Earlier quoted context omitted.
>If you manage to pwn a key, you have access to traffic. That's why I mentioned "Full (Strict)" SSL. If you configure this in Cloudflare then the entire user Cloudflare origin path is encrypted and attackers can't snoop on the plaintext even if they have access. They'll get some metadata, but every ISP in the world gets that at all times anyway.
While both client and origin network connections are encrypted with "Full (Strict)" SSL mode, Cloudflare proxy in the middle decrypts client traffic and then encrypts it towards the server (and vice versa). It does have access to plaintext, which is how various mitigations work. So it's indeed MITM proxy, by design.
Thanksgiving 2023 security incident
331–336 of 336 posts
Re: Thanksgiving 2023 security incident
#332Re: Thanksgiving 2023 security incident
#333Earlier quoted context omitted.
So you just don't listen to music at work?
There's a huge difference between using your personal Spotify account at work and using your personal Github account at work.
Re: Thanksgiving 2023 security incident
#334The most surprising part of this is that Cloudflare uses BitBucket.
Wonder how powerful is Scriptrunner for Jira. They got the security certifications but I cant tell how sandboxed it is.
https://github.com/BishopFox/sliver
"Since the Smartsheet service account had administrative access to Atlassian Jira, the threat actor was able to install the Sliver Adversary Emulation Framework, which is a widely used tool and framework that red teams and attackers use to enable “C2” (command and control), connectivity gaining persistent and stealthy access to a computer on which it is installed. Sliver was installed using the ScriptRunner for Jira plugin."
https://blog.cloudflare.com/thanksgiving-2023-security-incid...
Re: Thanksgiving 2023 security incident
#335Earlier quoted context omitted.
There's a huge difference between using your personal Spotify account at work and using your personal Github account at work.
I agree, but GP was pretty explicit about "no personal stuff on company devices", and I'm poking a hole in their black-and-white logic.
Re: Thanksgiving 2023 security incident
#336Earlier quoted context omitted.
This came up before and it was super confusing to me because I had no idea what it was referring to but I also believe Tavis isn’t one to make something up. So I took some time to investigate. Turned out, no one on our management, legal, communications, or public policy team had any idea what he was talking about. Eventually I figured out that a non-executive former member of our engineering team was dating someone w…
> we and Project Zero had agreed on a disclosure timeline and then they unilaterally shortened it because an embargo with a reporter got messed up This is not what happened at all. What happened is that after the initial discovery, the gzero team realized it was much worse than expected AND the cloudflare team who he synced with for the disclosure started ghosting him, and yet gzero still kept to the full timeline. I…