I don't work for Snowflake but I spend a lot of time working with them and their SE organisation. When working and building demos with clients, SEs create demonstration environments on the same $400 Snowflake demo accounts anyone can. To build demos the client would grant access to that SE. The SE would take some of the data to the demo environment and then work on it. This is further confirmed by the name of the env…
Just because there isn’t a “novel exploit” doesn’t mean this isn’t a big deal. Snowflake is susceptible to their SE’s having credentials stolen. These credentials can bypass MFA. And per the article, they have no expiry. That’s strikes one, two, and three. Snowflake’s security practices lead to a situation where their customers are either required, or at minimum encouraged, to share access to broad datasets with Snow…
Data stolen because of some crazy multi-exploit zero day chain. Well that is understandable, i don't blame the company.
Data stolen because no 2FA support? In 2024 that is just embarassing.