Live data from Hacker News

Hacker confirms access through infostealer infection [withdrawn]

hudsonrock.com

231–235 of 235 posts

Re: Hacker confirms access through infostealer infection [withdrawn]

#231

Earlier quoted context omitted.

@dang is a no-op, consider contacting at the email in the footer. But on the other hand, that they yanked the blog post is interesting and shouldn't be glossed over by just linking to the archive. What changed? Edit: It looks like Snowflake's official response denies essentially all of the claims in TFA. Maybe Hudson Rock got taken in by a dishonest source and pulled the article when they realized their mistake? http…

Quietly pulling the piece without a retraction is pretty shady as well

Yeah that's bad. I've put "[withdrawn]" in the title and taken out the name of the company for now, since it seems unfair to leave it in there. If the claims turn out to have been accurate, we can put it back.

Re: Hacker confirms access through infostealer infection [withdrawn]

#232
post #96

Earlier quoted context omitted.

The whole blog post reeks of extreme self-congratulation and youre right, a total scum move to expose the victim. Altogether very weak performance from Hudson Rock.

Snowflake’s customers are the victim, not Snowflake.

By victim I referred to the Snowflake employee that had their credentials taken

Re: Hacker confirms access through infostealer infection [withdrawn]

#233

Earlier quoted context omitted.

@dang is a no-op, consider contacting at the email in the footer. But on the other hand, that they yanked the blog post is interesting and shouldn't be glossed over by just linking to the archive. What changed? Edit: It looks like Snowflake's official response denies essentially all of the claims in TFA. Maybe Hudson Rock got taken in by a dishonest source and pulled the article when they realized their mistake? http…

Quietly pulling the piece without a retraction is pretty shady as well

Well, they doxed the alleged employee that they claimed was the source of the breach and likely got conned into what could have been a short-selling scam.

Life comes at you fast…

Re: Hacker confirms access through infostealer infection [withdrawn]

#234
post #199

Earlier quoted context omitted.

About as ethical as those other 8200 alums, NSO. The ethics of the IDF on full display.

NSO wasn't founded by 8200 alumni, however companies such as the following were: * Checkpoint * Palo Alto Networks * Waze * Wiz * Cybereason Does your theory hold up? no, but why not generalize

They've supposedly founded >1K companies, so easy to cherry-pick for any desired conclusion, but point taken.

Re: Hacker confirms access through infostealer infection [withdrawn]

#235
post #213

Currently the linked URL 302-redirects to '/'. @dang, consider replacing with: https://web.archive.org/web/20240531140540/https://www.hudso...

@dang is a no-op, consider contacting at the email in the footer. But on the other hand, that they yanked the blog post is interesting and shouldn't be glossed over by just linking to the archive. What changed? Edit: It looks like Snowflake's official response denies essentially all of the claims in TFA. Maybe Hudson Rock got taken in by a dishonest source and pulled the article when they realized their mistake? http…

I don’t think the source was dishonest. Also, Snowflake hasn’t really denied anything. That press release still reads the same, and still acknowledges that customers were impacted.

Also, both infosec groups and journalists were given sample data. On top of that, Live Nation explicitly said in their SEC filing that the breach happened through a third-party cloud provider, which is what Snowflake is.

I think that if Ticketmaster starts to send out breach emails to their customers next week, that will put any suspicions about this being fake to rest.

It’s difficult to imagine ShinyHunters getting duped as well, since they are the initial strongest link to this whole thing.

vx-underground says that Mandiant and Crowdstrike worked with Snowflake and tl;dr of it is that Snowflake wasn’t breached. That is also strange. They weren’t breached but some customers were affected? :jackie_chan_holding_his_head_pic:

Post reply on HN