Live data from Hacker News

Hacker confirms access through infostealer infection [withdrawn]

hudsonrock.com

111–120 of 235 posts

Re: Hacker confirms access through infostealer infection [withdrawn]

#111

I don't work for Snowflake but I spend a lot of time working with them and their SE organisation. When working and building demos with clients, SEs create demonstration environments on the same $400 Snowflake demo accounts anyone can. To build demos the client would grant access to that SE. The SE would take some of the data to the demo environment and then work on it. This is further confirmed by the name of the env…

Just because there isn’t a “novel exploit” doesn’t mean this isn’t a big deal. Snowflake is susceptible to their SE’s having credentials stolen. These credentials can bypass MFA. And per the article, they have no expiry. That’s strikes one, two, and three. Snowflake’s security practices lead to a situation where their customers are either required, or at minimum encouraged, to share access to broad datasets with Snow…

Indeed, the less novel the exploit the more embarassing it is.

Data stolen because of some crazy multi-exploit zero day chain. Well that is understandable, i don't blame the company.

Data stolen because no 2FA support? In 2024 that is just embarassing.

Re: Hacker confirms access through infostealer infection [withdrawn]

#112

Earlier quoted context omitted.

Will there be any direct comment regarding the article here?

the ad for protection services?

Yes, I know... I've seen that, also the posts on Reddit/HN and so on, but I am just curious if there is some truth to it.

Re: Hacker confirms access through infostealer infection [withdrawn]

#113

Earlier quoted context omitted.

Just because there isn’t a “novel exploit” doesn’t mean this isn’t a big deal. Snowflake is susceptible to their SE’s having credentials stolen. These credentials can bypass MFA. And per the article, they have no expiry. That’s strikes one, two, and three. Snowflake’s security practices lead to a situation where their customers are either required, or at minimum encouraged, to share access to broad datasets with Snow…

Indeed, the less novel the exploit the more embarassing it is. Data stolen because of some crazy multi-exploit zero day chain. Well that is understandable, i don't blame the company. Data stolen because no 2FA support? In 2024 that is just embarassing.

Yes, that's also what I think must have happened—missing 2FA. But it seems it's also not mandatory within Snowflake accounts also, from what I understand from the general message.

I've never used Snowflake and assumed that because you push all your data into it, it probably has 2FA enabled by default. Is it optional?

Re: Hacker confirms access through infostealer infection [withdrawn]

#114
post #7

At least based on the wording of the perpetrator, Snowflake really did have the system designed in a way where a single administrator account gives you carte blanche to everything. > On may 31st, Snowflake released a statement in which they claim that they are investigating an industry-wide identity-based attacks that have impacted “some” of their customers. https://community.snowflake.com/s/question/0D5VI00000Emyl00…

yeah, the perpetrator is wrong: nothing in production was accessed, no customer data either. totally being mischaracterized in the hudson post.

Re: Hacker confirms access through infostealer infection [withdrawn]

#115
post #9

The screenshots of the chat logs are really something. This firm claims to be in communication with the actual criminal, and the actual criminal says that using their firm would have helped prevent the breach. I have updated my sense of the firm's trustworthiness accordingly.

Sounds like implied extortion to me.

Re: Hacker confirms access through infostealer infection [withdrawn]

#116
post #9

The screenshots of the chat logs are really something. This firm claims to be in communication with the actual criminal, and the actual criminal says that using their firm would have helped prevent the breach. I have updated my sense of the firm's trustworthiness accordingly.

they're also totally wrong about what they had access to . . .

Re: Hacker confirms access through infostealer infection [withdrawn]

#117
post #74

Earlier quoted context omitted.

Can a tool like Snowflake work if it doesn’t have access to the unencrypted data?

No. E2E encryption doesn't really apply here.

lol everyone in this thread is wrong about everything basically.

Re: Hacker confirms access through infostealer infection [withdrawn]

#119
> Okta

Just how many pwns involve this keyword? Between Okta itself being pwned and it allowing stupid shit like ignoring expiry, I am strongly inclined to believe that rolling your own login system might be the strongest security posture these days. Last I heard, Okta doesn't use any form of FIDO internally: how completely and utterly worthless.

Post reply on HN