Earlier quoted context omitted.
Great, so these companies do not give a flying fuck about their customer data in making sure the data stored at cloud storage companies are end to end encrypted. To think these random cloud storage companies can access your bank information is utterly shocking.
Can a tool like Snowflake work if it doesn’t have access to the unencrypted data?
Hacker confirms access through infostealer infection [withdrawn]
91–100 of 235 posts
Re: Hacker confirms access through infostealer infection [withdrawn]
#92The screenshots of the chat logs are really something. This firm claims to be in communication with the actual criminal, and the actual criminal says that using their firm would have helped prevent the breach. I have updated my sense of the firm's trustworthiness accordingly.
This is just pure speculation, but it kind of looks like the hacker was being ignored by Snowflake, so they somehow got in touch with Hudson Rock and offered them this promotional opportunity (to break the news, more than the throwaway line in the article) with the goal of retaliating against Snowflake for failing to pay the ransom. And Hudson Rock agreed to play along and hype up the story, presenting it as a bigger…
Re: Hacker confirms access through infostealer infection [withdrawn]
#93> The data from these companies was put up for sale on the Russian-speaking cybercrime forum Just russia being russia, as usual.
Your daily evidence that modern Russia is essentially just an organized crime ring with oil reserves and nukes.
Re: Hacker confirms access through infostealer infection [withdrawn]
#94Earlier quoted context omitted.
That particular exchange is bizarre and cartoonish. I don’t know what to make of it. “should have bought protection from Hudson Rock could have saved them this one” “yes i agree it wouldve helped for sure”
seems like a shameless marketing plug to me
Re: Hacker confirms access through infostealer infection [withdrawn]
#95I don't work for Snowflake but I spend a lot of time working with them and their SE organisation. When working and building demos with clients, SEs create demonstration environments on the same $400 Snowflake demo accounts anyone can. To build demos the client would grant access to that SE. The SE would take some of the data to the demo environment and then work on it. This is further confirmed by the name of the env…
Agreed, mentioning the login name of the compromised account seems really unprofessional and unnecessary.
Re: Hacker confirms access through infostealer infection [withdrawn]
#96I don't work for Snowflake but I spend a lot of time working with them and their SE organisation. When working and building demos with clients, SEs create demonstration environments on the same $400 Snowflake demo accounts anyone can. To build demos the client would grant access to that SE. The SE would take some of the data to the demo environment and then work on it. This is further confirmed by the name of the env…
Re: Hacker confirms access through infostealer infection [withdrawn]
#97At least based on the wording of the perpetrator, Snowflake really did have the system designed in a way where a single administrator account gives you carte blanche to everything. > On may 31st, Snowflake released a statement in which they claim that they are investigating an industry-wide identity-based attacks that have impacted “some” of their customers. https://community.snowflake.com/s/question/0D5VI00000Emyl00…
One SE is working on many accounts. Snowflake SEs don't build within the client environment typically. They set up a demo account like you or I do with the $400 in credits. SEs are constantly starting these. Why? They expire after the fact. The SE builds in the created demo account and shows the client. After 30 days Snowflake locks the account (no credit card) and subsequently drops the demo instance and data.
For an SE to do the work the customer can do one or more of the following: The customer's SF instance shares data to that demo instance created by the SE AND/OR the customer has given access to that Snowflake SE through SSO.
Either way, this is more of orgs not being restrictive in their security posture. There is nothing novel about this exploit other than they found an SE who was working very hard and clients who had not properly scoped the security permissions of an employee/contractoe/guest.
Re: Hacker confirms access through infostealer infection [withdrawn]
#98I don't work for Snowflake but I spend a lot of time working with them and their SE organisation. When working and building demos with clients, SEs create demonstration environments on the same $400 Snowflake demo accounts anyone can. To build demos the client would grant access to that SE. The SE would take some of the data to the demo environment and then work on it. This is further confirmed by the name of the env…
The whole blog post reeks of extreme self-congratulation and youre right, a total scum move to expose the victim. Altogether very weak performance from Hudson Rock.
Re: Hacker confirms access through infostealer infection [withdrawn]
#99Snowflake internal staff do not have access to read customer data, unless a customer grants it. Customers can use their own KMS to generate table keys. Snowflake has a lot of security features. But still, customers may well misconfigure their own Snowflake accounts and therefore be vulnerable. A well configured Snowflake account: - does not allow any access from the public Internet. Network policies set by the custom…
By default, no. But it is standard operating procedure for sales engineers to request and be given access to customer data so they can build demos.
Re: Hacker confirms access through infostealer infection [withdrawn]
#100Earlier quoted context omitted.
I'm not sure it does, perhaps it violates the spirit but not the letter. You need a way to give your employees access to customer data; for support cases. So you build a "request access" form in your ITSM. Now you can tick off every box related to certification: There is a process. Only authorized persons have access. Every aspect of it can be audited. Later, perhaps sales people (the 1000's of new joiners) start usi…
> What other criteria would apply? Many companies have processes that require 2 or more humans in the loop for sensitive prod data.