Earlier quoted context omitted.
Yes, but if after two months they’d found out that customer data had been compromised, that would be a little late for me to do anything about it.
Had customer data been impacted we would have disclosed it immediately.
Thanksgiving 2023 security incident
121–130 of 336 posts
Re: Thanksgiving 2023 security incident
#122Re: Thanksgiving 2023 security incident
#123Re: Thanksgiving 2023 security incident
#124Which "nation state" do we think this was?
Which nation state has good enough employment protection laws that they can take weekends off while doing recon on a top value target?
Re: Thanksgiving 2023 security incident
#125> Even though we believed, and later confirmed, the attacker had limited access, we undertook a comprehensive effort to rotate every production credential (more than 5,000 individual credentials), physically segment test and staging systems, performed forensic triages on 4,893 systems, reimaged and rebooted every machine in our global network including all the systems the threat actor accessed and all Atlassian produ…
If you assume that they only accessed what you can prove they accessed, you've left a hole for them to live in. It should require a quorum of people to say you DON'T need to do this.
Of course, this is ideal world. I'm glad my group is afforded the time to implement features with no direct monetary or user benefit.
Re: Thanksgiving 2023 security incident
#126> The one service token and three accounts were not rotated because mistakenly it was believed they were unused. Eh? So why weren't they revoked entirely? I'm sure something's just unsaid there, or lost in communication or something, but as written that doesn't really make sense to me?
Re: Thanksgiving 2023 security incident
#127Earlier quoted context omitted.
Maybe but maybe not. I don't like Bitbucket but there are a number of large companies where they worry about using services owned by competitors in one of their verticals.
Bitbucket doesn't have to be a service. It can be an old-fashioned downloaded software that you install on your own machines. Not everything is SaaS.
In the git universe there is a pretty short list of services, locally or hosted that you would probably use as an entity as large as cloud flare.
Re: Thanksgiving 2023 security incident
#128Re: Thanksgiving 2023 security incident
#129Fascinating and thorough analysis! I guess if you think an account is unused, just delete it!
Re: Thanksgiving 2023 security incident
#130Earlier quoted context omitted.
I think they did have to do that far though. Getting in at the "ground floor" of a new datacentre build is pretty much the ultimate exploit. Imagine getting in at the centre of a new Meet-Me room ( https://en.wikipedia.org/wiki/Meet-me_room ) and having persistent access to key switches there. Cloudflare datacentres tend to be at the hub of insane amounts of data traffic. The fact that the attacker knew how valuable…
> Imagine getting in at the centre of a new Meet-Me room and having persistent access to key switches there. This wouldn't get you much. We already assume the network is insecure. This is why TLS is a thing (and mTLS for those who are serious).