Live data from Hacker News

Thanksgiving 2023 security incident

blog.cloudflare.com

91–100 of 336 posts

Re: Thanksgiving 2023 security incident

#91
post #76

Earlier quoted context omitted.

I think they did have to do that far though. Getting in at the "ground floor" of a new datacentre build is pretty much the ultimate exploit. Imagine getting in at the centre of a new Meet-Me room ( https://en.wikipedia.org/wiki/Meet-me_room ) and having persistent access to key switches there. Cloudflare datacentres tend to be at the hub of insane amounts of data traffic. The fact that the attacker knew how valuable…

> Imagine getting in at the centre of a new Meet-Me room and having persistent access to key switches there. This wouldn't get you much. We already assume the network is insecure. This is why TLS is a thing (and mTLS for those who are serious).

> We already assume the network is insecure.

Maybe naively, I wish this assumption became universal.

Re: Thanksgiving 2023 security incident

#92

Earlier quoted context omitted.

Why do you need personal passwords on your laptop to do your work? I'm not understanding this.

Fair question, but I use a lot of things that are varying degrees of helpful for my work: * personal ChatGPT and copilot subscriptions, since company doesn’t pay for these * Trello account for keeping track of my todo list (following up with people, running deploys) * Obsidian for keeping notes, as a personal knowledge-base (things like technologies and reminders) * Apple account for music, copy/paste, sharing photos…

You use so many personal accounts for work that it's unfathomable for me. If some hacker manages to hack into your account and find so much valuable information about your work, your work is going to be mightily pissed about it. Imagine you are working on an upcoming product launch and the attacker used your personal account to leak the launch. Or imagine they just decided to leak your company's internal source code. Or imagine they simply use the technical information in your personal attacks to steal user data (even Cloudflare says they worry about this: "Our aim was to prevent the attacker from using the technical information about the operations of our network as a way to get back in").

You are making your work take on an extraordinary risk in hiring you.

Re: Thanksgiving 2023 security incident

#93
post #5

> Even though we believed, and later confirmed, the attacker had limited access, we undertook a comprehensive effort to rotate every production credential (more than 5,000 individual credentials), physically segment test and staging systems, performed forensic triages on 4,893 systems, reimaged and rebooted every machine in our global network including all the systems the threat actor accessed and all Atlassian produ…

Having seen the small number of DEFCON talks that I've seen, I would have absolutely gone that far.

Re: Thanksgiving 2023 security incident

#94
post #70

Earlier quoted context omitted.

I think they did have to do that far though. Getting in at the "ground floor" of a new datacentre build is pretty much the ultimate exploit. Imagine getting in at the centre of a new Meet-Me room ( https://en.wikipedia.org/wiki/Meet-me_room ) and having persistent access to key switches there. Cloudflare datacentres tend to be at the hub of insane amounts of data traffic. The fact that the attacker knew how valuable…

> It would be a company ending event Given they got out of cloudbleed without any real damage let alone lasting damage, I disagree. (I don't disagree with your point about how bad of a problem this would be, I'm just insisting that security failure is not taken seriously at all by anyone)

Presuming taviso is not exaggerating and why would he CF's reply to cloudbleed was ... not quite nice.

https://twitter.com/taviso/status/1566077115992133634

> True story: After cloudbleed, cloudflare literally lobbied the FTC to investigate me and question the legality of openly discussing security research. How come they're not lobbying their DC friends to investigate the legality KF?

For those not familiar with the history , this tweet started the cloudbleed disclosure to cloudflare:

https://twitter.com/taviso/status/832744397800214528

> Could someone from cloudflare security urgently contact me.

This followed: https://blog.cloudflare.com/incident-report-on-memory-leak-c...

Re: Thanksgiving 2023 security incident

#95

Earlier quoted context omitted.

A Github account, for one possible example.

Well, why? It just seems risky. Everything you make on your work laptop / during work hours is typically owned by your employer. If your employer is paying you to contribute to OSS, don't use your personal github account. Just don't ever mix personal and company accounts on company hardware.

Note that if you do make a second account, at least one of them must be a paid account. A single person cannot have multiple free accounts and GitHub does not care if it's because one is for work; it's in the TOS.

Re: Thanksgiving 2023 security incident

#96
post #86

Earlier quoted context omitted.

Fair question, but I use a lot of things that are varying degrees of helpful for my work: * personal ChatGPT and copilot subscriptions, since company doesn’t pay for these * Trello account for keeping track of my todo list (following up with people, running deploys) * Obsidian for keeping notes, as a personal knowledge-base (things like technologies and reminders) * Apple account for music, copy/paste, sharing photos…

> personal Trello account for keeping track of my todo list. > personal Obsidian for keeping meeting notes, and recording conversations as a personal knowledge-base I'm not a lawyer, but I'm pretty sure these could subject a lot of your other personal data to potential subpoena should your employer get sued by a sufficiently determined attacker. Don't cross the streams.

Also it's a violation of Obsidian's license:

> Obsidian is free for personal and non-profit use. However, if you use Obsidian for work-related activities that generate revenue in a company with two or more people, you must purchase a commercial license for each user. Non-profit organizations are exempt from this requirement.

https://obsidian.md/license

Re: Thanksgiving 2023 security incident

#97

Earlier quoted context omitted.

Fair question, but I use a lot of things that are varying degrees of helpful for my work: * personal ChatGPT and copilot subscriptions, since company doesn’t pay for these * Trello account for keeping track of my todo list (following up with people, running deploys) * Obsidian for keeping notes, as a personal knowledge-base (things like technologies and reminders) * Apple account for music, copy/paste, sharing photos…

Let me get this straight… you’re taking privileged company information and transferring it to personal… I’m now understanding how people get sued when going from company to company.

Certainly nothing privileged! Moreso just reminders about “follow up with person x” and that kind of thing

Re: Thanksgiving 2023 security incident

#98

Earlier quoted context omitted.

Why do you need personal passwords on your laptop to do your work? I'm not understanding this.

The parent's view does seem a bit extreme, but there is always some overlap. Whatever HR system you have is going to be in a weird area of personal/employee overlap, as it'll need to have a password that your personal life has access to. (As tax documents, pay stubs, benefits stuff, etc. all impact the "personal" side of one's life. E.g., I need to store — in my personal archives — the years W-2.) Also, people just d…

>From a technical standpoint, my employer could hack/compromise my personal laptop. From a legal and trust standpoint, I presume they won't.)

You trust all personnel with access to your employers network?

What's more surprising is that they trust you to setup adhoc ssh connections to arbitrary endpoints; unless you're the person in charge of network security?

Would anyone notice if you, or an intruder, dumped terabytes of data over that connection?

I don't work in IT but this just doesn't feel right to me.

Re: Thanksgiving 2023 security incident

#100
post #19

The most surprising part of this is that Cloudflare uses BitBucket.

Maybe but maybe not. I don't like Bitbucket but there are a number of large companies where they worry about using services owned by competitors in one of their verticals.

Bitbucket doesn't have to be a service. It can be an old-fashioned downloaded software that you install on your own machines. Not everything is SaaS.
Post reply on HN