Live data from Hacker News

Hacker confirms access through infostealer infection [withdrawn]

hudsonrock.com

181–190 of 235 posts

Re: Hacker confirms access through infostealer infection [withdrawn]

#181

Earlier quoted context omitted.

No, Snowflake runs it's own storage and compute (on either AWS, GCP, or Azure depending on what you pick).

So the customer data is actually stored on Snowflakes AWS accounts? What difference does it make what underlying storage / provider it uses then? Also does that mean every data query to snowflake goes out/in to/from internet at egress/Ingress costs?

> So the customer data is actually stored on Snowflakes AWS accounts?

Yes.

> Also does that mean every data query to snowflake goes out/in to/from internet at egress/Ingress costs?

Yes. It's covered comprehensively in their docs, along with the caveats.

> What difference does it make what underlying storage / provider it uses then?

"Snowflake does not charge data ingress fees. However, a cloud storage provider might charge a data egress fee for transferring data from the provider to your Snowflake account."

unsaid: "...and you have to pay for that".

Note that when they say 'your Snowflake account' they mean our cloud account which we own, and which we run our workloads in, which we refer to as 'your' snowflake account.

Tangibly speaking, what means is that if you want to check up your billing; you go through snowflake; you can't login to a cloud console and see the actual charges the cloud vendor is charging.

> What difference does it make what underlying storage / provider it uses then?

They pass the specific underlying cloud vendor costs on to you (with, I guess, some markup, though you have no way of know what that is :)

Re: Hacker confirms access through infostealer infection [withdrawn]

#182
post #138

I'm more than disappointed in Hudson Rock. They lead with confirmation of a breach, but detail no more than allegations and swagger. The decision to not redact the login is not just a moral failure, but it shows that they do not understand the subject matter that they purport to be experts in. Shameful.

This. Thank you.

Re: Hacker confirms access through infostealer infection [withdrawn]

#183

Earlier quoted context omitted.

Step 4 is right in the article: "they were able to sign into a Snowflake employee’s ServiceNow account using stolen credentials, thus bypassing OKTA which is located on lift.snowflake.com. Following the infiltration, the threat actor claims that they were able to generate session tokens, which enabled them to exfiltrate massive amounts of data from the company"

Yes, but how should ServiceNow create session tokens if it is not part of the SSO system? I don't know enough about ServiceNow, but I think every large company has some products that are not part of their-SSO system. So that makes sense, but I am not sure about the next step.

I think they mean regenerating servicenow's own tokens/cookies, without hitting okta. so SN's session would still be valid.

Re: Hacker confirms access through infostealer infection [withdrawn]

#184
post #173

Earlier quoted context omitted.

[flagged]

assuming seeing “dicks” upset you, and you think “cunts” would upset someone else, this seems less like equality and more like an attempt at hurting others due to hurt. or are you truly glad?

I don't know who you think are "due to hurt" and doubt HN is the right place for that discussion. I'm certainly not interested.

Re: Hacker confirms access through infostealer infection [withdrawn]

#185
post #66

It's surprising that SnowFlake didn't pay the $20M ransom. Seems like a no-brainer compared to the reputational damage this would cause.

I honestly don't understand why someone would pay a ransom. They just hacked you. Do you think they'd actually follow through with keeping quiet?

Re: Hacker confirms access through infostealer infection [withdrawn]

#186
post #163
post #160

Earlier quoted context omitted.

This is the description of one of Hudson Rock's main products, "Bayonet". "Imagine getting access to a lead-generation platform featuring hundreds of thousands of compromised companies around the world with active vulnerabilities that you can convert into customers." I've seen and dealt with a couple of these types of companies. It's a pretty sleazy tactic, and it's low skill/effort from a technical point of view as…

Doing some more digging, this is where the data is sourced "Hudson Rock acquires and purchases compromised data directly from top-tier threat actors operating in closed circle hacking groups. What sets our data apart is its quality in providing high accessibility to hacker groups looking for potential targets, and the speed in which we make it available to clients compared to other threat intelligence companies. Our…

About as ethical as those other 8200 alums, NSO. The ethics of the IDF on full display.

Re: Hacker confirms access through infostealer infection [withdrawn]

#188

Earlier quoted context omitted.

Just because there isn’t a “novel exploit” doesn’t mean this isn’t a big deal. Snowflake is susceptible to their SE’s having credentials stolen. These credentials can bypass MFA. And per the article, they have no expiry. That’s strikes one, two, and three. Snowflake’s security practices lead to a situation where their customers are either required, or at minimum encouraged, to share access to broad datasets with Snow…

Having spent a lot of time in the Snowflake ecosystem, a few things to understand. Snowflake is both a platform and a database. Customers can implement any level of security within the system. For example, when Snowflake introduced OAuth functionality, they put a lot of pressure for us to implement it in our tool. We're small enough and they are a significant partner so we priortised and got it into our platform so t…

(I condemn doxing in any way)

Calling the SE a "victim" is debatable. If you work environment is infected with malware, you screwed up.

"Typically, Lumma has been distributed disguised as cracked or fake popular software like VLC or ChatGPT. Recently though, threat actors have also delivered the malware through emails containing payloads in the form of attachments or links impersonating well-known companies."

I would not be suprised if this was a recruiter-attack-vector.

Re: Hacker confirms access through infostealer infection [withdrawn]

#189
post #184

Earlier quoted context omitted.

assuming seeing “dicks” upset you, and you think “cunts” would upset someone else, this seems less like equality and more like an attempt at hurting others due to hurt. or are you truly glad?

I don't know who you think are "due to hurt" and doubt HN is the right place for that discussion. I'm certainly not interested.

"I'm certainly not interested."

You started it?

Post reply on HN