Live data from Hacker News

Thanksgiving 2023 security incident

blog.cloudflare.com

201–210 of 336 posts

Re: Thanksgiving 2023 security incident

#201

Earlier quoted context omitted.

Doesn’t matter. No personal stuff on company devices. I just don’t understand any rational otherwise.

How about a PhD student working on open-source software? A more senior academic?

> How about a PhD student working on open-source software?

- Is the open-source software something that the company is sponsoring?

- If not, do you have permission to use company equipment for personal use?

> A more senior academic?

?

Do you do the above? If so, do you have a personal laptop? if yes, why utilize company property instead of personal, unless given permission to do so?

Re: Thanksgiving 2023 security incident

#202
post #111
post #103

> Analyzing the wiki pages they accessed, bug database issues, and source code repositories, it appears they were looking for information about the architecture, security, and management of our global network; no doubt with an eye on gaining a deeper foothold. For a nation state actor, the easiest way to accomplish that is to send one of their loyal citizens to become an employee of the target company and then have t…

Not if such citizens are sanctioned. Code Red. Hint hint.

> we redirected the efforts of a large part of the Cloudflare technical staff (inside and outside the security team) to work on a single project dubbed “Code Red”.

Code red is a standard term in emergency response that means smoke/fire. In general, in order to “redirect” that much effort one must do some paperwork to prove the urgency and immediacy of the threat.

The MO screams China to me but I wouldn’t read anything into the name “code red” which would have been selected before they identified the specific threat actor anyway.

Re: Thanksgiving 2023 security incident

#203

Earlier quoted context omitted.

Not until just now I didn't. Do they not have a smartphone? A personal laptop? I'm waiting for something to build as I'm typing this right now. On a separate computer. I would never go on Hacker News on my work computer. Why would I use a device to do personal things that they MITM everything I do on it? Privacy is too important to me to give it away like that. I'm sure all traffic on the corporate network is logged.…

If you're sitting in the office waiting for something to build, and you get out your phone to go on HN I'm sorry to say that is probably not the sort of professionalism that's going to afford you much protection from layoffs.

Probably so, but at least my company can't MITM and log all my traffic.

Re: Thanksgiving 2023 security incident

#204
post #120

Earlier quoted context omitted.

Stuxnet?

Stuxnet targeted the uranium enrichment facility at Natanz run by the Iranian government. When does the US attack private enterprise?

The NSA spied on French private companies according to Wikileaks docs from 2015. [1]

There's many such cases. They're well known for spying on Siemens as well. With allies like the United States, who needs enemies?

[1] https://www.spiegel.de/politik/ausland/wikileaks-enthuellung...

Re: Thanksgiving 2023 security incident

#205

Earlier quoted context omitted.

Doesn’t matter. No personal stuff on company devices. I just don’t understand any rational otherwise.

So you just don't listen to music at work?

There's a huge difference between using your personal Spotify account at work and using your personal Github account at work.

Re: Thanksgiving 2023 security incident

#206
post #6

> we were (for the second time) the victim of a compromise of Okta’s systems I'm curious if they're rethinking being on Okta.

My company will only give us new laptops that are preinstalled with Okta’s management system. I am grandfathered in to an old MacBook that has absolutely no management software on it, from the “Early Days” when there was no IT and we just got brand new untouched laptops. They offered me an upgrade to an M1/M2 pro, but I refused, saying that I wasn’t willing to use Okta’s login system if I have my own personal passwor…

I wouldn't use Okta at work, but as a network administrator, I also wouldn't allow your improperly managed laptop to talk to business resources (and I'd demand anyone overruling me sign a written statement demanding it to exempt me for responsibility for it). Wild you work somewhere that is letting you get away with that.

Re: Thanksgiving 2023 security incident

#207
post #89

Earlier quoted context omitted.

The parent's view does seem a bit extreme, but there is always some overlap. Whatever HR system you have is going to be in a weird area of personal/employee overlap, as it'll need to have a password that your personal life has access to. (As tax documents, pay stubs, benefits stuff, etc. all impact the "personal" side of one's life. E.g., I need to store — in my personal archives — the years W-2.) Also, people just d…

It's not extreme at all, it's the bare minimum that professionals do. Absolutely none of my personal stuff ever touches a corporate machine. Ever. I wouldn't even log in to the W2 downloading app as an employee from the work machine. Granting work ssh keys access to your personal machine is crazy; if your work machine gets compromised, they steal your entire personal system's home directory too. Why would you unneces…

What's the realistic threat model here? Someone hacks your company and during their exploitation window they're going to focus on... keylogging/MITMing random devs (likely far more paranoid/observant than the average computer user) so that they can get access to their personal machines via some artisan crafted attack to maybe make a fraudulent transfer from one person's bank account? In what world is that a low-hanging fruit to go after?

Re: Thanksgiving 2023 security incident

#208
post #65
post #7

Which "nation state" do we think this was?

Which nation state has good enough employment protection laws that they can take weekends off while doing recon on a top value target?

I assume the break is to have less chance of their activities be discovered and/or connected.

Re: Thanksgiving 2023 security incident

#209
post #204

Earlier quoted context omitted.

Stuxnet targeted the uranium enrichment facility at Natanz run by the Iranian government. When does the US attack private enterprise?

The NSA spied on French private companies according to Wikileaks docs from 2015. [1] There's many such cases. They're well known for spying on Siemens as well. With allies like the United States, who needs enemies? [1] https://www.spiegel.de/politik/ausland/wikileaks-enthuellung...

And NSA worked with Canada to penetrate a Brazilian oil company, which Snowden leaked

There was also inferences that they penetrated Huawei.

Re: Thanksgiving 2023 security incident

#210

Earlier quoted context omitted.

Sounds like a misunderstanding. They just remove you from the org. (And if they don't, it's not your problem.)

But being part of an organization, don’t they have admin control over your account? Could delete all of your repos, reset your keys, access private repos, etc. Even if a tiny risk, it seems silly just to bolster the GH activity graph.

No. They have control over your membership in their org and which of their repos you can access, not your repos. Note that a GitHub account can be members of multiple orgs.
Post reply on HN