Since they didn’t really have reason to believe my data was accessed, maybe that’s ok. I know from firsthand experience how hard rotating all your credentials across the whole org is.
Thanksgiving 2023 security incident
11–20 of 336 posts
Re: Thanksgiving 2023 security incident
#12Which "nation state" do we think this was?
Re: Thanksgiving 2023 security incident
#13Yes, they aren’t perfect. They do some things that I disagree with.
But overall they prove themselves worthy of my trust, specifically because of the engineering mindset that the company shares, and how serious they take things like this.
Thank you for the blog post!
Re: Thanksgiving 2023 security incident
#14> we were (for the second time) the victim of a compromise of Okta’s systems I'm curious if they're rethinking being on Okta.
The challenge being, who else could possibly handle Cloudflare's requirements? I imagine the next step is to build their own, and that's obviously not an easy pill to swallow.
Re: Thanksgiving 2023 security incident
#15> we were (for the second time) the victim of a compromise of Okta’s systems I'm curious if they're rethinking being on Okta.
The challenge being, who else could possibly handle Cloudflare's requirements? I imagine the next step is to build their own, and that's obviously not an easy pill to swallow.
Re: Thanksgiving 2023 security incident
#16The most surprising part of this is that Cloudflare uses BitBucket.
Re: Thanksgiving 2023 security incident
#17Writeups and actions like this from cloudflare are exactly why I trust them with my data and my business. Yes, they aren’t perfect. They do some things that I disagree with. But overall they prove themselves worthy of my trust, specifically because of the engineering mindset that the company shares, and how serious they take things like this. Thank you for the blog post!
Re: Thanksgiving 2023 security incident
#18Reading this 2 months after the fact feels a bit late, but I guess it’s better for your stock price if these revelations happen with remediation already in hand? Since they didn’t really have reason to believe my data was accessed, maybe that’s ok. I know from firsthand experience how hard rotating all your credentials across the whole org is.
Re: Thanksgiving 2023 security incident
#19The most surprising part of this is that Cloudflare uses BitBucket.
Re: Thanksgiving 2023 security incident
#20Earlier quoted context omitted.
The challenge being, who else could possibly handle Cloudflare's requirements? I imagine the next step is to build their own, and that's obviously not an easy pill to swallow.
They already run their own zero trust infrastructure for customers, kinda surprised they are not dogfooding it. https://www.cloudflare.com/plans/zero-trust-services/
They are using zero trust and explained that it's why the scope of the security incident was extremely limited.