Live data from Hacker News

Why CISA Is Warning CISOs About a Breach at Sisense

krebsonsecurity.com

51–60 of 62 posts

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#51
post #50
post #47

Earlier quoted context omitted.

It does say something that they were interested enough to want the opportunity, but specifically chose not to exercise it. Thought it was a nice addition to the piece.

What does it say? I think adding the comment that they “changed their mind” was unreasonable because they didn’t change their mind. They wanted an opportunity which they got but didn’t exercise. They didn’t say “don’t contact us for comment in the future.” Which would be “changing their mind”. Their comment was simply “no comment”. This seems completely reasonable to me.

That they weren't even prepared enough to say "We at Sisense take security very seriously. Highest priority. Industry standards. Etc. Etc."

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#52
post #51
post #50

Earlier quoted context omitted.

What does it say? I think adding the comment that they “changed their mind” was unreasonable because they didn’t change their mind. They wanted an opportunity which they got but didn’t exercise. They didn’t say “don’t contact us for comment in the future.” Which would be “changing their mind”. Their comment was simply “no comment”. This seems completely reasonable to me.

That they weren't even prepared enough to say "We at Sisense take security very seriously. Highest priority. Industry standards. Etc. Etc."

That seems like a leap. I’m not sure what value can be gained from such an assumption.

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#53
post #12

> Those sources said the breach appears to have started when the attackers somehow gained access to the company’s Gitlab code repository, and in that repository was a token or credential that gave the bad guys access to Sisense’s Amazon S3 buckets in the cloud. So plaintext AWS credentials checked into source control. > Both sources said the attackers used the S3 access to copy and exfiltrate several terabytes worth…

> So plaintext AWS credentials checked into source control.

Could also have been keys set as variables for their CI pipelines to support IaC/etc deployment.

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#54
post #52
post #51

Earlier quoted context omitted.

That they weren't even prepared enough to say "We at Sisense take security very seriously. Highest priority. Industry standards. Etc. Etc."

That seems like a leap. I’m not sure what value can be gained from such an assumption.

Incompetence.

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#55

Earlier quoted context omitted.

My previous team argued with me when i said to avoid using terraform with vault with our state in S3. I eventually got my way after 18 months and found out it was really bad - hard coded s3 access keys were floating around that could read any bucket and they had used terraform with vault and that had pulled all sorts of root level creds into the plain text state files. Lots of other ways to control this risk but I re…

opentofu is solving this with proper state encryption support: https://github.com/opentofu/opentofu/issues/874

State encryption won't solve this problem, it will simply move the key management problem further down the stack. I.e. to the users who are least equipped to deal with it.

The problem is storing anything sensitive at all in terraform. Terraform is terrible for secrets.

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#56
post #54
post #52

Earlier quoted context omitted.

That seems like a leap. I’m not sure what value can be gained from such an assumption.

Incompetence.

“No comment” doesn’t seem like an incompetent comment. Why do you assign more value to unsubstantive PR speak?

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#57
post #56
post #54

Earlier quoted context omitted.

Incompetence.

“No comment” doesn’t seem like an incompetent comment. Why do you assign more value to unsubstantive PR speak?

Because "no comment" is less of a plan than even mindless PR pablum, that a PR agency should have been able to churn out without thinking.

Unless Sisense (a) had no prepared PR plan for this scenario and/or (b) has no idea what actually happened, so are still terrified to legally expose themselves by putting any words to paper.

E.g. They still haven't put out a press release: https://www.sisense.com/newsroom/

Aside from, you know, their piece on how properly isolated multi-tenant is a secure architecture pattern: https://www.sisense.com/blog/benefits-of-next-generation-mul...

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#58
post #57
post #56

Earlier quoted context omitted.

“No comment” doesn’t seem like an incompetent comment. Why do you assign more value to unsubstantive PR speak?

Because "no comment" is less of a plan than even mindless PR pablum, that a PR agency should have been able to churn out without thinking. Unless Sisense (a) had no prepared PR plan for this scenario and/or (b) has no idea what actually happened, so are still terrified to legally expose themselves by putting any words to paper. E.g. They still haven't put out a press release: https://www.sisense.com/newsroom/ Aside f…

What if their prepared plan was “no comment“? I think you’re making an unreasonable number of assumptions.

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#59
post #58
post #57

Earlier quoted context omitted.

Because "no comment" is less of a plan than even mindless PR pablum, that a PR agency should have been able to churn out without thinking. Unless Sisense (a) had no prepared PR plan for this scenario and/or (b) has no idea what actually happened, so are still terrified to legally expose themselves by putting any words to paper. E.g. They still haven't put out a press release: https://www.sisense.com/newsroom/ Aside f…

What if their prepared plan was “no comment“? I think you’re making an unreasonable number of assumptions.

Do you think "no comment" is a good plan, when you've just sent out an emergency email to all of your customers telling them to rotate any credentials they entrusted to you?

Re: Why CISA Is Warning CISOs About a Breach at Sisense

#60
post #59
post #58

Earlier quoted context omitted.

What if their prepared plan was “no comment“? I think you’re making an unreasonable number of assumptions.

Do you think "no comment" is a good plan, when you've just sent out an emergency email to all of your customers telling them to rotate any credentials they entrusted to you?

[deleted]
Post reply on HN