Live data from Hacker News

MongoHQ Security breach

security.mongohq.com

1–10 of 130 posts

Re: MongoHQ Security breach

#3
Especially bad for people that were using MongoHQ to manage their DB backups to S3:

As a precaution, we took additional steps on behalf of our customers to invalidate the Amazon Web Services credentials we were storing for you (for the purposes of backups to S3). While this prevents the abuse of your AWS credentials by any malicious party, it may have resulted in additional unintended consequences for your AWS environment if you were utilizing the same AWS credentials for other purposes.

If you had S3 backups configured with MongoHQ, when possible, we have disabled the IAM access keys via AWS. In any case, please go to the AWS Management Console and regenerate any keys given to MongoHQ .

Re: MongoHQ Security breach

#4
And this is why you use 2FA and put this behind a corporate VPN in RFC 1918 space. Why they are just planning for that now is amusing.

"Our support tool includes an 'impersonate' feature that enables MongoHQ employees to access our primary web UI as if they were a logged in customer"

Re: MongoHQ Security breach

#5
I'm not a MongoHQ customer (and as I don't use either AWS or MongoDB... it's unlikely I ever will be), but this is one heck of a disclosure.

Other companies (looking at you Linode...) could stand to learn a thing or two from how MongoHQ is handling this. Extremely transparent, and explaining in very clear terms the steps they'll be taking to mitigate the breach and prevent future incidents.

All that being said... Ouch.

Re: MongoHQ Security breach

#8

detected unauthorized access to an internal support application using a password that was shared with a compromised personal account Someone's updating their resume tonight.

I doubt he'll be fired just for that, but yeah, that is a big mistake on his part.

In general though, in any security breach the most common way to pivot is via password re-use. You'll see this happen with many privileged employees at almost every company.

Post reply on HN