Live data from Hacker News

Thanksgiving 2023 security incident

blog.cloudflare.com

121–130 of 336 posts

Re: Thanksgiving 2023 security incident

#121
post #29

Earlier quoted context omitted.

Yes, but if after two months they’d found out that customer data had been compromised, that would be a little late for me to do anything about it.

Had customer data been impacted we would have disclosed it immediately.

^ eastdakota is part of the cloudflare mgmt team (CEO)

Re: Thanksgiving 2023 security incident

#122
post #7

Which "nation state" do we think this was?

For these kinds of attacks it's nearly always China, Russia, US, or sometimes Iran. 95% chance it's either China or Russia, here.

Their response program being called "Code Red" is likely a hint.

Re: Thanksgiving 2023 security incident

#123

Earlier quoted context omitted.

A Github account, for one possible example.

Doesn’t matter. No personal stuff on company devices. I just don’t understand any rational otherwise.

So you just don't listen to music at work?

Re: Thanksgiving 2023 security incident

#124
post #65
post #7

Which "nation state" do we think this was?

Which nation state has good enough employment protection laws that they can take weekends off while doing recon on a top value target?

Might be a coincidence. A certain nation-state is currently engaged in all-out war; the intruder might have been summoned to another, more urgent task.

Re: Thanksgiving 2023 security incident

#125
post #5

> Even though we believed, and later confirmed, the attacker had limited access, we undertook a comprehensive effort to rotate every production credential (more than 5,000 individual credentials), physically segment test and staging systems, performed forensic triages on 4,893 systems, reimaged and rebooted every machine in our global network including all the systems the threat actor accessed and all Atlassian produ…

The nuclear response to compromise should be the standard business practice. It should be exceptional to deviate from it.

If you assume that they only accessed what you can prove they accessed, you've left a hole for them to live in. It should require a quorum of people to say you DON'T need to do this.

Of course, this is ideal world. I'm glad my group is afforded the time to implement features with no direct monetary or user benefit.

Re: Thanksgiving 2023 security incident

#126
post #34

> The one service token and three accounts were not rotated because mistakenly it was believed they were unused. Eh? So why weren't they revoked entirely? I'm sure something's just unsaid there, or lost in communication or something, but as written that doesn't really make sense to me?

Betting they have a new item in their compromise runbook. :-)

Re: Thanksgiving 2023 security incident

#127
post #100
post #19

Earlier quoted context omitted.

Maybe but maybe not. I don't like Bitbucket but there are a number of large companies where they worry about using services owned by competitors in one of their verticals.

Bitbucket doesn't have to be a service. It can be an old-fashioned downloaded software that you install on your own machines. Not everything is SaaS.

Not sure what you mean? If you are alluding to the OP that said it was surprising...I don't think he found it suprising they they use Bitbucket over Mercurial. I think its safe to assume he meant bitbucket over a Github.

In the git universe there is a pretty short list of services, locally or hosted that you would probably use as an entity as large as cloud flare.

Re: Thanksgiving 2023 security incident

#129
post #2

Fascinating and thorough analysis! I guess if you think an account is unused, just delete it!

Probably safer to rotate the credentials and then schedule it for deletion later. Then if you discover it wasn't unused after all, you have an easier recovery... :-)

Re: Thanksgiving 2023 security incident

#130
post #76

Earlier quoted context omitted.

I think they did have to do that far though. Getting in at the "ground floor" of a new datacentre build is pretty much the ultimate exploit. Imagine getting in at the centre of a new Meet-Me room ( https://en.wikipedia.org/wiki/Meet-me_room ) and having persistent access to key switches there. Cloudflare datacentres tend to be at the hub of insane amounts of data traffic. The fact that the attacker knew how valuable…

> Imagine getting in at the centre of a new Meet-Me room and having persistent access to key switches there. This wouldn't get you much. We already assume the network is insecure. This is why TLS is a thing (and mTLS for those who are serious).

I suspect "we" is a much smaller group than you imagine. I've gotten pcaps from customers as recently as this year that include unencrypted financial transaction data. These were captured on a router, not an end host, so the traffic was going across the client's network raw.
Post reply on HN