Live data from Hacker News

Thanksgiving 2023 security incident

blog.cloudflare.com

191–200 of 336 posts

Re: Thanksgiving 2023 security incident

#191

Earlier quoted context omitted.

> Do not do this, its not a personal device. You think nobody's logged into their personal spotify on their work computer? All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? And that business traveller away from their partner and kids for a week+ isn't going to video call them? Or watch some netflix in their hotel room in the evening? That's so unrealistic, you coul…

Not until just now I didn't. Do they not have a smartphone? A personal laptop? I'm waiting for something to build as I'm typing this right now. On a separate computer. I would never go on Hacker News on my work computer. Why would I use a device to do personal things that they MITM everything I do on it? Privacy is too important to me to give it away like that. I'm sure all traffic on the corporate network is logged.…

If you're sitting in the office waiting for something to build, and you get out your phone to go on HN I'm sorry to say that is probably not the sort of professionalism that's going to afford you much protection from layoffs.

Re: Thanksgiving 2023 security incident

#192

Earlier quoted context omitted.

Whats your point?

That this is messaged and received as a net win. It’s not.

Are they just supposed to be invincible? Next best thing is an incident response with this level of quality and transparency. Thats definitely a win in my book, I want to know the provider of a core part of my infra is able to competently and maturely respond to a security incident and this post strongly communicates that.

Re: Thanksgiving 2023 security incident

#193
post #89

Earlier quoted context omitted.

It's not extreme at all, it's the bare minimum that professionals do. Absolutely none of my personal stuff ever touches a corporate machine. Ever. I wouldn't even log in to the W2 downloading app as an employee from the work machine. Granting work ssh keys access to your personal machine is crazy; if your work machine gets compromised, they steal your entire personal system's home directory too. Why would you unneces…

I love these sorts of comments. Could you please just be more direct and call GP “not a professional” for not working in the way that you do? It’s so unnecessarily passive-aggressive.

You are really, really, really sensitive about this. I wonder why?

GP said nothing of the sort.

Re: Thanksgiving 2023 security incident

#194

Earlier quoted context omitted.

Even among engineers, most people don't think like a security engineer. I'm sure there are plenty of people who have access to their company's private repos through their personal GitHub accounts.

At every company I've worked for, past 12+ years, this has been the rule, not the exception. They invite your personal github to corporate repos.

I have read a couple of horror stories where it then becomes impossible to separate the account once you leave the employer.

No thanks. New account per job.

Re: Thanksgiving 2023 security incident

#195

Earlier quoted context omitted.

> Do not do this, its not a personal device. You think nobody's logged into their personal spotify on their work computer? All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? And that business traveller away from their partner and kids for a week+ isn't going to video call them? Or watch some netflix in their hotel room in the evening? That's so unrealistic, you coul…

I’ve had company devices for over 20 years. I’m currently on the way back to my hotel. I refuse to carry more than one phone or one laptop, and I sure ain’t brining a personal device into a country I wouldnt go to on vacation.

Totally agree on travel. If I'm getting on a plane for work I don't want to bring my own devices. I can't even trust that my own country won't steal/copy my devices at the border.

Re: Thanksgiving 2023 security incident

#196
post #9

Great write up. > Over the next day, the threat actor viewed 120 code repositories (out of a total of 11,904 repositories > They accessed 36 Jira tickets (out of a total of 2,059,357 tickets) and 202 wiki pages (out of a total of 14,099 pages). Is it just me or 12K git repos and 2 million JIRA tickets sound like a crazy lot. 15K wiki pages is not that high though. > Since the Smartsheet service account had administra…

Blog updated:

They accessed 36 Jira tickets (out of a total of 2,059,357 tickets) and 202 wiki pages (out of a total of 194,100 pages)

Re: Thanksgiving 2023 security incident

#197

Earlier quoted context omitted.

At every company I've worked for, past 12+ years, this has been the rule, not the exception. They invite your personal github to corporate repos.

I have read a couple of horror stories where it then becomes impossible to separate the account once you leave the employer. No thanks. New account per job.

Sounds like a misunderstanding. They just remove you from the org. (And if they don't, it's not your problem.)

Re: Thanksgiving 2023 security incident

#198
post #85

>The one service token and three accounts were not rotated because mistakenly it was believed they were unused. This odd to me - unused credentials should probably be deleted, not rotated.

This smells weird, surely? I'd be looking at who chose not to rotate those particular credentials. 1: "what are these accounts?" 2: "oh they're unused, they don't even appear in the logs" 1: "we should rotate them" 2: "no, let's keep those rando accounts with the old credentials, the ones we think might be compromised ... y' know, for reasons" ?

More likely: "no one has any idea what these old credentials do, so let's not touch them and potentially break everything"

Re: Thanksgiving 2023 security incident

#199

Earlier quoted context omitted.

Stuxnet targeted the uranium enrichment facility at Natanz run by the Iranian government. When does the US attack private enterprise?

When it suits them (i.e. when there is data to be gained). But it's more often done through the courts, and when it needs to be a covert op, I'm guessing they'd get their buddies in friendly countries to do the dirty work.

Well how about some evidence then?

Re: Thanksgiving 2023 security incident

#200

Earlier quoted context omitted.

I have read a couple of horror stories where it then becomes impossible to separate the account once you leave the employer. No thanks. New account per job.

Sounds like a misunderstanding. They just remove you from the org. (And if they don't, it's not your problem.)

But being part of an organization, don’t they have admin control over your account? Could delete all of your repos, reset your keys, access private repos, etc.

Even if a tiny risk, it seems silly just to bolster the GH activity graph.

Post reply on HN