Earlier quoted context omitted.
> It would be a company ending event if someone managed to install themselves inside a data centre while it was being built/brought up. It wouldn't. Most people like to assume the impact of breaches to be what it should be, not what it actually is. Look at the 1-year stock chart of Okta and, without looking up the actual date, tell me when the breach happened/was disclosed.
> Look at the 1-year stock chart of Okta and, without looking up the actual date, tell me when the breach happened/was disclosed. The problem with this is that while security minded people know what Okta is and why to stay the fuck away from handing over your crown jewels to a SaaS company is warranted, C-level execs don't care . They only care about their golf course or backroom deal friends and about releasing PR s…
Thanksgiving 2023 security incident
151–160 of 336 posts
Re: Thanksgiving 2023 security incident
#152Re: Thanksgiving 2023 security incident
#153Re: Thanksgiving 2023 security incident
#154Earlier quoted context omitted.
> new laptops that are preinstalled with Okta’s management system Okta doesn't make device management software, thats made by companies like Jamf. Okta can integrate with them but Okta isn't what manages your laptop at all. > I wasn’t willing to use Okta’s login system if I have my own personal passwords or keys anywhere on my work computer. Do not do this, its not a personal device.
> Do not do this, its not a personal device. You think nobody's logged into their personal spotify on their work computer? All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? And that business traveller away from their partner and kids for a week+ isn't going to video call them? Or watch some netflix in their hotel room in the evening? That's so unrealistic, you coul…
I refuse to carry more than one phone or one laptop, and I sure ain’t brining a personal device into a country I wouldnt go to on vacation.
Re: Thanksgiving 2023 security incident
#155Re: Thanksgiving 2023 security incident
#156Am I missing something here?
There’s no machine cert used? AuthN tokens aren’t cryptographically bound?
This doesn’t meet my definition of ZT, it seems more like “we don’t have a VPN”
Re: Thanksgiving 2023 security incident
#157Writeups and actions like this from cloudflare are exactly why I trust them with my data and my business. Yes, they aren’t perfect. They do some things that I disagree with. But overall they prove themselves worthy of my trust, specifically because of the engineering mindset that the company shares, and how serious they take things like this. Thank you for the blog post!
- Insist that you have better integrity than your competitors
- share a few operational investigations after your latest security event
what cloudflare doesnt do is provide their SOC risk analysis as a PCI/DSS payment card processor. Cloudflare doesnt explain why they ignored/failed to identify the elevated accounts or how those accounts became compromised to begin with. They just explain remediation without accountability.
They mention a third-party audit was conducted, but thats not because they care about you. Its because PCI/DSS mandates when an organization of any level experiences a data breach or cyber-attack that compromises payment card information, it needs to pass a yearly on-premise audit to ensure PCI compliance. if they didnt, major credit houses would stop processing their payments.
Re: Thanksgiving 2023 security incident
#158Earlier quoted context omitted.
> new laptops that are preinstalled with Okta’s management system Okta doesn't make device management software, thats made by companies like Jamf. Okta can integrate with them but Okta isn't what manages your laptop at all. > I wasn’t willing to use Okta’s login system if I have my own personal passwords or keys anywhere on my work computer. Do not do this, its not a personal device.
> Do not do this, its not a personal device. You think nobody's logged into their personal spotify on their work computer? All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? And that business traveller away from their partner and kids for a week+ isn't going to video call them? Or watch some netflix in their hotel room in the evening? That's so unrealistic, you coul…
Why would I use a device to do personal things that they MITM everything I do on it? Privacy is too important to me to give it away like that. I'm sure all traffic on the corporate network is logged. Why open myself up for grounds for termination if my company hits hard times and wants to lay people off?
Re: Thanksgiving 2023 security incident
#159Earlier quoted context omitted.
> personal Trello account for keeping track of my todo list. > personal Obsidian for keeping meeting notes, and recording conversations as a personal knowledge-base I'm not a lawyer, but I'm pretty sure these could subject a lot of your other personal data to potential subpoena should your employer get sued by a sufficiently determined attacker. Don't cross the streams.
Also it's a violation of Obsidian's license: > Obsidian is free for personal and non-profit use. However, if you use Obsidian for work-related activities that generate revenue in a company with two or more people, you must purchase a commercial license for each user. Non-profit organizations are exempt from this requirement. https://obsidian.md/license
> Q3. Can I buy a license for myself, or do I have to ask my company to buy it for me? > Yes, you can buy a license for yourself; just put your name in the company > field. You can use such a license to work for any company.
https://help.obsidian.md/Licenses+and+payment/Commercial+lic...
Re: Thanksgiving 2023 security incident
#160They mention Zero Trust, yet you can gain access to applications with just a single bearer token? Am I missing something here? There’s no machine cert used? AuthN tokens aren’t cryptographically bound? This doesn’t meet my definition of ZT, it seems more like “we don’t have a VPN”