Live data from Hacker News

Thanksgiving 2023 security incident

blog.cloudflare.com

51–60 of 336 posts

Re: Thanksgiving 2023 security incident

#52

Earlier quoted context omitted.

Why do you need personal passwords on your laptop to do your work? I'm not understanding this.

Fair question, but I use a lot of things that are varying degrees of helpful for my work: * personal ChatGPT and copilot subscriptions, since company doesn’t pay for these * Trello account for keeping track of my todo list (following up with people, running deploys) * Obsidian for keeping notes, as a personal knowledge-base (things like technologies and reminders) * Apple account for music, copy/paste, sharing photos…

Why don't you just do those on a second, personal, laptop?

Does your workplace restrict you from bringing it in?

Re: Thanksgiving 2023 security incident

#53
post #5

> Even though we believed, and later confirmed, the attacker had limited access, we undertook a comprehensive effort to rotate every production credential (more than 5,000 individual credentials), physically segment test and staging systems, performed forensic triages on 4,893 systems, reimaged and rebooted every machine in our global network including all the systems the threat actor accessed and all Atlassian produ…

> The manufacturers’ forensic teams examined all of our systems to ensure that no access or persistence was gained. Nothing was found, but we replaced the hardware anyway. Aha, the old replace-your-trusted-hardware trick.

Manufacturers have had security vulnerabilities for hardware to the point that the firmware on device couldn’t be trusted to be replaced so they said to get new hardware so it’s not a bad strategy.

Re: Thanksgiving 2023 security incident

#54

Am I the only one who just sees a totally blank page? Viewing the HTML shows it's got an empty body tag, and a single script in the with a URL of https://static.cloudflareinsights.com/beacon.min.js/v84a3a40...

No, that's also what I see. I'm not sure why you're getting downvoted.

EDIT: re-opened the link a few minutes later and now I see the post

Re: Thanksgiving 2023 security incident

#55
post #29

Earlier quoted context omitted.

The final security report was only released yesterday, and the amount of work they did to make sure all of their systems were secure after the incident was A Lot; two months is pretty quick for a project of that scale IMO.

Yes, but if after two months they’d found out that customer data had been compromised, that would be a little late for me to do anything about it.

Had customer data been impacted we would have disclosed it immediately.

Re: Thanksgiving 2023 security incident

#56

Earlier quoted context omitted.

Fair question, but I use a lot of things that are varying degrees of helpful for my work: * personal ChatGPT and copilot subscriptions, since company doesn’t pay for these * Trello account for keeping track of my todo list (following up with people, running deploys) * Obsidian for keeping notes, as a personal knowledge-base (things like technologies and reminders) * Apple account for music, copy/paste, sharing photos…

Why don't you just do those on a second, personal, laptop? Does your workplace restrict you from bringing it in?

Convenience, I suppose… and that doesn’t solve all of the issues (eg Copilot)

I’m fine with it because I know there’s no management software on this laptop, but yeah it’s a totally different story if I had to use a newer one with SSO and management software

Re: Thanksgiving 2023 security incident

#57
post #5

> Even though we believed, and later confirmed, the attacker had limited access, we undertook a comprehensive effort to rotate every production credential (more than 5,000 individual credentials), physically segment test and staging systems, performed forensic triages on 4,893 systems, reimaged and rebooted every machine in our global network including all the systems the threat actor accessed and all Atlassian produ…

I think they did have to do that far though. Getting in at the "ground floor" of a new datacentre build is pretty much the ultimate exploit. Imagine getting in at the centre of a new Meet-Me room ( https://en.wikipedia.org/wiki/Meet-me_room ) and having persistent access to key switches there. Cloudflare datacentres tend to be at the hub of insane amounts of data traffic. The fact that the attacker knew how valuable…

do manufacturers share some of the cost of this kind of security related return or is this a straight up "pay twice for the same thing" financial hit?

Re: Thanksgiving 2023 security incident

#58
post #22
post #9

Great write up. > Over the next day, the threat actor viewed 120 code repositories (out of a total of 11,904 repositories > They accessed 36 Jira tickets (out of a total of 2,059,357 tickets) and 202 wiki pages (out of a total of 14,099 pages). Is it just me or 12K git repos and 2 million JIRA tickets sound like a crazy lot. 15K wiki pages is not that high though. > Since the Smartsheet service account had administra…

> Is it just me or 12K git repos and 2 million JIRA tickets sound like a crazy lot. 15K wiki pages is not that high though. I think my org has on the order of 3 repositories per dev? They seem to have 3200 employees, with what I assume to be a slightly higher rate of devs, so you’d expect around 6-7 thousand? 2M Jira tickets is probably easily achieved if you create tickets using any automated process.

They might create a JIRA ticket for each customer support interaction. Would make sense.

Re: Thanksgiving 2023 security incident

#60
post #5

> Even though we believed, and later confirmed, the attacker had limited access, we undertook a comprehensive effort to rotate every production credential (more than 5,000 individual credentials), physically segment test and staging systems, performed forensic triages on 4,893 systems, reimaged and rebooted every machine in our global network including all the systems the threat actor accessed and all Atlassian produ…

I think they did have to do that far though. Getting in at the "ground floor" of a new datacentre build is pretty much the ultimate exploit. Imagine getting in at the centre of a new Meet-Me room ( https://en.wikipedia.org/wiki/Meet-me_room ) and having persistent access to key switches there. Cloudflare datacentres tend to be at the hub of insane amounts of data traffic. The fact that the attacker knew how valuable…

> It would be a company ending event if someone managed to install themselves inside a data centre while it was being built/brought up.

It wouldn't. Most people like to assume the impact of breaches to be what it should be, not what it actually is.

Look at the 1-year stock chart of Okta and, without looking up the actual date, tell me when the breach happened/was disclosed.

Post reply on HN