The thoroughness is pretty amazing
Thanksgiving 2023 security incident
231–240 of 336 posts
Re: Thanksgiving 2023 security incident
#232Earlier quoted context omitted.
Then, the advertisement worked. - Insist that you have better integrity than your competitors - share a few operational investigations after your latest security event what cloudflare doesnt do is provide their SOC risk analysis as a PCI/DSS payment card processor. Cloudflare doesnt explain why they ignored/failed to identify the elevated accounts or how those accounts became compromised to begin with. They just expl…
I was the one who made the call to bring in CrowdStrike. It had zero to do with PCI/DSS or any other compliance obligation. It was to 1) bring in a team with deep experience with a broad set of breaches; and 2) to make sure our team didn’t miss anything. The CrowdStrike team were first class and it was good to confirm they didn’t find anything significant our team hadn’t already. And, for the sake of clarity, no syst…
I guess no need to specific names. I'm just using that as examples.
Re: Thanksgiving 2023 security incident
#233Writeups and actions like this from cloudflare are exactly why I trust them with my data and my business. Yes, they aren’t perfect. They do some things that I disagree with. But overall they prove themselves worthy of my trust, specifically because of the engineering mindset that the company shares, and how serious they take things like this. Thank you for the blog post!
Then, the advertisement worked. - Insist that you have better integrity than your competitors - share a few operational investigations after your latest security event what cloudflare doesnt do is provide their SOC risk analysis as a PCI/DSS payment card processor. Cloudflare doesnt explain why they ignored/failed to identify the elevated accounts or how those accounts became compromised to begin with. They just expl…
Like I get cynicism, but they very clearly explained the lead-up to the accounts being compromised and the mistakes that caused that. They took full accountability of it. Which is frankly more than most companies dealing with security incidents. This entire write-up is more than most companies obligations or responses.
Re: Thanksgiving 2023 security incident
#234Earlier quoted context omitted.
I’ve been in the same situation. With two laptops you lose the ability to, say, send email directly to your task system. It’s really easy to say ‘don’t use your personal stuff at work’, but when work is some locked-down behemoth whose view of productivity software is ‘just use Office’, and you’re really trying to be better at your job, using your own tools can be the only solution. And in my situation, yeah, they did…
Then you need to let the employer see your lack of productivity when you are limited by the locked-down system. Finding solutions to work around the systems, on your own time and dime, only hurts in the long run. They think everything is fine. Nothing will ever get fixed. Voice these concerns.
The tools are the tools. There’s nothing me or my boss or theirs can do about it.
They just don’t care. But I care, because if nothing else it’s my reputation.
(HP used purely for size comparison. I’ve never worked there.)
Re: Thanksgiving 2023 security incident
#235Thing about a data breach is once the data is out there - source code in this case - it’s out there for good and you have absolutely no control over who gets it. You can do as much post incident hardening as you want, and talk about it as much as you want, but the thing you’re trying to protect against, and blogging about how good you’re getting at preventing, has already happened. Can’t unscramble those eggs.
obviously a customer data breach would be worse but this is really no bueno
Re: Thanksgiving 2023 security incident
#236Earlier quoted context omitted.
This smells weird, surely? I'd be looking at who chose not to rotate those particular credentials. 1: "what are these accounts?" 2: "oh they're unused, they don't even appear in the logs" 1: "we should rotate them" 2: "no, let's keep those rando accounts with the old credentials, the ones we think might be compromised ... y' know, for reasons" ?
More likely: "no one has any idea what these old credentials do, so let's not touch them and potentially break everything"
I'd definitely consider a "silent" credential - a credential not registered centrally - to be a huge red flag. Either it could get stolen, or break and no one knows how to regenerate it. And it's pretty easy as devs to quickly generate an auth key that ends up being used permanently, without any documentation.
Re: Thanksgiving 2023 security incident
#237Earlier quoted context omitted.
The NSA spied on French private companies according to Wikileaks docs from 2015. [1] There's many such cases. They're well known for spying on Siemens as well. With allies like the United States, who needs enemies? [1] https://www.spiegel.de/politik/ausland/wikileaks-enthuellung...
I don't know German but nothing on that translated page says anything about hacking or attacking.
Given hacking means unauthorized access to data, can you explain how intercepting confidential documents in an unauthorized manner could not possibly meet the definition?
Additionally, we know much more detail on Siemens, including the planting of malicious code, which absolutely meets any definition of hacking. [1]
Re: Thanksgiving 2023 security incident
#238Earlier quoted context omitted.
> new laptops that are preinstalled with Okta’s management system Okta doesn't make device management software, thats made by companies like Jamf. Okta can integrate with them but Okta isn't what manages your laptop at all. > I wasn’t willing to use Okta’s login system if I have my own personal passwords or keys anywhere on my work computer. Do not do this, its not a personal device.
> Do not do this, its not a personal device. You think nobody's logged into their personal spotify on their work computer? All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? And that business traveller away from their partner and kids for a week+ isn't going to video call them? Or watch some netflix in their hotel room in the evening? That's so unrealistic, you coul…
I've worked for large media companies where this is exactly the only way to have music available. The production network was blocked from accessing the www. To ensure content wasn't pirated, the original media had to be used. No CD-Rs were allowed. Personal devices were kept in lockers outside the restricted areas, so no streaming from them either.
Email was from a remote session. If you were emailed an attachment necessary for production work, there was an approved workflow to scan the data and then make it available to the production network.
So, while you were trying to be sarcastic, there are networks that are set up exactly like you thought didn't exist because it was too outlandish.
Re: Thanksgiving 2023 security incident
#239Earlier quoted context omitted.
> new laptops that are preinstalled with Okta’s management system Okta doesn't make device management software, thats made by companies like Jamf. Okta can integrate with them but Okta isn't what manages your laptop at all. > I wasn’t willing to use Okta’s login system if I have my own personal passwords or keys anywhere on my work computer. Do not do this, its not a personal device.
> Do not do this, its not a personal device. You think nobody's logged into their personal spotify on their work computer? All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? And that business traveller away from their partner and kids for a week+ isn't going to video call them? Or watch some netflix in their hotel room in the evening? That's so unrealistic, you coul…
Re: Thanksgiving 2023 security incident
#240Earlier quoted context omitted.
When it suits them (i.e. when there is data to be gained). But it's more often done through the courts, and when it needs to be a covert op, I'm guessing they'd get their buddies in friendly countries to do the dirty work.
Well how about some evidence then?
As for covert ops, well, they're covert. I don't have any evidence (hence I said "I'm guessing") but that's how I understand secretive agencies do things. If you look at all of the agencies involved in Stuxnet, you'd get the idea that allied countries' secret services tend to work together (or for each other) to some degree when it suits them.