Live data from Hacker News

Why CISA Is Warning CISOs About a Breach at Sisense

krebsonsecurity.com

11–20 of 62 posts

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#12
> Those sources said the breach appears to have started when the attackers somehow gained access to the company’s Gitlab code repository, and in that repository was a token or credential that gave the bad guys access to Sisense’s Amazon S3 buckets in the cloud.

So plaintext AWS credentials checked into source control.

> Both sources said the attackers used the S3 access to copy and exfiltrate several terabytes worth of Sisense customer data, which apparently included millions of access tokens, email account passwords, and even SSL certificates.

And those credentials can access tons of other credentials, also stored in plaintext.

Even if the security policies didn’t pick this up, didn’t they at least having billing alerts for the terabytes of AWS bandwidth?

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#14
post #12

> Those sources said the breach appears to have started when the attackers somehow gained access to the company’s Gitlab code repository, and in that repository was a token or credential that gave the bad guys access to Sisense’s Amazon S3 buckets in the cloud. So plaintext AWS credentials checked into source control. > Both sources said the attackers used the S3 access to copy and exfiltrate several terabytes worth…

This feels... ...ridiculous in this day and age.

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#15
post #12

> Those sources said the breach appears to have started when the attackers somehow gained access to the company’s Gitlab code repository, and in that repository was a token or credential that gave the bad guys access to Sisense’s Amazon S3 buckets in the cloud. So plaintext AWS credentials checked into source control. > Both sources said the attackers used the S3 access to copy and exfiltrate several terabytes worth…

Isn't S3 egress billed at something like $0.01/GB? Even if you assume they exfiltrated 100TB, you're only talking about maybe $1k. I can't imagine they'd have alerts fine-tuned enough to catch that without driving their on-call staff crazy.

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#16
> If they are telling people to reset credentials, that means it was not encrypted.

I'm not sure that follows. If I leaked customer information, even encrypted, I believe it would still be responsible to tell people and give them the option to react. Encryption is not foolproof technology. Vulnerable to cracking, or perhaps the key could simply be leaked as well.

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#17

> If they are telling people to reset credentials, that means it was not encrypted. I'm not sure that follows. If I leaked customer information, even encrypted, I believe it would still be responsible to tell people and give them the option to react. Encryption is not foolproof technology. Vulnerable to cracking, or perhaps the key could simply be leaked as well.

Possibly the credentials were encrypted, but the attackers got the encryption keys as well?

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#18
post #12

> Those sources said the breach appears to have started when the attackers somehow gained access to the company’s Gitlab code repository, and in that repository was a token or credential that gave the bad guys access to Sisense’s Amazon S3 buckets in the cloud. So plaintext AWS credentials checked into source control. > Both sources said the attackers used the S3 access to copy and exfiltrate several terabytes worth…

This feels... ...ridiculous in this day and age.

On the other hand, once they had source code access, does it matter?

People play make believe about this stuff. “The practice I feel strongly about, it’s secure. And the other guy is a moron.” The XZ crisis shows how little credential isolation matters. Maybe even at Google, you could work there and feel very strongly about their security practices, and then governments have access to everything anyway, at the front end proxies or whatever. It’s important to pay attention to security, but I think programmer resources should focus on “cheating,” not “security.”

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#19

Earlier quoted context omitted.

This feels... ...ridiculous in this day and age.

On the other hand, once they had source code access, does it matter? People play make believe about this stuff. “The practice I feel strongly about, it’s secure. And the other guy is a moron.” The XZ crisis shows how little credential isolation matters. Maybe even at Google, you could work there and feel very strongly about their security practices, and then governments have access to everything anyway, at the front…

[deleted]

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#20
post #4

Ouch """ Earlier today, a public relations firm working with Sisense reached out to learn if KrebsOnSecurity planned to publish any further updates on their breach (KrebsOnSecurity posted a screenshot of the CISO’s customer email to both LinkedIn and Mastodon on Wednesday evening). The PR rep said Sisense wanted to make sure they had an opportunity to comment before the story ran. But when confronted with the details…

They wanted an opportunity to comment. That implies no obligation to comment.
Post reply on HN