Live data from Hacker News

Thanksgiving 2023 security incident

blog.cloudflare.com

211–220 of 336 posts

Re: Thanksgiving 2023 security incident

#211

Writeups and actions like this from cloudflare are exactly why I trust them with my data and my business. Yes, they aren’t perfect. They do some things that I disagree with. But overall they prove themselves worthy of my trust, specifically because of the engineering mindset that the company shares, and how serious they take things like this. Thank you for the blog post!

Then, the advertisement worked. - Insist that you have better integrity than your competitors - share a few operational investigations after your latest security event what cloudflare doesnt do is provide their SOC risk analysis as a PCI/DSS payment card processor. Cloudflare doesnt explain why they ignored/failed to identify the elevated accounts or how those accounts became compromised to begin with. They just expl…

I am not sure where you're getting your information on requirements for PCI service providers. There isn't anything inside of PCI DSS that requires some sort of SOC report to be generated and distributed to customers. And Cloudflare does make their PCI AoC available to customers.

They clearly defined the scope of impact, and demonstrated that none of this impacts systems in scope for PCI. There was no breach to change management inside of BitBucket, and none of the edge servers processing cardholder data were impacted. They will have plenty of artifacts to demonstrate that by bringing in an external firm. So I am really not clear why you're bringing up PCI at all here. They made it clear no cardholder data was impacted so your perspective on the required "on-site" audits is moot.

Cloudflare operates two entirely different scopes for PCI; The first being as a Merchant where you the customer pays for the services. This is a very small scope of systems. The second is as a Service Provider that processes cards over the network. The network works such that it is not feasible to exfiltrate card data from the network. There are many reasons as to why this is, but they demonstrate year over year that this is not something that is reasonably possible. You can review their PCI AoC and get the details (albeit limited) to understand this better. Or you could get their SOC 2 Type 2 Report which will cover many aspects of the edge networks control environment with much better testing details. After reading that you can then come back to the blog and see that clearly no PCI scoped systems were impacted in a way that would require any on-prem audit to occur.

And they are not a card network. They are a PCI Service Provider because cards transit over their network. They are not at risk of being unable to process payments or transactions for their Merchant scope even if there are issues with their Service Provider scope. Because, again, these are two separate PCI audits that are done, testing two different sets of systems and controls.

And, as an aside, Cloudflare effectively always has on-prem PCI audits occur. Because the PCI QSA's need to physically visit Cloudflare datacenters to demonstrate not only the software side of compliance, but the datacenters deployed globally.

Re: Thanksgiving 2023 security incident

#212
post #207
post #89

Earlier quoted context omitted.

It's not extreme at all, it's the bare minimum that professionals do. Absolutely none of my personal stuff ever touches a corporate machine. Ever. I wouldn't even log in to the W2 downloading app as an employee from the work machine. Granting work ssh keys access to your personal machine is crazy; if your work machine gets compromised, they steal your entire personal system's home directory too. Why would you unneces…

What's the realistic threat model here? Someone hacks your company and during their exploitation window they're going to focus on... keylogging/MITMing random devs (likely far more paranoid/observant than the average computer user) so that they can get access to their personal machines via some artisan crafted attack to maybe make a fraudulent transfer from one person's bank account? In what world is that a low-hangi…

Devs in small companies often have a ton of access to systems and almost certainly aren’t heavily scrutinized about random novel binaries (being devs), so those are some of the first machines you’d target in an org.

You wouldn’t keylog “random devs”, you’d keylog all of the ones doing ops.

Re: Thanksgiving 2023 security incident

#213
Such a beautiful report and beautiful ownage.

Whenever some shitty Australian telco gets owned, people are angry and call them incompetent and idiots; it's nice to see Cloudflare gets owned in style with much more class and expertise.

Like the rest of the HN crowd, this incident has only increased my trust in Cloudflare.

Re: Thanksgiving 2023 security incident

#214
post #212
post #207

Earlier quoted context omitted.

What's the realistic threat model here? Someone hacks your company and during their exploitation window they're going to focus on... keylogging/MITMing random devs (likely far more paranoid/observant than the average computer user) so that they can get access to their personal machines via some artisan crafted attack to maybe make a fraudulent transfer from one person's bank account? In what world is that a low-hangi…

Devs in small companies often have a ton of access to systems and almost certainly aren’t heavily scrutinized about random novel binaries (being devs), so those are some of the first machines you’d target in an org. You wouldn’t keylog “random devs”, you’d keylog all of the ones doing ops.

