Live data from Hacker News

Thanksgiving 2023 security incident

blog.cloudflare.com

151–160 of 336 posts

Re: Thanksgiving 2023 security incident

#151

Earlier quoted context omitted.

> It would be a company ending event if someone managed to install themselves inside a data centre while it was being built/brought up. It wouldn't. Most people like to assume the impact of breaches to be what it should be, not what it actually is. Look at the 1-year stock chart of Okta and, without looking up the actual date, tell me when the breach happened/was disclosed.

> Look at the 1-year stock chart of Okta and, without looking up the actual date, tell me when the breach happened/was disclosed. The problem with this is that while security minded people know what Okta is and why to stay the fuck away from handing over your crown jewels to a SaaS company is warranted, C-level execs don't care . They only care about their golf course or backroom deal friends and about releasing PR s…

Yes, that’s literally the point being made. The point is that it isn’t a company-ending event. You are going on an unrelated rant about how those darn dumb executives aren’t as smart as God’s gift to earth, engineers.

Re: Thanksgiving 2023 security incident

#154

Earlier quoted context omitted.

> new laptops that are preinstalled with Okta’s management system Okta doesn't make device management software, thats made by companies like Jamf. Okta can integrate with them but Okta isn't what manages your laptop at all. > I wasn’t willing to use Okta’s login system if I have my own personal passwords or keys anywhere on my work computer. Do not do this, its not a personal device.

> Do not do this, its not a personal device. You think nobody's logged into their personal spotify on their work computer? All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? And that business traveller away from their partner and kids for a week+ isn't going to video call them? Or watch some netflix in their hotel room in the evening? That's so unrealistic, you coul…

I’ve had company devices for over 20 years. I’m currently on the way back to my hotel.

I refuse to carry more than one phone or one laptop, and I sure ain’t brining a personal device into a country I wouldnt go to on vacation.

Re: Thanksgiving 2023 security incident

#156
They mention Zero Trust, yet you can gain access to applications with just a single bearer token?

Am I missing something here?

There’s no machine cert used? AuthN tokens aren’t cryptographically bound?

This doesn’t meet my definition of ZT, it seems more like “we don’t have a VPN”

Re: Thanksgiving 2023 security incident

#157

Writeups and actions like this from cloudflare are exactly why I trust them with my data and my business. Yes, they aren’t perfect. They do some things that I disagree with. But overall they prove themselves worthy of my trust, specifically because of the engineering mindset that the company shares, and how serious they take things like this. Thank you for the blog post!

Then, the advertisement worked.

- Insist that you have better integrity than your competitors

- share a few operational investigations after your latest security event

what cloudflare doesnt do is provide their SOC risk analysis as a PCI/DSS payment card processor. Cloudflare doesnt explain why they ignored/failed to identify the elevated accounts or how those accounts became compromised to begin with. They just explain remediation without accountability.

They mention a third-party audit was conducted, but thats not because they care about you. Its because PCI/DSS mandates when an organization of any level experiences a data breach or cyber-attack that compromises payment card information, it needs to pass a yearly on-premise audit to ensure PCI compliance. if they didnt, major credit houses would stop processing their payments.

Re: Thanksgiving 2023 security incident

#158

Earlier quoted context omitted.

> new laptops that are preinstalled with Okta’s management system Okta doesn't make device management software, thats made by companies like Jamf. Okta can integrate with them but Okta isn't what manages your laptop at all. > I wasn’t willing to use Okta’s login system if I have my own personal passwords or keys anywhere on my work computer. Do not do this, its not a personal device.

> Do not do this, its not a personal device. You think nobody's logged into their personal spotify on their work computer? All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? And that business traveller away from their partner and kids for a week+ isn't going to video call them? Or watch some netflix in their hotel room in the evening? That's so unrealistic, you coul…

Not until just now I didn't. Do they not have a smartphone? A personal laptop? I'm waiting for something to build as I'm typing this right now. On a separate computer. I would never go on Hacker News on my work computer.

Why would I use a device to do personal things that they MITM everything I do on it? Privacy is too important to me to give it away like that. I'm sure all traffic on the corporate network is logged. Why open myself up for grounds for termination if my company hits hard times and wants to lay people off?

Re: Thanksgiving 2023 security incident

#159
post #86

Earlier quoted context omitted.

> personal Trello account for keeping track of my todo list. > personal Obsidian for keeping meeting notes, and recording conversations as a personal knowledge-base I'm not a lawyer, but I'm pretty sure these could subject a lot of your other personal data to potential subpoena should your employer get sued by a sufficiently determined attacker. Don't cross the streams.

Also it's a violation of Obsidian's license: > Obsidian is free for personal and non-profit use. However, if you use Obsidian for work-related activities that generate revenue in a company with two or more people, you must purchase a commercial license for each user. Non-profit organizations are exempt from this requirement. https://obsidian.md/license

Perhaps they pay for a commercial license?

> Q3. Can I buy a license for myself, or do I have to ask my company to buy it for me? > Yes, you can buy a license for yourself; just put your name in the company > field. You can use such a license to work for any company.

https://help.obsidian.md/Licenses+and+payment/Commercial+lic...

Re: Thanksgiving 2023 security incident

#160
post #156

They mention Zero Trust, yet you can gain access to applications with just a single bearer token? Am I missing something here? There’s no machine cert used? AuthN tokens aren’t cryptographically bound? This doesn’t meet my definition of ZT, it seems more like “we don’t have a VPN”

these were service accounts used by third parties to provide jira integrations, not a user account
Post reply on HN