Live data from Hacker News

Thanksgiving 2023 security incident

blog.cloudflare.com

221–230 of 336 posts

Re: Thanksgiving 2023 security incident

#221
post #209
post #204

Earlier quoted context omitted.

The NSA spied on French private companies according to Wikileaks docs from 2015. [1] There's many such cases. They're well known for spying on Siemens as well. With allies like the United States, who needs enemies? [1] https://www.spiegel.de/politik/ausland/wikileaks-enthuellung...

And NSA worked with Canada to penetrate a Brazilian oil company, which Snowden leaked There was also inferences that they penetrated Huawei.

Petrobas is state-owned.

I might be willing to give you Huawei if you cite a source. They're a gray area (by design) due to China's strategy of military-civil fusion.

https://en.wikipedia.org/wiki/Military-civil_fusion

Re: Thanksgiving 2023 security incident

#222
post #6

> we were (for the second time) the victim of a compromise of Okta’s systems I'm curious if they're rethinking being on Okta.

This wasn't really an additional failure at Okta. This was credentials lost during the original Okta compromise that CloudFlare failed to rotate out. Okta deserves criticism for their failure, but this feels like CloudFlare punching down to shift blame for a miss on their part.

> They did this by using one access token and three service account credentials that had been taken, and that we failed to rotate, after the Okta compromise of October 2023

It's fair to "punch down" imo as that's how the credentials were originally compromised. I'd agree with you if CF were trying to minimize their own mistake but that doesn't seem to be what is happening here

Re: Thanksgiving 2023 security incident

#223

Earlier quoted context omitted.

Okay, I'll bite; what about a github account? You don't generally own code you write for an employer, so why would you be an personal repos from a company machine? (Likewise, there's generally no good reason for the company to have access to personal repos, so those security domains should never overlap)

My Github profile is part of my CV: it shows the projects I've worked on, and those organizations to which I have commit access. Some of those projects are likely to continue even if I change jobs. I think this is fairly common for people who work on open source projects.

On the other hand, I’ve known engineers who were harassed on their GitHub accounts because they stopped working on a project when the company transferred them internally. Some people take you no longer corresponding on a GitHub issue extremely personally. Being able to abandon an “work identity” and move on is useful.

Re: Thanksgiving 2023 security incident

#224
post #94
post #70

Earlier quoted context omitted.

> It would be a company ending event Given they got out of cloudbleed without any real damage let alone lasting damage, I disagree. (I don't disagree with your point about how bad of a problem this would be, I'm just insisting that security failure is not taken seriously at all by anyone)

Presuming taviso is not exaggerating and why would he CF's reply to cloudbleed was ... not quite nice. https://twitter.com/taviso/status/1566077115992133634 > True story: After cloudbleed, cloudflare literally lobbied the FTC to investigate me and question the legality of openly discussing security research. How come they're not lobbying their DC friends to investigate the legality KF? For those not familiar with the…

Yeah cloudflare is pretty sketchy too imo. They present as transparent but they've had some actions over the years that signal otherwise. Heck, pretty much every performance blog post they hype up buries the caveats, kinda reminiscent of Intel always using their custom cpp compiler for benchmarks. Not technically lying, but definitely omitting some context.

Re: Thanksgiving 2023 security incident

#225

Earlier quoted context omitted.

If you use your phone at work, doesn’t that then become discoverable in the legal sense?

Having a cable or radiowaves coming out of your bag or pocket is considered "use", in nonsecured areas?

That’s very much up to the judge to decide…

Re: Thanksgiving 2023 security incident

#226

Earlier quoted context omitted.

When it suits them (i.e. when there is data to be gained). But it's more often done through the courts, and when it needs to be a covert op, I'm guessing they'd get their buddies in friendly countries to do the dirty work.

Well how about some evidence then?

I mean, did we already forget about Ed Snowden and "SSL added and removed here :-)"?

Re: Thanksgiving 2023 security incident

#227
post #120

Earlier quoted context omitted.

Stuxnet?

Stuxnet targeted the uranium enrichment facility at Natanz run by the Iranian government. When does the US attack private enterprise?

Linus Torvalds claims the NSA reached out to him with a backdoor

Also remember the Google sniffing?

https://www.theregister.com/2013/11/07/google_engineers_slam...

Re: Thanksgiving 2023 security incident

#229
post #94
post #70

Earlier quoted context omitted.

> It would be a company ending event Given they got out of cloudbleed without any real damage let alone lasting damage, I disagree. (I don't disagree with your point about how bad of a problem this would be, I'm just insisting that security failure is not taken seriously at all by anyone)

Presuming taviso is not exaggerating and why would he CF's reply to cloudbleed was ... not quite nice. https://twitter.com/taviso/status/1566077115992133634 > True story: After cloudbleed, cloudflare literally lobbied the FTC to investigate me and question the legality of openly discussing security research. How come they're not lobbying their DC friends to investigate the legality KF? For those not familiar with the…

I love this quote:

> However, Server-Side Excludes are rarely used and only activated for malicious IP addresses.

So… you’re celebrating that you only had buffer overruns for malicious IP addresses?

Post reply on HN