Thanksgiving 2023 security incident
261–270 of 336 posts
Re: Thanksgiving 2023 security incident
#262Earlier quoted context omitted.
None of this would have had anything to do with PCI (nobody gives a shit about PCI; the worst shops in the world, the proprietors of the largest breaches, have had no trouble getting PCI certified and keeping certification after their breaches). At much smaller company sizes than this, insurance requires you to retain forensics/incident response firms. There's a variety of ways they could do that cheaply. They brough…
Yeah at best PCI is somewhat hard to get at first, but after that it's basically only good, or less shady, corporations that bother keeping up compliance or make sure that they follow the guidelines at every step. Shady/troubled operators don't, and to an extent don't have to really be afraid of losing said certification unless they just go fully rogue.
Re: Thanksgiving 2023 security incident
#263Earlier quoted context omitted.
If a breach is disclosed and some time later your systems are compromised because you didn't bother to take appropriate action in response to that, it's not "fair" to punch down, or even reasonable to do so.
Okta was painfully negligent, with CF going as far as posting "recommendations for Okta" because it was their only way to get through to them. I don't love CF, but IMO Okta deserves to be punched down on.
Re: Thanksgiving 2023 security incident
#264Earlier quoted context omitted.
Well, why? It just seems risky. Everything you make on your work laptop / during work hours is typically owned by your employer. If your employer is paying you to contribute to OSS, don't use your personal github account. Just don't ever mix personal and company accounts on company hardware.
Note that if you do make a second account, at least one of them must be a paid account. A single person cannot have multiple free accounts and GitHub does not care if it's because one is for work; it's in the TOS.
Re: Thanksgiving 2023 security incident
#265Earlier quoted context omitted.
Then you need to let the employer see your lack of productivity when you are limited by the locked-down system. Finding solutions to work around the systems, on your own time and dime, only hurts in the long run. They think everything is fine. Nothing will ever get fixed. Voice these concerns.
I’m not being snarky, but have you ever worked for a company the size of, say, HP? The tools are the tools. There’s nothing me or my boss or theirs can do about it. They just don’t care. But I care, because if nothing else it’s my reputation. (HP used purely for size comparison. I’ve never worked there.)
Re: Thanksgiving 2023 security incident
#266Earlier quoted context omitted.
Why don't you just do those on a second, personal, laptop? Does your workplace restrict you from bringing it in?
Convenience, I suppose… and that doesn’t solve all of the issues (eg Copilot) I’m fine with it because I know there’s no management software on this laptop, but yeah it’s a totally different story if I had to use a newer one with SSO and management software
At least that's how it works in the vast majority of companies.
Re: Thanksgiving 2023 security incident
#267This seems incredibly wasteful.
Replacing an entire datacenter is effectively tossing tens of millions of dollars of compute hardware.
Re: Thanksgiving 2023 security incident
#268> The manufacturers’ forensic teams examined all of our systems to ensure that no access or persistence was gained. Nothing was found, but we replaced the hardware anyway. This seems incredibly wasteful. Replacing an entire datacenter is effectively tossing tens of millions of dollars of compute hardware.
Anyway, I really hope that the hardware isn't just tossed into the recycling, but provided to schools and other places that could put them to good use.
Re: Thanksgiving 2023 security incident
#269> The manufacturers’ forensic teams examined all of our systems to ensure that no access or persistence was gained. Nothing was found, but we replaced the hardware anyway. This seems incredibly wasteful. Replacing an entire datacenter is effectively tossing tens of millions of dollars of compute hardware.
> To ensure these systems are 100% secure, equipment in the Brazil data center was returned to the manufacturers.
It doesn't say all equipment, and that would have been very helpful. But if it's just two or three access devices sitting on the border, it's not so bad.
Also, the manufacturer likely just sold the hardware to a different customer, sounds like it was pretty new and unused anyway. Just flash the firmware and you're good.
Re: Thanksgiving 2023 security incident
#270Earlier quoted context omitted.
How about a PhD student working on open-source software? A more senior academic?
> How about a PhD student working on open-source software? - Is the open-source software something that the company is sponsoring? - If not, do you have permission to use company equipment for personal use? > A more senior academic? ? Do you do the above? If so, do you have a personal laptop? if yes, why utilize company property instead of personal, unless given permission to do so?
An example university policy [1]
> 11.5 reasonable personal use of College IT resources is permitted provided such use does not disrupt the conduct of College business or other users. Recreational use of the Halls of Residence network is also permitted, subject to these conditions;
We have a similar policy where I work. I have a personal laptop, but I don't take it to work. I am signed in to my personal GMail account on my work computer, along with many other accounts — like this HN account. If work needed to look at an employee's computer, we'd have someone from IT + someone from HR overseeing the process, and wouldn't look at anything clearly private, e.g. a personal email account. Doing otherwise would be a breach of the GDPR.
[1] https://www.imperial.ac.uk/admin-services/ict/self-service/c...