Earlier quoted context omitted.
We do a lot of hacking
I'm sure we do. I don't agree that we attack private civilian enterprise.
Thanksgiving 2023 security incident
271–280 of 336 posts
Re: Thanksgiving 2023 security incident
#272Earlier quoted context omitted.
At every company I've worked for, past 12+ years, this has been the rule, not the exception. They invite your personal github to corporate repos.
I have read a couple of horror stories where it then becomes impossible to separate the account once you leave the employer. No thanks. New account per job.
Involvement with private repositories is removed as soon as the organization removes the employee, or the employee removes themselves.
I think the horror stories could only happen if the individual's account has been used for generating many API keys or similar, but there are other reasons not to rely on that sort of thing.
Re: Thanksgiving 2023 security incident
#273Earlier quoted context omitted.
Not if such citizens are sanctioned. Code Red. Hint hint.
> we redirected the efforts of a large part of the Cloudflare technical staff (inside and outside the security team) to work on a single project dubbed “Code Red”. Code red is a standard term in emergency response that means smoke/fire. In general, in order to “redirect” that much effort one must do some paperwork to prove the urgency and immediacy of the threat. The MO screams China to me but I wouldn’t read anythin…
Re: Thanksgiving 2023 security incident
#274Earlier quoted context omitted.
Probably so, but at least my company can't MITM and log all my traffic.
Agreed. The presumption should be that anything on a work computer is visible to, logged, and retained by your employer. It was a public case, but the essentially unanimous Supreme Court opinion in City of Ontario v. Quon [0, 2010] shows what expectations of privacy you should have on any work devices -- none. [0] https://en.m.wikipedia.org/wiki/City_of_Ontario_v._Quon
Reasonable or limited private use of a work computer remains private.
https://edps.europa.eu/data-protection/data-protection/refer...
Re: Thanksgiving 2023 security incident
#275Earlier quoted context omitted.
> Do not do this, its not a personal device. You think nobody's logged into their personal spotify on their work computer? All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? And that business traveller away from their partner and kids for a week+ isn't going to video call them? Or watch some netflix in their hotel room in the evening? That's so unrealistic, you coul…
> All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? I've worked for large media companies where this is exactly the only way to have music available. The production network was blocked from accessing the www. To ensure content wasn't pirated, the original media had to be used. No CD-Rs were allowed. Personal devices were kept in lockers outside the restricted areas…
Re: Thanksgiving 2023 security incident
#276Earlier quoted context omitted.
And NSA worked with Canada to penetrate a Brazilian oil company, which Snowden leaked There was also inferences that they penetrated Huawei.
Petrobas is state-owned. I might be willing to give you Huawei if you cite a source. They're a gray area (by design) due to China's strategy of military-civil fusion. https://en.wikipedia.org/wiki/Military-civil_fusion
Re: Thanksgiving 2023 security incident
#277Earlier quoted context omitted.
these were service accounts used by third parties to provide jira integrations, not a user account
If they are using Active Directory, wouldn’t a service account be no different than a regular employee account? Both a Jira service account and the CEO of Cloudflare are still Domain Users in AD. Granted, a service account should be way more locked down and have the least amount of access possible.
Re: Thanksgiving 2023 security incident
#278Earlier quoted context omitted.
I love these sorts of comments. Could you please just be more direct and call GP “not a professional” for not working in the way that you do? It’s so unnecessarily passive-aggressive.
You are really, really, really sensitive about this. I wonder why? GP said nothing of the sort.
Re: Thanksgiving 2023 security incident
#279Earlier quoted context omitted.
Not if such citizens are sanctioned. Code Red. Hint hint.
> we redirected the efforts of a large part of the Cloudflare technical staff (inside and outside the security team) to work on a single project dubbed “Code Red”. Code red is a standard term in emergency response that means smoke/fire. In general, in order to “redirect” that much effort one must do some paperwork to prove the urgency and immediacy of the threat. The MO screams China to me but I wouldn’t read anythin…
How exactly ?
Nothing out of the ordinary/regular infiltration, investigation and attempt to move laterally is exposed.
Re: Thanksgiving 2023 security incident
#280Earlier quoted context omitted.
Yeah at best PCI is somewhat hard to get at first, but after that it's basically only good, or less shady, corporations that bother keeping up compliance or make sure that they follow the guidelines at every step. Shady/troubled operators don't, and to an extent don't have to really be afraid of losing said certification unless they just go fully rogue.
It's not hard to get at first, either. It's the archetypical checklist audit.