Earlier quoted context omitted.
> Do not do this, its not a personal device. You think nobody's logged into their personal spotify on their work computer? All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? And that business traveller away from their partner and kids for a week+ isn't going to video call them? Or watch some netflix in their hotel room in the evening? That's so unrealistic, you coul…
Not until just now I didn't. Do they not have a smartphone? A personal laptop? I'm waiting for something to build as I'm typing this right now. On a separate computer. I would never go on Hacker News on my work computer. Why would I use a device to do personal things that they MITM everything I do on it? Privacy is too important to me to give it away like that. I'm sure all traffic on the corporate network is logged.…
Thanksgiving 2023 security incident
191–200 of 336 posts
Re: Thanksgiving 2023 security incident
#192Earlier quoted context omitted.
Whats your point?
That this is messaged and received as a net win. It’s not.
Re: Thanksgiving 2023 security incident
#193Earlier quoted context omitted.
It's not extreme at all, it's the bare minimum that professionals do. Absolutely none of my personal stuff ever touches a corporate machine. Ever. I wouldn't even log in to the W2 downloading app as an employee from the work machine. Granting work ssh keys access to your personal machine is crazy; if your work machine gets compromised, they steal your entire personal system's home directory too. Why would you unneces…
I love these sorts of comments. Could you please just be more direct and call GP “not a professional” for not working in the way that you do? It’s so unnecessarily passive-aggressive.
GP said nothing of the sort.
Re: Thanksgiving 2023 security incident
#194Earlier quoted context omitted.
Even among engineers, most people don't think like a security engineer. I'm sure there are plenty of people who have access to their company's private repos through their personal GitHub accounts.
At every company I've worked for, past 12+ years, this has been the rule, not the exception. They invite your personal github to corporate repos.
No thanks. New account per job.
Re: Thanksgiving 2023 security incident
#195Earlier quoted context omitted.
> Do not do this, its not a personal device. You think nobody's logged into their personal spotify on their work computer? All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? And that business traveller away from their partner and kids for a week+ isn't going to video call them? Or watch some netflix in their hotel room in the evening? That's so unrealistic, you coul…
I’ve had company devices for over 20 years. I’m currently on the way back to my hotel. I refuse to carry more than one phone or one laptop, and I sure ain’t brining a personal device into a country I wouldnt go to on vacation.
Re: Thanksgiving 2023 security incident
#196Great write up. > Over the next day, the threat actor viewed 120 code repositories (out of a total of 11,904 repositories > They accessed 36 Jira tickets (out of a total of 2,059,357 tickets) and 202 wiki pages (out of a total of 14,099 pages). Is it just me or 12K git repos and 2 million JIRA tickets sound like a crazy lot. 15K wiki pages is not that high though. > Since the Smartsheet service account had administra…
They accessed 36 Jira tickets (out of a total of 2,059,357 tickets) and 202 wiki pages (out of a total of 194,100 pages)
Re: Thanksgiving 2023 security incident
#197Earlier quoted context omitted.
At every company I've worked for, past 12+ years, this has been the rule, not the exception. They invite your personal github to corporate repos.
I have read a couple of horror stories where it then becomes impossible to separate the account once you leave the employer. No thanks. New account per job.
Re: Thanksgiving 2023 security incident
#198>The one service token and three accounts were not rotated because mistakenly it was believed they were unused. This odd to me - unused credentials should probably be deleted, not rotated.
This smells weird, surely? I'd be looking at who chose not to rotate those particular credentials. 1: "what are these accounts?" 2: "oh they're unused, they don't even appear in the logs" 1: "we should rotate them" 2: "no, let's keep those rando accounts with the old credentials, the ones we think might be compromised ... y' know, for reasons" ?
Re: Thanksgiving 2023 security incident
#199Earlier quoted context omitted.
Stuxnet targeted the uranium enrichment facility at Natanz run by the Iranian government. When does the US attack private enterprise?
When it suits them (i.e. when there is data to be gained). But it's more often done through the courts, and when it needs to be a covert op, I'm guessing they'd get their buddies in friendly countries to do the dirty work.
Re: Thanksgiving 2023 security incident
#200Earlier quoted context omitted.
I have read a couple of horror stories where it then becomes impossible to separate the account once you leave the employer. No thanks. New account per job.
Sounds like a misunderstanding. They just remove you from the org. (And if they don't, it's not your problem.)
Even if a tiny risk, it seems silly just to bolster the GH activity graph.