Live data from Hacker News

Zapier says someone broke into its code repositories and may have customer data

theverge.com

11–14 of 14 posts

Re: Zapier says someone broke into its code repositories and may have customer data

#11
post #8

Zapier’s breach shows that even big SaaS companies can accidentally expose customer data in code repos. If they got hit due to a 2FA misconfiguration, how many other companies are at similar risk without knowing?

Similar things have happened before:

https://gizmodo.com/amazon-engineer-leaked-private-encryptio...

"An Amazon Web Services (AWS) engineer last week inadvertently made public almost a gigabyte’s worth of sensitive data, including their own personal documents as well as passwords and cryptographic keys to various AWS environments."

Re: Zapier says someone broke into its code repositories and may have customer data

#12
post #5

This is the most mealy mouthed disclosure ever. Shame on them. How can an employees 2FA misconfiguration lead to someone else accessing these repos? 2FA setups are supposed to prevent this sort of thing. If I had to guess it was someone on the “devops/sre/infra” team that usually has god mode access that were setting up some integration and disabled 2FA for testing or something for a test account … but it would have…

Disclosure: ex-Zapier employee, shareholder, biased disclosed, I have zero information or access today. Thoughts and opinions always my own. I’m not sure who you worked with, but I worked for several years with both engineers and the CTO, and I strongly disagree with your assertion regarding their engineering prowess. It is one of the most engineering focused companies I have ever worked at in ~25 years, and at least…

[dead]

Re: Zapier says someone broke into its code repositories and may have customer data

#13
post #5

This is the most mealy mouthed disclosure ever. Shame on them. How can an employees 2FA misconfiguration lead to someone else accessing these repos? 2FA setups are supposed to prevent this sort of thing. If I had to guess it was someone on the “devops/sre/infra” team that usually has god mode access that were setting up some integration and disabled 2FA for testing or something for a test account … but it would have…

Cant comment on rest of your points, but as someone who has worked on Zapier-like 3rd party integrations a lot, it is much harder than it appears.

Re: Zapier says someone broke into its code repositories and may have customer data

#14
post #2

I never used it because I could never figure out the pricing. Fortuitous.

It’s been either free or $20/mo for a long time. You use the free version until you hit a paywall. They’re a cool company, all or mostly self-funded and from the Midwest (St Louis, IIRC.) I hope this isn’t too damaging.

[deleted]
Post reply on HN