Earlier quoted context omitted.
It does say something that they were interested enough to want the opportunity, but specifically chose not to exercise it. Thought it was a nice addition to the piece.
What does it say? I think adding the comment that they “changed their mind” was unreasonable because they didn’t change their mind. They wanted an opportunity which they got but didn’t exercise. They didn’t say “don’t contact us for comment in the future.” Which would be “changing their mind”. Their comment was simply “no comment”. This seems completely reasonable to me.
Why CISA Is Warning CISOs About a Breach at Sisense
51–60 of 62 posts
Re: Why CISA Is Warning CISOs About a Breach at Sisense
#52Earlier quoted context omitted.
What does it say? I think adding the comment that they “changed their mind” was unreasonable because they didn’t change their mind. They wanted an opportunity which they got but didn’t exercise. They didn’t say “don’t contact us for comment in the future.” Which would be “changing their mind”. Their comment was simply “no comment”. This seems completely reasonable to me.
That they weren't even prepared enough to say "We at Sisense take security very seriously. Highest priority. Industry standards. Etc. Etc."
Re: Why CISA Is Warning CISOs About a Breach at Sisense
#53> Those sources said the breach appears to have started when the attackers somehow gained access to the company’s Gitlab code repository, and in that repository was a token or credential that gave the bad guys access to Sisense’s Amazon S3 buckets in the cloud. So plaintext AWS credentials checked into source control. > Both sources said the attackers used the S3 access to copy and exfiltrate several terabytes worth…
Could also have been keys set as variables for their CI pipelines to support IaC/etc deployment.
Re: Why CISA Is Warning CISOs About a Breach at Sisense
#54Re: Why CISA Is Warning CISOs About a Breach at Sisense
#55Earlier quoted context omitted.
My previous team argued with me when i said to avoid using terraform with vault with our state in S3. I eventually got my way after 18 months and found out it was really bad - hard coded s3 access keys were floating around that could read any bucket and they had used terraform with vault and that had pulled all sorts of root level creds into the plain text state files. Lots of other ways to control this risk but I re…
opentofu is solving this with proper state encryption support: https://github.com/opentofu/opentofu/issues/874
The problem is storing anything sensitive at all in terraform. Terraform is terrible for secrets.
Re: Why CISA Is Warning CISOs About a Breach at Sisense
#56Re: Why CISA Is Warning CISOs About a Breach at Sisense
#57Earlier quoted context omitted.
Incompetence.
“No comment” doesn’t seem like an incompetent comment. Why do you assign more value to unsubstantive PR speak?
Unless Sisense (a) had no prepared PR plan for this scenario and/or (b) has no idea what actually happened, so are still terrified to legally expose themselves by putting any words to paper.
E.g. They still haven't put out a press release: https://www.sisense.com/newsroom/
Aside from, you know, their piece on how properly isolated multi-tenant is a secure architecture pattern: https://www.sisense.com/blog/benefits-of-next-generation-mul...
Re: Why CISA Is Warning CISOs About a Breach at Sisense
#58Earlier quoted context omitted.
“No comment” doesn’t seem like an incompetent comment. Why do you assign more value to unsubstantive PR speak?
Because "no comment" is less of a plan than even mindless PR pablum, that a PR agency should have been able to churn out without thinking. Unless Sisense (a) had no prepared PR plan for this scenario and/or (b) has no idea what actually happened, so are still terrified to legally expose themselves by putting any words to paper. E.g. They still haven't put out a press release: https://www.sisense.com/newsroom/ Aside f…
Re: Why CISA Is Warning CISOs About a Breach at Sisense
#59Earlier quoted context omitted.
Because "no comment" is less of a plan than even mindless PR pablum, that a PR agency should have been able to churn out without thinking. Unless Sisense (a) had no prepared PR plan for this scenario and/or (b) has no idea what actually happened, so are still terrified to legally expose themselves by putting any words to paper. E.g. They still haven't put out a press release: https://www.sisense.com/newsroom/ Aside f…
What if their prepared plan was “no comment“? I think you’re making an unreasonable number of assumptions.
Re: Why CISA Is Warning CISOs About a Breach at Sisense
#60Earlier quoted context omitted.
What if their prepared plan was “no comment“? I think you’re making an unreasonable number of assumptions.
Do you think "no comment" is a good plan, when you've just sent out an emergency email to all of your customers telling them to rotate any credentials they entrusted to you?