Live data from Hacker News

Thanksgiving 2023 security incident

blog.cloudflare.com

261–270 of 336 posts

Re: Thanksgiving 2023 security incident

#262

Earlier quoted context omitted.

None of this would have had anything to do with PCI (nobody gives a shit about PCI; the worst shops in the world, the proprietors of the largest breaches, have had no trouble getting PCI certified and keeping certification after their breaches). At much smaller company sizes than this, insurance requires you to retain forensics/incident response firms. There's a variety of ways they could do that cheaply. They brough…

Yeah at best PCI is somewhat hard to get at first, but after that it's basically only good, or less shady, corporations that bother keeping up compliance or make sure that they follow the guidelines at every step. Shady/troubled operators don't, and to an extent don't have to really be afraid of losing said certification unless they just go fully rogue.

It's not hard to get at first, either. It's the archetypical checklist audit.

Re: Thanksgiving 2023 security incident

#263
post #253

Earlier quoted context omitted.

If a breach is disclosed and some time later your systems are compromised because you didn't bother to take appropriate action in response to that, it's not "fair" to punch down, or even reasonable to do so.

Okta was painfully negligent, with CF going as far as posting "recommendations for Okta" because it was their only way to get through to them. I don't love CF, but IMO Okta deserves to be punched down on.

In both situations Okta and Cloudflare a generic or system account has been compromised. CloudFlare would have had to upload or provide a session tokens or secret to Okta's support system.

Re: Thanksgiving 2023 security incident

#264

Earlier quoted context omitted.

Well, why? It just seems risky. Everything you make on your work laptop / during work hours is typically owned by your employer. If your employer is paying you to contribute to OSS, don't use your personal github account. Just don't ever mix personal and company accounts on company hardware.

Note that if you do make a second account, at least one of them must be a paid account. A single person cannot have multiple free accounts and GitHub does not care if it's because one is for work; it's in the TOS.

I have blissfully been unaware of this. Have even linked free accounts with the account switcher. I'd say this is fairly unenforced.

Re: Thanksgiving 2023 security incident

#265
post #80

Earlier quoted context omitted.

Then you need to let the employer see your lack of productivity when you are limited by the locked-down system. Finding solutions to work around the systems, on your own time and dime, only hurts in the long run. They think everything is fine. Nothing will ever get fixed. Voice these concerns.

I’m not being snarky, but have you ever worked for a company the size of, say, HP? The tools are the tools. There’s nothing me or my boss or theirs can do about it. They just don’t care. But I care, because if nothing else it’s my reputation. (HP used purely for size comparison. I’ve never worked there.)

Then why not leave if there's no prospects of change in the near future and if you really care?

Re: Thanksgiving 2023 security incident

#266

Earlier quoted context omitted.

Why don't you just do those on a second, personal, laptop? Does your workplace restrict you from bringing it in?

Convenience, I suppose… and that doesn’t solve all of the issues (eg Copilot) I’m fine with it because I know there’s no management software on this laptop, but yeah it’s a totally different story if I had to use a newer one with SSO and management software

Part of the comp. package is presumably paying for you to endure some level of inconvenience at the company's request. Such as isolating work and personal things on separate systems.

At least that's how it works in the vast majority of companies.

Re: Thanksgiving 2023 security incident

#267
> The manufacturers’ forensic teams examined all of our systems to ensure that no access or persistence was gained. Nothing was found, but we replaced the hardware anyway.

This seems incredibly wasteful.

Replacing an entire datacenter is effectively tossing tens of millions of dollars of compute hardware.

Re: Thanksgiving 2023 security incident

#268

> The manufacturers’ forensic teams examined all of our systems to ensure that no access or persistence was gained. Nothing was found, but we replaced the hardware anyway. This seems incredibly wasteful. Replacing an entire datacenter is effectively tossing tens of millions of dollars of compute hardware.

It is, but for most of these components there is no other choice since there is no way to guarantee that nothing was changed. lvrick would say that's what why want to attest everything.

Anyway, I really hope that the hardware isn't just tossed into the recycling, but provided to schools and other places that could put them to good use.

Re: Thanksgiving 2023 security incident

#269

> The manufacturers’ forensic teams examined all of our systems to ensure that no access or persistence was gained. Nothing was found, but we replaced the hardware anyway. This seems incredibly wasteful. Replacing an entire datacenter is effectively tossing tens of millions of dollars of compute hardware.

The sentence before...

> To ensure these systems are 100% secure, equipment in the Brazil data center was returned to the manufacturers.

It doesn't say all equipment, and that would have been very helpful. But if it's just two or three access devices sitting on the border, it's not so bad.

Also, the manufacturer likely just sold the hardware to a different customer, sounds like it was pretty new and unused anyway. Just flash the firmware and you're good.

Re: Thanksgiving 2023 security incident

#270

Earlier quoted context omitted.

How about a PhD student working on open-source software? A more senior academic?

> How about a PhD student working on open-source software? - Is the open-source software something that the company is sponsoring? - If not, do you have permission to use company equipment for personal use? > A more senior academic? ? Do you do the above? If so, do you have a personal laptop? if yes, why utilize company property instead of personal, unless given permission to do so?

I'm not an academic, but I have worked with a lot of academics and I think most of them would have no concerns about accessing personal data on their work computer. I thought a university would be an example of a very 'friendly' employer.

An example university policy [1]

> 11.5 reasonable personal use of College IT resources is permitted provided such use does not disrupt the conduct of College business or other users. Recreational use of the Halls of Residence network is also permitted, subject to these conditions;

We have a similar policy where I work. I have a personal laptop, but I don't take it to work. I am signed in to my personal GMail account on my work computer, along with many other accounts — like this HN account. If work needed to look at an employee's computer, we'd have someone from IT + someone from HR overseeing the process, and wouldn't look at anything clearly private, e.g. a personal email account. Doing otherwise would be a breach of the GDPR.

[1] https://www.imperial.ac.uk/admin-services/ict/self-service/c...

Post reply on HN