Live data from Hacker News

Thanksgiving 2023 security incident

blog.cloudflare.com

271–280 of 336 posts

Re: Thanksgiving 2023 security incident

#271
post #119

Earlier quoted context omitted.

We do a lot of hacking

I'm sure we do. I don't agree that we attack private civilian enterprise.

If the usa does I don't understand why you expect we'd know about it. Also the us totally does and we do know about it - the nsa buys zero days - it's not exactly a secret lol

Re: Thanksgiving 2023 security incident

#272

Earlier quoted context omitted.

At every company I've worked for, past 12+ years, this has been the rule, not the exception. They invite your personal github to corporate repos.

I have read a couple of horror stories where it then becomes impossible to separate the account once you leave the employer. No thanks. New account per job.

If the organization has public repositories, and the ex-employee has issues/PRs in those repositories, then I think they will continue to get notifications about followups to those issues.

Involvement with private repositories is removed as soon as the organization removes the employee, or the employee removes themselves.

I think the horror stories could only happen if the individual's account has been used for generating many API keys or similar, but there are other reasons not to rely on that sort of thing.

Re: Thanksgiving 2023 security incident

#273
post #111

Earlier quoted context omitted.

Not if such citizens are sanctioned. Code Red. Hint hint.

> we redirected the efforts of a large part of the Cloudflare technical staff (inside and outside the security team) to work on a single project dubbed “Code Red”. Code red is a standard term in emergency response that means smoke/fire. In general, in order to “redirect” that much effort one must do some paperwork to prove the urgency and immediacy of the threat. The MO screams China to me but I wouldn’t read anythin…

The name has nothing to do with where we believe the attacker came from. We borrowed it from Google. At Google they have a procedure where, in an emergency, they can declare a Code Yellow or Code Red — depending on the severity. When it happens, it becomes the top engineering priority and whoever is leading it can pull any engineer off to work on the emergency. Those may not be the exact details of Google's system but it's the gist that we ran with. We'd had an outage of some of our services earlier in the Fall that prompted us to first borrow Google's idea. Since our logo is orange, we created "Code Orange" to mitigate the mistakes we'd made that led to that outage. Then this happened and we realized we needed something that was a higher level of emergency than Code Orange, so we created Code Red. At some point we'll write up how we thought of the rules and exit criteria around these, but I think they'll become a part of how we deal with emergencies that come up going forward.

Re: Thanksgiving 2023 security incident

#274
post #217

Earlier quoted context omitted.

Probably so, but at least my company can't MITM and log all my traffic.

Agreed. The presumption should be that anything on a work computer is visible to, logged, and retained by your employer. It was a public case, but the essentially unanimous Supreme Court opinion in City of Ontario v. Quon [0, 2010] shows what expectations of privacy you should have on any work devices -- none. [0] https://en.m.wikipedia.org/wiki/City_of_Ontario_v._Quon

Unsurprisingly, the EU has a different idea about employee's privacy when using a work computer.

Reasonable or limited private use of a work computer remains private.

https://edps.europa.eu/data-protection/data-protection/refer...

Re: Thanksgiving 2023 security incident

#275

Earlier quoted context omitted.

> Do not do this, its not a personal device. You think nobody's logged into their personal spotify on their work computer? All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? And that business traveller away from their partner and kids for a week+ isn't going to video call them? Or watch some netflix in their hotel room in the evening? That's so unrealistic, you coul…

> All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives? I've worked for large media companies where this is exactly the only way to have music available. The production network was blocked from accessing the www. To ensure content wasn't pirated, the original media had to be used. No CD-Rs were allowed. Personal devices were kept in lockers outside the restricted areas…

Presumably the company then takes on the task of passing personal messages from outside to their staff, e.g. if a school phones to say a child is sick.

Re: Thanksgiving 2023 security incident

#276
post #209

Earlier quoted context omitted.

And NSA worked with Canada to penetrate a Brazilian oil company, which Snowden leaked There was also inferences that they penetrated Huawei.

Petrobas is state-owned. I might be willing to give you Huawei if you cite a source. They're a gray area (by design) due to China's strategy of military-civil fusion. https://en.wikipedia.org/wiki/Military-civil_fusion

Dude you're replying to a comment that's replying to a comment with a source for what you're asking. I'm not sure why you want it to be the case that the US' cyber warfare capabilities are worse than competing nations but Snowden et al made it pretty clear that we're even invading the privacy of our allies and our own citizens. America is going to be fine we're perfectly capable of hacking foreign private enterprises to protect our interests

Re: Thanksgiving 2023 security incident

#277
post #160

Earlier quoted context omitted.

these were service accounts used by third parties to provide jira integrations, not a user account

If they are using Active Directory, wouldn’t a service account be no different than a regular employee account? Both a Jira service account and the CEO of Cloudflare are still Domain Users in AD. Granted, a service account should be way more locked down and have the least amount of access possible.

https://developers.cloudflare.com/cloudflare-one/identity/se...

Re: Thanksgiving 2023 security incident

#278
post #193

Earlier quoted context omitted.

I love these sorts of comments. Could you please just be more direct and call GP “not a professional” for not working in the way that you do? It’s so unnecessarily passive-aggressive.

You are really, really, really sensitive about this. I wonder why? GP said nothing of the sort.

GP wrote "it's the bare minimum that professionals do".

Re: Thanksgiving 2023 security incident

#279
post #111

Earlier quoted context omitted.

Not if such citizens are sanctioned. Code Red. Hint hint.

> we redirected the efforts of a large part of the Cloudflare technical staff (inside and outside the security team) to work on a single project dubbed “Code Red”. Code red is a standard term in emergency response that means smoke/fire. In general, in order to “redirect” that much effort one must do some paperwork to prove the urgency and immediacy of the threat. The MO screams China to me but I wouldn’t read anythin…

> The MO screams China to me

How exactly ?

Nothing out of the ordinary/regular infiltration, investigation and attempt to move laterally is exposed.

Re: Thanksgiving 2023 security incident

#280

Earlier quoted context omitted.

Yeah at best PCI is somewhat hard to get at first, but after that it's basically only good, or less shady, corporations that bother keeping up compliance or make sure that they follow the guidelines at every step. Shady/troubled operators don't, and to an extent don't have to really be afraid of losing said certification unless they just go fully rogue.

It's not hard to get at first, either. It's the archetypical checklist audit.

Ah I think I'm just not used to those then, I hated the whole checklist busywork that we had to do even though we were barely related to the sales infra. But yeah, it was a bit like soc2 in that regard. Is there any certification that isn't just checklist "auditing"? That involves actual monitoring or something? Not sure if that's even possible
Post reply on HN