Live data from Hacker News

Hacker confirms access through infostealer infection [withdrawn]

hudsonrock.com

101–110 of 235 posts

Re: Hacker confirms access through infostealer infection [withdrawn]

#101
post #56

It's unclear if it's customer metadata or real customer data data?

Santander claims:

"Following an investigation, we have now confirmed that certain information relating to customers of Santander Chile, Spain and Uruguay, as well as all current and some former Santander employees of the group had been accessed. Customer data in all other Santander markets and businesses are not affected."

https://www.santander.com/en/stories/statement

Re: Hacker confirms access through infostealer infection [withdrawn]

#102

I don't work for Snowflake but I spend a lot of time working with them and their SE organisation. When working and building demos with clients, SEs create demonstration environments on the same $400 Snowflake demo accounts anyone can. To build demos the client would grant access to that SE. The SE would take some of the data to the demo environment and then work on it. This is further confirmed by the name of the env…

Just because there isn’t a “novel exploit” doesn’t mean this isn’t a big deal.

Snowflake is susceptible to their SE’s having credentials stolen. These credentials can bypass MFA. And per the article, they have no expiry. That’s strikes one, two, and three.

Snowflake’s security practices lead to a situation where their customers are either required, or at minimum encouraged, to share access to broad datasets with Snowflake employees. That’s strike four.

Yes, there is also issue here that the customers are responsible themselves for not granting too broad access, and that’s on them. But it’s also on Snowflake for not having a better system that doesn’t require this access, or at minimum not having better oversight and control over this transitive access.

Once these accounts are granted access to a customer’s data, they aren’t “demo accounts” anymore. They’re real accounts, with real, very valuable data, and they should be treated as such.

Edit to add: it is worth noting that Snowflake claims the demo account did not have access to customer data and wasn’t the source of the leak, which is in contradiction with what the attackers claim.

Re: Hacker confirms access through infostealer infection [withdrawn]

#103

Earlier quoted context omitted.

something doesn't add up, because I don't see how this extrapolates from stealing privileged Snowflake employee credentials. How does that become a keylogger on a client's computer?

Yeah it is a bit muddled honestly. I had to read it a couple times and I still don’t completely get what happened: 1. Employee installs a key logger 2. Snowflake does not expire session cookies 3. Malware steals their session cookie and password, so can bypass employee MFA/okta 4. ??? 5. Somehow this one employee has admin access to 4000 snowflake instances

Step 4 is right in the article:

"they were able to sign into a Snowflake employee’s ServiceNow account using stolen credentials, thus bypassing OKTA which is located on lift.snowflake.com.

Following the infiltration, the threat actor claims that they were able to generate session tokens, which enabled them to exfiltrate massive amounts of data from the company"

Re: Hacker confirms access through infostealer infection [withdrawn]

#105
post #96

I don't work for Snowflake but I spend a lot of time working with them and their SE organisation. When working and building demos with clients, SEs create demonstration environments on the same $400 Snowflake demo accounts anyone can. To build demos the client would grant access to that SE. The SE would take some of the data to the demo environment and then work on it. This is further confirmed by the name of the env…

The whole blog post reeks of extreme self-congratulation and youre right, a total scum move to expose the victim. Altogether very weak performance from Hudson Rock.

It seems somehow like an Indiehacker page, probably taken too lightheartedly. Additionally, the related pages have no real contact details.

Re: Hacker confirms access through infostealer infection [withdrawn]

#106
post #90

Earlier quoted context omitted.

Agreed, mentioning the login name of the compromised account seems really unprofessional and unnecessary.

This was a really effective anti-ad for Hudson Rock.

Generally, I like the page and the openness of the API behind it. It is much more common for people to talk about haveibeenpwned as a source for leaked credentials, but the site claims to have over 20 million computer entries from log stealers ... and every computer has XX password.. But yes probably this was written in a hurry to catch the wave?

Re: Hacker confirms access through infostealer infection [withdrawn]

#108
post #104

Hi, Felipe at Snowflake here. Here is the latest from Snowflake on this issue: https://community.snowflake.com/s/question/0D5VI00000Emyl00A... We'll keep updating that URL with any further news.

Will there be any direct comment regarding the article here?

Re: Hacker confirms access through infostealer infection [withdrawn]

#109
post #9

The screenshots of the chat logs are really something. This firm claims to be in communication with the actual criminal, and the actual criminal says that using their firm would have helped prevent the breach. I have updated my sense of the firm's trustworthiness accordingly.

It's a common euphemism in ransomware and protection rackets in general. One of my favourites is the message the akira group leaves in infected machines that goes something like:

    Congratulations, you have passed a surprise information
    security audit and become a victim of ransomware.

    [...]

    We offer:

    1) full decryption assistance
    2) evidence of data removal
    3) security report on vulnerabilities we found
    4) guarantees not to publish or sell your data
    5) guarantees not to attack you in the future
They're just a security consulting company that you didn't know you had on payroll!

Btw I looked at what they provide as evidence of data removal (2) and it's literally just the stdout of `rm -vrf data` lol. I mean, I get that it's impossible to provide evidence of absence, plus the victims have no leverage anyway, but I dig the theatrics.

Re: Hacker confirms access through infostealer infection [withdrawn]

#110
post #104

Hi, Felipe at Snowflake here. Here is the latest from Snowflake on this issue: https://community.snowflake.com/s/question/0D5VI00000Emyl00A... We'll keep updating that URL with any further news.

Will there be any direct comment regarding the article here?

the ad for protection services?
Post reply on HN