Live data from Hacker News

Hacker confirms access through infostealer infection [withdrawn]

hudsonrock.com

121–130 of 235 posts

Re: Hacker confirms access through infostealer infection [withdrawn]

#122
> were able to sign into a Snowflake employee’s ServiceNow account using stolen credentials, thus bypassing OKTA

It's probably not technically relevant to the breach, but it's at least interesting that the CEO of Snowflake is the former CEO of ServiceNow: https://en.wikipedia.org/wiki/Frank_Slootman

Re: Hacker confirms access through infostealer infection [withdrawn]

#123

Earlier quoted context omitted.

Yeah it is a bit muddled honestly. I had to read it a couple times and I still don’t completely get what happened: 1. Employee installs a key logger 2. Snowflake does not expire session cookies 3. Malware steals their session cookie and password, so can bypass employee MFA/okta 4. ??? 5. Somehow this one employee has admin access to 4000 snowflake instances

Step 4 is right in the article: "they were able to sign into a Snowflake employee’s ServiceNow account using stolen credentials, thus bypassing OKTA which is located on lift.snowflake.com. Following the infiltration, the threat actor claims that they were able to generate session tokens, which enabled them to exfiltrate massive amounts of data from the company"

Yes, but how should ServiceNow create session tokens if it is not part of the SSO system? I don't know enough about ServiceNow, but I think every large company has some products that are not part of their-SSO system. So that makes sense, but I am not sure about the next step.

Re: Hacker confirms access through infostealer infection [withdrawn]

#124
post #122

> were able to sign into a Snowflake employee’s ServiceNow account using stolen credentials, thus bypassing OKTA It's probably not technically relevant to the breach, but it's at least interesting that the CEO of Snowflake is the former CEO of ServiceNow: https://en.wikipedia.org/wiki/Frank_Slootman

The current CEO is Sridhar Ramaswamy

Re: Hacker confirms access through infostealer infection [withdrawn]

#125
post #61

Earlier quoted context omitted.

Great, so these companies do not give a flying fuck about their customer data in making sure the data stored at cloud storage companies are end to end encrypted. To think these random cloud storage companies can access your bank information is utterly shocking.

> To think these random cloud storage companies can access your bank information is utterly shocking. Honestly this sort of thing shouldn't be shocking at all.

It’s been a while since I’ve been a Snowflake customer, but I do recall that Snowflake has a mode where the customer owns their own encryption key for their data. Snowflake employees (even admins with the highest access) have no access to the customer’s data unless the customer grants explicit access. It’d take a pretty serious breach on their compute notes to exfiltrate data.

https://docs.snowflake.com/en/user-guide/security-encryption...

Re: Hacker confirms access through infostealer infection [withdrawn]

#126
post #122

> were able to sign into a Snowflake employee’s ServiceNow account using stolen credentials, thus bypassing OKTA It's probably not technically relevant to the breach, but it's at least interesting that the CEO of Snowflake is the former CEO of ServiceNow: https://en.wikipedia.org/wiki/Frank_Slootman

The current CEO is Sridhar Ramaswamy

Yes (since February), although according to the article the infection happened in October 2023 during Slootman's tenure.

Re: Hacker confirms access through infostealer infection [withdrawn]

#127

Earlier quoted context omitted.

Indeed, the less novel the exploit the more embarassing it is. Data stolen because of some crazy multi-exploit zero day chain. Well that is understandable, i don't blame the company. Data stolen because no 2FA support? In 2024 that is just embarassing.

Yes, that's also what I think must have happened—missing 2FA. But it seems it's also not mandatory within Snowflake accounts also, from what I understand from the general message. I've never used Snowflake and assumed that because you push all your data into it, it probably has 2FA enabled by default. Is it optional?

I don't quite understand how Snowflake works.

My understanding was that you had to grant storage access (e.g. S3) and compute access (e.g. EC2) from your account to Snowflake, which would then use said resources to perform queries that you issue from their hosted web UI.

In that case it would mean stealing the Snowflake demo account of a SE should not expose your data unless you forgot to revoke their access to your underlying resources.

Can someone explain if that is how it works?

Re: Hacker confirms access through infostealer infection [withdrawn]

#128
post #104

Hi, Felipe at Snowflake here. Here is the latest from Snowflake on this issue: https://community.snowflake.com/s/question/0D5VI00000Emyl00A... We'll keep updating that URL with any further news.

The salesforce.com servers are temporarily unable to respond to your request. We apologize for the inconvenience. Thank you for your patience, and please try again in a few moments.
Post reply on HN