience.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#295

> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.

What do these queries look like...

Re: Capital One Says Breach Hit 100M Individuals in U.S

#296

Earlier quoted context omitted.

Good lord. -Paige left code used in the "attack" on her GitHub. -Paige left text files with unencrypted data there, too. -Paige openly posted about it in an open (!!!) Slack channel and publicly named her VPN service of choice, which of course, matched access logs AND GitHub server logs. (Also tor, which the FBI agent was able to confirm and add yet another data point) -Paige said "I have a leak proof IPredator route…

Why do you use first name here instead of last? No one calls Snowden just Edward, this comes across as a form of degrading women to girls.

Mostly people call me by my first name and I do the same to most people (likely more to men than women, if I had to guess). People call Edward Snowden by his last name because it's unique and catchy.

Theo de Raadt is often just called "Theo" here for similar reasons. Rarely if ever have I seen him called "de Raadt" on this forum.

Your comment is unfortunately typical of drive-by Internet outrage these days.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#297

Earlier quoted context omitted.

Miss the LevelMoney folks... Yeah AWS can’t protect you against a misconfigured environment

The problem with AWS (and other cloud providers) is that it's nearly impossible to properly configure an environment because of how many different methods there are to gain access to resources. Capital One has been all in on AWS and has dedicated an immense amount of time and money to developing systems for managing their AWS resources (Cloud Custodian for instance) and yet they still couldn't protect their data. Wha…

I think AWS's use of synthetic reasoning in this space is groundbreaking and shows the way to go forward for complex systems in the future.

See also: https://aws.amazon.com/blogs/security/protect-sensitive-data...

Re: Capital One Says Breach Hit 100M Individuals in U.S

#298

Earlier quoted context omitted.

“Didn’t require” is a very precise way of stating a truth about the vulnerability that was exploited, while neither confirming nor denying whether her role at Amazon was in some way responsible for her discovering the vulnerability. (If I could query all AWS permissions for publicly exploitable permissions, that would comply, for example.)

The AWS spokesman quoted in the article also explicitly says it wasn't a vulnerability.

Do you consider an access control misconfiguration to be a vulnerability? Does Amazon?

Point stands; they’re being very careful to say that there aren’t any CVEs, but they are also very carefully not saying whether she abused the privileges of her role to identify misconfigurations more rapidly than she could have otherwise.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#299
post #268

Earlier quoted context omitted.

According to the Daily Mail article linked above, they've known since mid-July. They could have issued a statement today if they wanted to. I can understand why they didn't do it earlier, to minimize the number of press cycles with their name attached to this incident. But if this were my credit card company, I would be pretty irked to be finding out about it weeks after the company knew, from the news.

The FBI is probably to blame there, announcing before charges files would be interfering with their investigation

If this is the case, they should have had an announcement ready to go for yesterday. The absence of a response makes it seem like either they’re not taking the incident seriously enough, or they still don’t know the full scope and want to delay their announcement until then.

Either way, not good.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#300
post #247
post #172

Earlier quoted context omitted.

Given that Ms. Thompson is transgender [0], it's likely a lot was stacked against her emotionally. 40% of trans-identifying individuals to attempt suicide [1]. This is a disappointing omission from the reporting and the road that lies ahead for Ms. Thomson in the hands of the federal prison system is surely horrifying. [0] https://twitter.com/0xA3A97B6C/status/1152518528907354112 [1] https://transequality.org/sites/d…

I wonder if it could be an effective legal defense for her, akin to plot of Soderbergh Side Effects (2013). "not guilty by reason of insanity" due to hormonal treatment, there are precedents https://www.charlotteobserver.com/news/local/crime/article64... https://ps.psychiatryonline.org/doi/full/10.1176/appi.ps.53.... https://www.mercurynews.com/2012/08/21/man-acquitted-after-a...

As a transgender person, I can tell you that estradiol absolutely cannot induce insanity. At the absolute most, it can screw with your emotions in the same exact ways as PMS (and PMS is indeed caused by hormonal fluctuations).

The idea that it's on the same level as ambien is absurd.

Post reply on HN