Live data from Hacker News

Matrix.org Security Incident

matrix.org

11–17 of 17 posts

Re: Matrix.org Security Incident

#11
The attacker seems to have responded:

https://github.com/matrix-org/matrix.org/issues/357 edit: just saw the rest: https://github.com/matrix-org/matrix.org/issues?utf8=%E2%9C%...

"[SECURITY] SSH Agent Forwarding

I noticed in your blog post that you were talking about doing a postmortem and steps you need to take. As someone who is intimately familiar with your entire infrastructure, I thought I could help you out.

Complete compromise could have been avoided if developers were prohibited from using ForwardAgent yes or not using -A in their SSH commands. The flaws with agent forwarding are well documented."

Re: Matrix.org Security Incident

#13
post #3

Earlier quoted context omitted.

it was not, read again

But it does seem to be the case that the same SSH key pair that was used to access Jenkins also provided access to the production infrastructure. Unless I'm misunderstanding the nature of the attack.

It seems the issue was developers using SSH agent forwarding which was abused to access the production environment.

Re: Matrix.org Security Incident

#14

content before it gets fixed: Time for actual transparency. [list of servers, uname -a for each] root@[name]:/var/lib/postgresql# df -h [list of partitions] $ cat users.txt | grep [name] | head -n1 @[name]:matrix.org|[hash] $ wc -l users.txt [~6M users] See you soon. (affects whole site, even https://matrix.org , site is on jekyll BTW)

Here's the source of that page: https://github.com/matrixnotorg/matrixnotorg.github.io/blob/....

Re: Matrix.org Security Incident

#15
post #12

Assuming the GitHub issues are from the actual attacker -- and I see no reason to doubt they are -- this is very troubling: https://github.com/matrix-org/matrix.org/issues/363 Compromise began well over a month ago Yikes. That's a long time for a compromise to go unnoticed.

Not really, the average in the industry seems to be floating between 70 and 400 days depending on the source of your stats on the topic (different vendors and reports use different stats for this)

Re: Matrix.org Security Incident

#16
post #11

The attacker seems to have responded: https://github.com/matrix-org/matrix.org/issues/357 edit: just saw the rest: https://github.com/matrix-org/matrix.org/issues?utf8=%E2%9C%... "[SECURITY] SSH Agent Forwarding I noticed in your blog post that you were talking about doing a postmortem and steps you need to take. As someone who is intimately familiar with your entire infrastructure, I thought I could help you out. Co…

[deleted]

Re: Matrix.org Security Incident

#17
post #14

content before it gets fixed: Time for actual transparency. [list of servers, uname -a for each] root@[name]:/var/lib/postgresql# df -h [list of partitions] $ cat users.txt | grep [name] | head -n1 @[name]:matrix.org|[hash] $ wc -l users.txt [~6M users] See you soon. (affects whole site, even https://matrix.org , site is on jekyll BTW)

Here's the source of that page: https://github.com/matrixnotorg/matrixnotorg.github.io/blob/... .

account got banned :) (it's on archive.org though)
Post reply on HN