"Threat actor"… I love this "security" lingo. Threat actors, attack vectors, state actors :-)
Grafana Labs internal source code accessed
21–28 of 28 posts
Re: Grafana Labs internal source code accessed
#22I was recently considering an engineering job offer at Grafana. At the end I was turned off by the amount of their AI-related mindless propaganda and demands they have put right in the job offer. (Which is by the way quite rare; it is rather untypical to state in the position description how a developer should use AI tools; even though everyone can imagine how it looks like). Looks like they could have invested more…
Jobs are trully ridiculous in today's market. Not only you have to be "AI-native" with more years of experience with GenAI code, than the time it started getting popular, but you also get jobs that require you to know Claude Code in'n out, as if no other agent coding exists.
See, it is bullshit, but it is also easy enough. Claude Code is not inscrutable, this is much easier than learning, say, a new programming language. You can meaningfully learn enough to pass an interview in a couple of weeks. It's basically the same amount of information you need to learn to hype AI in HN comment section.
So yeah, I think AI is a deadend technology, far from being as useful as everyone invested on it claims. But I have been using it liberally just so I am on top of this shit, since it is the current hype cycle.
Re: Grafana Labs internal source code accessed
#23I was recently considering an engineering job offer at Grafana. At the end I was turned off by the amount of their AI-related mindless propaganda and demands they have put right in the job offer. (Which is by the way quite rare; it is rather untypical to state in the position description how a developer should use AI tools; even though everyone can imagine how it looks like). Looks like they could have invested more…
Jobs are trully ridiculous in today's market. Not only you have to be "AI-native" with more years of experience with GenAI code, than the time it started getting popular, but you also get jobs that require you to know Claude Code in'n out, as if no other agent coding exists.
hadoop had only existed for 5 years at the time, at most.
he figured that someone in HR got the draft for the job advert and just added in the 7 years as a guess based on another role they were hiring for.
edit — number of years required with specific technology is just a hand wavy estimate of how important it is for the role. never treat the numbers as gospel. that was the lesson he was teaching us.
Re: Grafana Labs internal source code accessed
#24"We recently discovered.." then later "..The attacker attempted to blackmail us"
So, I'd wager they had no idea of the breach until the attacker tried to blackmail them.
Re: Grafana Labs internal source code accessed
#25> We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. I don't much like the securityese dialect of bureaucratese, but doesn't it make more sense as "We recently discovered that a threat actor obtained a token with access to the Grafana Labs GitHub environment, enabling the unauthorized party to downl…
Re: Grafana Labs internal source code accessed
#26Is there anything of value in the internal codebase? So many companies internal codebases are of approximately zero value to any outsider. The code is only a small proportion of the business.
Re: Grafana Labs internal source code accessed
#27Is there anything of value in the internal codebase? So many companies internal codebases are of approximately zero value to any outsider. The code is only a small proportion of the business.
Given a lot of their software is OSS or OSS based there's a probable chance non-OSS is runnable and usable outside the company
The product is mostly "standalone" in that it doesn't require integrations with 3rd parties unlike, say, banking software
Re: Grafana Labs internal source code accessed
#28Is there anything of value in the internal codebase? So many companies internal codebases are of approximately zero value to any outsider. The code is only a small proportion of the business.
Critical vulnerability in that source code could enable further access to other production systems or databases.
Edit: typo