Would someone making a serious, targeted attack on the company focus on ops staff, and maybe go to the trouble of keylogging them? Sure. But those are precisely the attackers who wouldn't get distracted (and risk detection) going after those staff's personal machines.

Re: Thanksgiving 2023 security incident

#215

Earlier quoted context omitted.

Not until just now I didn't. Do they not have a smartphone? A personal laptop? I'm waiting for something to build as I'm typing this right now. On a separate computer. I would never go on Hacker News on my work computer. Why would I use a device to do personal things that they MITM everything I do on it? Privacy is too important to me to give it away like that. I'm sure all traffic on the corporate network is logged.…

If you're sitting in the office waiting for something to build, and you get out your phone to go on HN I'm sorry to say that is probably not the sort of professionalism that's going to afford you much protection from layoffs.

This comes off as passive aggressive and misinformed. I agree with not putting personal things on work devices as much as possible.

Been in the industry for a while now, no one cares if you pull out your phone. Generally, people treat others like adults not children.

Re: Thanksgiving 2023 security incident

#216

Earlier quoted context omitted.

Even among engineers, most people don't think like a security engineer. I'm sure there are plenty of people who have access to their company's private repos through their personal GitHub accounts.

At every company I've worked for, past 12+ years, this has been the rule, not the exception. They invite your personal github to corporate repos.

So?

Re: Thanksgiving 2023 security incident

#217

Earlier quoted context omitted.

If you're sitting in the office waiting for something to build, and you get out your phone to go on HN I'm sorry to say that is probably not the sort of professionalism that's going to afford you much protection from layoffs.

Probably so, but at least my company can't MITM and log all my traffic.

Agreed. The presumption should be that anything on a work computer is visible to, logged, and retained by your employer.

It was a public case, but the essentially unanimous Supreme Court opinion in City of Ontario v. Quon [0, 2010] shows what expectations of privacy you should have on any work devices -- none.

[0] https://en.m.wikipedia.org/wiki/City_of_Ontario_v._Quon

Re: Thanksgiving 2023 security incident

#218
post #80
post #69

Earlier quoted context omitted.

I’ve been in the same situation. With two laptops you lose the ability to, say, send email directly to your task system. It’s really easy to say ‘don’t use your personal stuff at work’, but when work is some locked-down behemoth whose view of productivity software is ‘just use Office’, and you’re really trying to be better at your job, using your own tools can be the only solution. And in my situation, yeah, they did…

Then you need to let the employer see your lack of productivity when you are limited by the locked-down system. Finding solutions to work around the systems, on your own time and dime, only hurts in the long run. They think everything is fine. Nothing will ever get fixed. Voice these concerns.

Hurts who? If you’ve worked around it then it doesn’t hurt you, at least not too badly. It still hurts the company as a whole. But is that your problem?

You might feel a sense of social obligation or solidarity with the company. I usually do. But if I was placed in a dehumanizing situation like that – forced to work inefficiently due to overly rigid policies that assume everyone’s needs are the same – well, whether I worked around it or not, my empathy for the company would be at a nadir whenever I thought about it.

Re: Thanksgiving 2023 security incident

#219
post #6

> we were (for the second time) the victim of a compromise of Okta’s systems I'm curious if they're rethinking being on Okta.

This wasn't really an additional failure at Okta. This was credentials lost during the original Okta compromise that CloudFlare failed to rotate out. Okta deserves criticism for their failure, but this feels like CloudFlare punching down to shift blame for a miss on their part.

This wasn’t a new compromise, but there were still two Okta compromises that impacted CloudFlare

January 2022: https://blog.cloudflare.com/cloudflare-investigation-of-the-...

October 2023: https://blog.cloudflare.com/how-cloudflare-mitigated-yet-ano...

Re: Thanksgiving 2023 security incident

#220
post #204

Earlier quoted context omitted.

Stuxnet targeted the uranium enrichment facility at Natanz run by the Iranian government. When does the US attack private enterprise?

The NSA spied on French private companies according to Wikileaks docs from 2015. [1] There's many such cases. They're well known for spying on Siemens as well. With allies like the United States, who needs enemies? [1] https://www.spiegel.de/politik/ausland/wikileaks-enthuellung...

I don't know German but nothing on that translated page says anything about hacking or attacking.
Post reply on HN