Live data from Hacker News

Hacker confirms access through infostealer infection [withdrawn]

hudsonrock.com

191–200 of 235 posts

Re: Hacker confirms access through infostealer infection [withdrawn]

#191

Earlier quoted context omitted.

> They provide enough information (unfortunately) to identify the employee whose credentials were stolen, and she's a Sales Engineer. I'm not previously familiar with Hudson Rock, nor how "standard" disclosures around this work, but identifying the breached employee felt like an extremely shitty move to me. If a single infected laptop of a sales engineer (i.e. not even an admin with extensive access rights) resulted…

Exactly, how is an SE privileged enough to cause a problem? Or for the activities to go unnoticed? Like I would be very humiliated to have a system under my care that had this problem.

The prospective customer copies their data to Snowflake so Snowflake can demonstrate their awesomeness with the customer data.

Re: Hacker confirms access through infostealer infection [withdrawn]

#192
I'll bet there's a few of those reputedly 400 companies keeping an eye on the news of this and another eye on their stick price.

If data gets out, especially financial data being reported to investors, that spells curtains for a company generally.

Re: Hacker confirms access through infostealer infection [withdrawn]

#194

Earlier quoted context omitted.

So the customer data is actually stored on Snowflakes AWS accounts? What difference does it make what underlying storage / provider it uses then? Also does that mean every data query to snowflake goes out/in to/from internet at egress/Ingress costs?

> So the customer data is actually stored on Snowflakes AWS accounts? Yes. > Also does that mean every data query to snowflake goes out/in to/from internet at egress/Ingress costs? Yes. It's covered comprehensively in their docs, along with the caveats. > What difference does it make what underlying storage / provider it uses then? "Snowflake does not charge data ingress fees. However, a cloud storage provider might…

Snowflake usually unloads data to an internal stage bucket in the same region as your snowflake account. If you use an s3 gateway endpoint getting that data is free of egress charges.

Re: Hacker confirms access through infostealer infection [withdrawn]

#196
post #163

Earlier quoted context omitted.

Doing some more digging, this is where the data is sourced "Hudson Rock acquires and purchases compromised data directly from top-tier threat actors operating in closed circle hacking groups. What sets our data apart is its quality in providing high accessibility to hacker groups looking for potential targets, and the speed in which we make it available to clients compared to other threat intelligence companies. Our…

About as ethical as those other 8200 alums, NSO. The ethics of the IDF on full display.

Just a side effect of any apartheid regime, it is a deeply morally corrupted nation to the very core.

Re: Hacker confirms access through infostealer infection [withdrawn]

#198
This is my first ever HN post, and I actually got distracted/took timeout from studing for a Snowflake cert (what are the odds; first ever story I saw about Snowflake on HN).

So, I was reading the comments and then in my mind I said to myself, this sounds like something connected with a Pegasus type company. The very next line in the comment I was reading was: "our boots-on-the-ground approach to cybercrime originates from the IDF's 8200 Cybercrime division"!

As others have noted, doxing the SE seems unnecessary...unless, that was part of the threat/proposal to Snowflake. You can imagine companies that had worked with that SE being concerned/need reassuring they're not affected.

I wouldn't at all be surprised if someone had bet against Snowflake stock before this story broke, if the story was hyped up enough or it was bad enough to spook the market.

Snowflake "strongly recommends" using 2FA for the admin account role, but users are free to decide whether to use it or not. Snowflake's website states: "MFA is enabled on a per-user basis; however, at this time, users are not automatically enrolled in MFA. To use MFA, users must enrol themselves." - I assume a future update will change that so they can enable it by default. MFA related questions always appear in lower-level Snowflake certs.

I'd assume (as a consultant) It would be against company policy to use a username/password for client work. Sometimes that's one of the first bad practices we see working with new clients. Perhaps that's why the SE is an ex-employee.

Re: Hacker confirms access through infostealer infection [withdrawn]

#199
post #163

Earlier quoted context omitted.

Doing some more digging, this is where the data is sourced "Hudson Rock acquires and purchases compromised data directly from top-tier threat actors operating in closed circle hacking groups. What sets our data apart is its quality in providing high accessibility to hacker groups looking for potential targets, and the speed in which we make it available to clients compared to other threat intelligence companies. Our…

About as ethical as those other 8200 alums, NSO. The ethics of the IDF on full display.

NSO wasn't founded by 8200 alumni, however companies such as the following were:

* Checkpoint

* Palo Alto Networks

* Waze

* Wiz

* Cybereason

Does your theory hold up? no, but why not generalize

Re: Hacker confirms access through infostealer infection [withdrawn]

#200

Earlier quoted context omitted.

About as ethical as those other 8200 alums, NSO. The ethics of the IDF on full display.

Just a side effect of any apartheid regime, it is a deeply morally corrupted nation to the very core.

Generalizing over the whole nation? Hmm... Where have we seen this?..
Post reply on HN