> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.
Kind of like the AT&T "hack" wherein just changing the url leaked other customers info. They were still successfully prosecuted though. And AT&T received no punishment. When a company says jump the USG asks how high.
Capital One Says Breach Hit 100M Individuals in U.S
291–300 of 319 posts
Re: Capital One Says Breach Hit 100M Individuals in U.S
#292Earlier quoted context omitted.
Is there enough space in an S3 bucket access policy to include DENY rules for every known Tor IP address?
By the sounds of it, the s3 bucket was internally accessible only. But attacker connected through the corp's Web Application Firewall after grabbing the credentials to login to the S3 bucket.
You can also add IP address restrictions to a bucket access policy; this was obviously not done here because once she had the credentials, it didn't matter where she was accessing from.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#293Earlier quoted context omitted.
The whole point of moving to a cloud provider it allow the quick setup and deployment of new projects/products as well as trying to limit your costs. With that sort of open-ended system, unless everyone is always thinking security first and okay with the inevitable slow downs associated with a highly locked down system then you will more than likely always run the risk of this sort of situation.
> The whole point of moving to a cloud provider it allow the quick setup and deployment of new projects/products There is nothing approaching quick setup and deployment at large banks. Not Citibank, but previously worked for a financial firm that sold a copy of it's back office fund administration stack. Large, on site deployment. It would take a month or two to make a simple DNS change so they could locate the servi…
Re: Capital One Says Breach Hit 100M Individuals in U.S
#294Earlier quoted context omitted.
The whole point of moving to a cloud provider it allow the quick setup and deployment of new projects/products as well as trying to limit your costs. With that sort of open-ended system, unless everyone is always thinking security first and okay with the inevitable slow downs associated with a highly locked down system then you will more than likely always run the risk of this sort of situation.
Having everything locked down by default on AWS/Azure/GCP would go a long way to improving the security of the internet. Centralisation isn't healthy, but at least these companies could make a credible impact on data security by pushing the mentality.
IME, the usual mistake many implementors make is that they inadvertently grant too many privileges and often to the wrong audience.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#295> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#296Earlier quoted context omitted.
Good lord. -Paige left code used in the "attack" on her GitHub. -Paige left text files with unencrypted data there, too. -Paige openly posted about it in an open (!!!) Slack channel and publicly named her VPN service of choice, which of course, matched access logs AND GitHub server logs. (Also tor, which the FBI agent was able to confirm and add yet another data point) -Paige said "I have a leak proof IPredator route…
Why do you use first name here instead of last? No one calls Snowden just Edward, this comes across as a form of degrading women to girls.
Theo de Raadt is often just called "Theo" here for similar reasons. Rarely if ever have I seen him called "de Raadt" on this forum.
Your comment is unfortunately typical of drive-by Internet outrage these days.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#297Earlier quoted context omitted.
Miss the LevelMoney folks... Yeah AWS can’t protect you against a misconfigured environment
The problem with AWS (and other cloud providers) is that it's nearly impossible to properly configure an environment because of how many different methods there are to gain access to resources. Capital One has been all in on AWS and has dedicated an immense amount of time and money to developing systems for managing their AWS resources (Cloud Custodian for instance) and yet they still couldn't protect their data. Wha…
See also: https://aws.amazon.com/blogs/security/protect-sensitive-data...
Re: Capital One Says Breach Hit 100M Individuals in U.S
#298Earlier quoted context omitted.
“Didn’t require” is a very precise way of stating a truth about the vulnerability that was exploited, while neither confirming nor denying whether her role at Amazon was in some way responsible for her discovering the vulnerability. (If I could query all AWS permissions for publicly exploitable permissions, that would comply, for example.)
The AWS spokesman quoted in the article also explicitly says it wasn't a vulnerability.
Point stands; they’re being very careful to say that there aren’t any CVEs, but they are also very carefully not saying whether she abused the privileges of her role to identify misconfigurations more rapidly than she could have otherwise.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#299Earlier quoted context omitted.
According to the Daily Mail article linked above, they've known since mid-July. They could have issued a statement today if they wanted to. I can understand why they didn't do it earlier, to minimize the number of press cycles with their name attached to this incident. But if this were my credit card company, I would be pretty irked to be finding out about it weeks after the company knew, from the news.
The FBI is probably to blame there, announcing before charges files would be interfering with their investigation
Either way, not good.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#300Earlier quoted context omitted.
Given that Ms. Thompson is transgender [0], it's likely a lot was stacked against her emotionally. 40% of trans-identifying individuals to attempt suicide [1]. This is a disappointing omission from the reporting and the road that lies ahead for Ms. Thomson in the hands of the federal prison system is surely horrifying. [0] https://twitter.com/0xA3A97B6C/status/1152518528907354112 [1] https://transequality.org/sites/d…
I wonder if it could be an effective legal defense for her, akin to plot of Soderbergh Side Effects (2013). "not guilty by reason of insanity" due to hormonal treatment, there are precedents https://www.charlotteobserver.com/news/local/crime/article64... https://ps.psychiatryonline.org/doi/full/10.1176/appi.ps.53.... https://www.mercurynews.com/2012/08/21/man-acquitted-after-a...
The idea that it's on the same level as ambien is absurd.