Live data from Hacker News

Thanksgiving 2023 security incident

blog.cloudflare.com

331–336 of 336 posts

Re: Thanksgiving 2023 security incident

#331
post #287

Earlier quoted context omitted.

>If you manage to pwn a key, you have access to traffic. That's why I mentioned "Full (Strict)" SSL. If you configure this in Cloudflare then the entire user Cloudflare origin path is encrypted and attackers can't snoop on the plaintext even if they have access. They'll get some metadata, but every ISP in the world gets that at all times anyway.

While both client and origin network connections are encrypted with "Full (Strict)" SSL mode, Cloudflare proxy in the middle decrypts client traffic and then encrypts it towards the server (and vice versa). It does have access to plaintext, which is how various mitigations work. So it's indeed MITM proxy, by design.

Ah, yeah, you're right.

Re: Thanksgiving 2023 security incident

#333

Earlier quoted context omitted.

So you just don't listen to music at work?

There's a huge difference between using your personal Spotify account at work and using your personal Github account at work.

I agree, but GP was pretty explicit about "no personal stuff on company devices", and I'm poking a hole in their black-and-white logic.

Re: Thanksgiving 2023 security incident

#334

The most surprising part of this is that Cloudflare uses BitBucket.

Wonder how powerful is Scriptrunner for Jira. They got the security certifications but I cant tell how sandboxed it is.

As well as can be expected in a company that gives Smartsheet access to Jira with an Admin Service Account.

https://github.com/BishopFox/sliver

"Since the Smartsheet service account had administrative access to Atlassian Jira, the threat actor was able to install the Sliver Adversary Emulation Framework, which is a widely used tool and framework that red teams and attackers use to enable “C2” (command and control), connectivity gaining persistent and stealthy access to a computer on which it is installed. Sliver was installed using the ScriptRunner for Jira plugin."

https://blog.cloudflare.com/thanksgiving-2023-security-incid...

Re: Thanksgiving 2023 security incident

#335

Earlier quoted context omitted.

There's a huge difference between using your personal Spotify account at work and using your personal Github account at work.

I agree, but GP was pretty explicit about "no personal stuff on company devices", and I'm poking a hole in their black-and-white logic.

Fair enough.

Re: Thanksgiving 2023 security incident

#336
post #285

Earlier quoted context omitted.

This came up before and it was super confusing to me because I had no idea what it was referring to but I also believe Tavis isn’t one to make something up. So I took some time to investigate. Turned out, no one on our management, legal, communications, or public policy team had any idea what he was talking about. Eventually I figured out that a non-executive former member of our engineering team was dating someone w…

> we and Project Zero had agreed on a disclosure timeline and then they unilaterally shortened it because an embargo with a reporter got messed up This is not what happened at all. What happened is that after the initial discovery, the gzero team realized it was much worse than expected AND the cloudflare team who he synced with for the disclosure started ghosting him, and yet gzero still kept to the full timeline. I…

Yo. He's the CEO of CloudFlare. He also seems to have dug into it pretty deep. Not a standard PR response.
Post reply on HN