Damn that is so not classy. Who approved that?
Hacker confirms access through infostealer infection [withdrawn]
121–130 of 235 posts
Re: Hacker confirms access through infostealer infection [withdrawn]
#122It's probably not technically relevant to the breach, but it's at least interesting that the CEO of Snowflake is the former CEO of ServiceNow: https://en.wikipedia.org/wiki/Frank_Slootman
Re: Hacker confirms access through infostealer infection [withdrawn]
#123Earlier quoted context omitted.
Yeah it is a bit muddled honestly. I had to read it a couple times and I still don’t completely get what happened: 1. Employee installs a key logger 2. Snowflake does not expire session cookies 3. Malware steals their session cookie and password, so can bypass employee MFA/okta 4. ??? 5. Somehow this one employee has admin access to 4000 snowflake instances
Step 4 is right in the article: "they were able to sign into a Snowflake employee’s ServiceNow account using stolen credentials, thus bypassing OKTA which is located on lift.snowflake.com. Following the infiltration, the threat actor claims that they were able to generate session tokens, which enabled them to exfiltrate massive amounts of data from the company"
Re: Hacker confirms access through infostealer infection [withdrawn]
#124> were able to sign into a Snowflake employee’s ServiceNow account using stolen credentials, thus bypassing OKTA It's probably not technically relevant to the breach, but it's at least interesting that the CEO of Snowflake is the former CEO of ServiceNow: https://en.wikipedia.org/wiki/Frank_Slootman
Re: Hacker confirms access through infostealer infection [withdrawn]
#125Earlier quoted context omitted.
Great, so these companies do not give a flying fuck about their customer data in making sure the data stored at cloud storage companies are end to end encrypted. To think these random cloud storage companies can access your bank information is utterly shocking.
> To think these random cloud storage companies can access your bank information is utterly shocking. Honestly this sort of thing shouldn't be shocking at all.
https://docs.snowflake.com/en/user-guide/security-encryption...
Re: Hacker confirms access through infostealer infection [withdrawn]
#126> were able to sign into a Snowflake employee’s ServiceNow account using stolen credentials, thus bypassing OKTA It's probably not technically relevant to the breach, but it's at least interesting that the CEO of Snowflake is the former CEO of ServiceNow: https://en.wikipedia.org/wiki/Frank_Slootman
The current CEO is Sridhar Ramaswamy
Re: Hacker confirms access through infostealer infection [withdrawn]
#127Earlier quoted context omitted.
Indeed, the less novel the exploit the more embarassing it is. Data stolen because of some crazy multi-exploit zero day chain. Well that is understandable, i don't blame the company. Data stolen because no 2FA support? In 2024 that is just embarassing.
Yes, that's also what I think must have happened—missing 2FA. But it seems it's also not mandatory within Snowflake accounts also, from what I understand from the general message. I've never used Snowflake and assumed that because you push all your data into it, it probably has 2FA enabled by default. Is it optional?
My understanding was that you had to grant storage access (e.g. S3) and compute access (e.g. EC2) from your account to Snowflake, which would then use said resources to perform queries that you issue from their hosted web UI.
In that case it would mean stealing the Snowflake demo account of a SE should not expose your data unless you forgot to revoke their access to your underlying resources.
Can someone explain if that is how it works?
Re: Hacker confirms access through infostealer infection [withdrawn]
#128Hi, Felipe at Snowflake here. Here is the latest from Snowflake on this issue: https://community.snowflake.com/s/question/0D5VI00000Emyl00A... We'll keep updating that URL with any further news.
Re: Hacker confirms access through infostealer infection [withdrawn]
#129Was their intent to dox the employee while discussing this beach? They show the employee’s username, which is easily Googleable.
Re: Hacker confirms access through infostealer infection [withdrawn]
#130Hi, Felipe at Snowflake here. Here is the latest from Snowflake on this issue: https://community.snowflake.com/s/question/0D5VI00000Emyl00A... We'll keep updating that URL with any further news.