Live data from Hacker News

Thanksgiving 2023 security incident

blog.cloudflare.com

101–110 of 336 posts

Re: Thanksgiving 2023 security incident

#101
> The threat actor searched the wiki for things like remote access, secret, client-secret, openconnect, cloudflared, and token. They accessed 36 Jira tickets (out of a total of 2,059,357 tickets) and 202 wiki pages (out of a total of 14,099 pages).

In Atlassian's Confluence even the built-in Apache Lucene search engine can leak sensitive information and this kind of access (to the info by the attacker) can be very hard to track/identify. They don't have to open a Confluence page if the sensitive information is already shown on the search results page.

Re: Thanksgiving 2023 security incident

#102

Earlier quoted context omitted.

What are they now, if not an engineering company?

[flagged]

> a vessel of shareholder value, nothing more.

This is my general opinion of publicly traded companies, i.e. the primary product is their stock, but I personally haven't seen anything out of the ordinary with Cloudflare compared to other big tech companies.

I wouldn't say they aren't engineering companies though. There's plenty of engineering that goes on there, its just no longer the top priority once the company has gone public (same to some extent with VC investors).

Re: Thanksgiving 2023 security incident

#103
> Analyzing the wiki pages they accessed, bug database issues, and source code repositories, it appears they were looking for information about the architecture, security, and management of our global network; no doubt with an eye on gaining a deeper foothold.

For a nation state actor, the easiest way to accomplish that is to send one of their loyal citizens to become an employee of the target company and then have the person send back "information about the architecture, security, and management" of the target company.

Fun (but possibly apocryphal) fact: more than a decade ago in a social gathering of SREs at Google, several admitted to being on the payroll of some national intelligence bureaus.

Re: Thanksgiving 2023 security incident

#104
post #85

>The one service token and three accounts were not rotated because mistakenly it was believed they were unused. This odd to me - unused credentials should probably be deleted, not rotated.

This smells weird, surely? I'd be looking at who chose not to rotate those particular credentials.

1: "what are these accounts?"

2: "oh they're unused, they don't even appear in the logs"

1: "we should rotate them"

2: "no, let's keep those rando accounts with the old credentials, the ones we think might be compromised ... y' know, for reasons"

?

Re: Thanksgiving 2023 security incident

#105
post #5

> Even though we believed, and later confirmed, the attacker had limited access, we undertook a comprehensive effort to rotate every production credential (more than 5,000 individual credentials), physically segment test and staging systems, performed forensic triages on 4,893 systems, reimaged and rebooted every machine in our global network including all the systems the threat actor accessed and all Atlassian produ…

Cloudflare is showing how to correctly respond to attacks. Other companies should take note.

Re: Thanksgiving 2023 security incident

#108

Earlier quoted context omitted.

My company will only give us new laptops that are preinstalled with Okta’s management system. I am grandfathered in to an old MacBook that has absolutely no management software on it, from the “Early Days” when there was no IT and we just got brand new untouched laptops. They offered me an upgrade to an M1/M2 pro, but I refused, saying that I wasn’t willing to use Okta’s login system if I have my own personal passwor…

> new laptops that are preinstalled with Okta’s management system Okta doesn't make device management software, thats made by companies like Jamf. Okta can integrate with them but Okta isn't what manages your laptop at all. > I wasn’t willing to use Okta’s login system if I have my own personal passwords or keys anywhere on my work computer. Do not do this, its not a personal device.

> Do not do this, its not a personal device.

You think nobody's logged into their personal spotify on their work computer? All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives?

And that business traveller away from their partner and kids for a week+ isn't going to video call them? Or watch some netflix in their hotel room in the evening?

That's so unrealistic, you could write IT security policy for a Fortune 100 company :)

Re: Thanksgiving 2023 security incident

#109

Earlier quoted context omitted.

> if I have my own personal passwords or keys anywhere on my work computer. Well... don't do that? Why would you ever have personal anything on a work computer?

A Github account, for one possible example.

Okay, I'll bite; what about a github account? You don't generally own code you write for an employer, so why would you be an personal repos from a company machine? (Likewise, there's generally no good reason for the company to have access to personal repos, so those security domains should never overlap)

Re: Thanksgiving 2023 security incident

#110

Earlier quoted context omitted.

Let me get this straight… you’re taking privileged company information and transferring it to personal… I’m now understanding how people get sued when going from company to company.

Certainly nothing privileged! Moreso just reminders about “follow up with person x” and that kind of thing

Let me ask you one follow up question: if you and the company had a disagreement of sorts and they examined your activity, would you believe they find nothing that they’d deem privileged?
Post reply on HN