Live data from Hacker News

Thanksgiving 2023 security incident

blog.cloudflare.com

241–250 of 336 posts

Re: Thanksgiving 2023 security incident

#241

Writeups and actions like this from cloudflare are exactly why I trust them with my data and my business. Yes, they aren’t perfect. They do some things that I disagree with. But overall they prove themselves worthy of my trust, specifically because of the engineering mindset that the company shares, and how serious they take things like this. Thank you for the blog post!

Then, the advertisement worked. - Insist that you have better integrity than your competitors - share a few operational investigations after your latest security event what cloudflare doesnt do is provide their SOC risk analysis as a PCI/DSS payment card processor. Cloudflare doesnt explain why they ignored/failed to identify the elevated accounts or how those accounts became compromised to begin with. They just expl…

Nimbius, you sound like you work for a Cloudflare competitor.

No competitors were mentioned in Cloudflares article, they explained what kind of information was breached, nothing to do with payment/card info... so I doubt you even read past the first few paragraphs/conclusion.

Re: Thanksgiving 2023 security incident

#242

Earlier quoted context omitted.

Then, the advertisement worked. - Insist that you have better integrity than your competitors - share a few operational investigations after your latest security event what cloudflare doesnt do is provide their SOC risk analysis as a PCI/DSS payment card processor. Cloudflare doesnt explain why they ignored/failed to identify the elevated accounts or how those accounts became compromised to begin with. They just expl…

> Cloudflare doesnt explain why they ignored/failed to identify the elevated accounts or how those accounts became compromised to begin with. They just explain remediation without accountability. They did, and they admitted that it was their fault. I have to give them credit for that much. > They did this by using one access token and three service account credentials that had been taken, and that we failed to rotate…

The fact that they got their internal source/all bug reports is so bad. Literally every known and unknown vuln in their source is now up for grabs.

Re: Thanksgiving 2023 security incident

#243

Writeups and actions like this from cloudflare are exactly why I trust them with my data and my business. Yes, they aren’t perfect. They do some things that I disagree with. But overall they prove themselves worthy of my trust, specifically because of the engineering mindset that the company shares, and how serious they take things like this. Thank you for the blog post!

Then, the advertisement worked. - Insist that you have better integrity than your competitors - share a few operational investigations after your latest security event what cloudflare doesnt do is provide their SOC risk analysis as a PCI/DSS payment card processor. Cloudflare doesnt explain why they ignored/failed to identify the elevated accounts or how those accounts became compromised to begin with. They just expl…

>Its because PCI/DSS mandates when an organization of any level experiences a data breach or cyber-attack that compromises payment card information

No payment card information was compromised.

Re: Thanksgiving 2023 security incident

#244
post #111

Earlier quoted context omitted.

Not if such citizens are sanctioned. Code Red. Hint hint.

I think this probably was a name after the famous Code Red worm [1], not a reference to China. [1] https://en.wikipedia.org/wiki/Code_Red_(computer_worm)

Or after the flavor of Mountain Dew which was that worm's namesake. Not all names have to make sense. :)

Re: Thanksgiving 2023 security incident

#245

Earlier quoted context omitted.

> Cloudflare doesnt explain why they ignored/failed to identify the elevated accounts or how those accounts became compromised to begin with. They just explain remediation without accountability. They did, and they admitted that it was their fault. I have to give them credit for that much. > They did this by using one access token and three service account credentials that had been taken, and that we failed to rotate…

The fact that they got their internal source/all bug reports is so bad. Literally every known and unknown vuln in their source is now up for grabs.

I mean, per TFA they didn’t get all the source and all the bugs, they accessed only a few hundred jira tickets, and less than a hundred repos.

Re: Thanksgiving 2023 security incident

#246

Earlier quoted context omitted.

This wasn't really an additional failure at Okta. This was credentials lost during the original Okta compromise that CloudFlare failed to rotate out. Okta deserves criticism for their failure, but this feels like CloudFlare punching down to shift blame for a miss on their part.

> They did this by using one access token and three service account credentials that had been taken, and that we failed to rotate , after the Okta compromise of October 2023 It's fair to "punch down" imo as that's how the credentials were originally compromised. I'd agree with you if CF were trying to minimize their own mistake but that doesn't seem to be what is happening here

If a breach is disclosed and some time later your systems are compromised because you didn't bother to take appropriate action in response to that, it's not "fair" to punch down, or even reasonable to do so.

Re: Thanksgiving 2023 security incident

#247
post #94
post #70

Earlier quoted context omitted.

> It would be a company ending event Given they got out of cloudbleed without any real damage let alone lasting damage, I disagree. (I don't disagree with your point about how bad of a problem this would be, I'm just insisting that security failure is not taken seriously at all by anyone)

Presuming taviso is not exaggerating and why would he CF's reply to cloudbleed was ... not quite nice. https://twitter.com/taviso/status/1566077115992133634 > True story: After cloudbleed, cloudflare literally lobbied the FTC to investigate me and question the legality of openly discussing security research. How come they're not lobbying their DC friends to investigate the legality KF? For those not familiar with the…

This came up before and it was super confusing to me because I had no idea what it was referring to but I also believe Tavis isn’t one to make something up. So I took some time to investigate.

Turned out, no one on our management, legal, communications, or public policy team had any idea what he was talking about. Eventually I figured out that a non-executive former member of our engineering team was dating someone who worked as a fairly junior staffer at the FTC. On the employee’s personal time they mentioned being frustrated by how the disclosure took place to the person they were dating. I believe the employee’s frustration was because we and Project Zero had agreed on a disclosure timeline and then they unilaterally shortened it because an embargo with a reporter got messed up.

There was never anything that Cloudflare or any executive raised with the FTC. And the FTC never took or even considered taking any action. The junior FTC staffer may have said something to Tavis or our employee may have said something about telling the staffer they were dating, but that was the extent of it.

I understand Tavis’s perspective, and agree it was inappropriate of the former Cloudflare employee, but this was two people not in any position of leadership at either Cloudflare or the FTC talking very much out of school.

Re: Thanksgiving 2023 security incident

#248
post #85

>The one service token and three accounts were not rotated because mistakenly it was believed they were unused. This odd to me - unused credentials should probably be deleted, not rotated.

Agreed. This whole post reads as "I'm the victim" but they don't admit on the one mistake that snowballed

Re: Thanksgiving 2023 security incident

#249

Earlier quoted context omitted.

> Do not do this, its not a personal device. You think nobody's logged into their personal spotify on their work computer? All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? And that business traveller away from their partner and kids for a week+ isn't going to video call them? Or watch some netflix in their hotel room in the evening? That's so unrealistic, you coul…

> All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? I've worked for large media companies where this is exactly the only way to have music available. The production network was blocked from accessing the www. To ensure content wasn't pirated, the original media had to be used. No CD-Rs were allowed. Personal devices were kept in lockers outside the restricted areas…

In the last 10 years? Outside of govt? That sounds horrifically inefficient for 2024

Re: Thanksgiving 2023 security incident

#250
post #156

They mention Zero Trust, yet you can gain access to applications with just a single bearer token? Am I missing something here? There’s no machine cert used? AuthN tokens aren’t cryptographically bound? This doesn’t meet my definition of ZT, it seems more like “we don’t have a VPN”

Yeah it seems odd to me that their internal wiki, code repo, and Jira is exposed directly to the internet and arbitrary IPs could connect to it. Atlassian had a rash of vulnerabilities recently, who knows how many undiscovered ones still exist.

If they had a VPN in place secured with machine certs, that would be yet another layer for an attacker to defeat.

Post reply on HN