Live data from Hacker News

Kurt Got Got

fly.io

91–100 of 256 posts

Re: Kurt Got Got

#91
post #83
post #30

Earlier quoted context omitted.

How does this square with the fact that the tech savvy person in the post was phished despite using a password manager.

The post calls this out: > the 1Password browser plugin would have noticed that “members-x.com” wasn’t an “x.com” host. But shared accounts are tricky here, like the post says it's not part of their IdP / SSO and can't be, so it has to be something different. Yes, they can and should use Passkeys and/or 1password browser integration, but if you only have a few shared accounts, that difference makes for a different wo…

Yes; 1Password was used. And it worked properly. But because humans are fallible, a human made a mistake anyways.

"Properly working password managers" do not provide a strong defense against real world phishing attacks. The weak link of a phishing attack is human fallibility.

Re: Kurt Got Got

#92
post #71
post #61

Earlier quoted context omitted.

Yeah, that was definitely a pebkac on my part.

It's ok, I just couldn't pass up a good opportunity for snark!

It genuinely took me a second - I was midway through writing a very different comment. Apparently reading comprehension is not on my skills list today…

Re: Kurt Got Got

#93

When we did annual pen testing audits for my last company, the security audit company always offered to do phishing or social engineering attacks, but advised against it because they said it worked every single time. One of the most memorable things they shared is they'd throw USB sticks in the parking lot of the company they were pentesting and somebody would always put the thing into a workstation to see what as on…

If you are getting powned by running random executables found on usb drives, passkeys aren’t going to save you. Same if the social engineering is going to get you to install random executables.

Sure; the fix for that is blocking unexpected USB devices on corporate devices.

Re: Kurt Got Got

#94

When we did annual pen testing audits for my last company, the security audit company always offered to do phishing or social engineering attacks, but advised against it because they said it worked every single time. One of the most memorable things they shared is they'd throw USB sticks in the parking lot of the company they were pentesting and somebody would always put the thing into a workstation to see what as on…

If you are getting powned by running random executables found on usb drives, passkeys aren’t going to save you. Same if the social engineering is going to get you to install random executables.

If you're getting pwned a physical Security Key still means bad guys don't have the actual credential (there's no way to get that), and they have to work relatively hard to even create a situation where maybe you to let them use the credential you do have (inside the Security Key) while they're in position to exploit you.

These devices want a physical interaction (this is called "User present") for most operations, typically signified by having a push button or contact sensor, so the attacker needs to have a proof of identity ready to sign, send that over - then persuade the user to push the button or whatever. It's not that difficult but it's one more step and if that doesn't work you wasted your shot.

Re: Kurt Got Got

#95

I don't know the gullibility of the average tech CEO but this doesn't strike me as a very convincing phishing attempt. * "We've received reports about the latest content" - weird copy * "which doesn't meet X Terms of Service" - bad grammar lol * "Important:Simply ..." - no spacing lol * "Simply removing the content from your page doesn't help your case" - weird tone * "We've opened a support portal for you " - weird…

I think you'll be led astray thinking this is CEO-specific.

The whole theory of phishing, and especially targeted phishing, is to present a scenario that tricks the user into ignoring the red flags. Usually, this is an urgent call to action that something negative will happen, coupled with a tie-in to something that seems legit. In this case, it was referencing a real post that the company had made.

A parallel example is when parents get phone calls saying "hey it's your kid, I took a surprise trip to a tiny island nation and I've been kidnapped, I need you to wire $1000 immediately or they're going to kill me". That interaction is full of red flags, but the psychological hit is massive and people pay out all the time.

Re: Kurt Got Got

#96

Earlier quoted context omitted.

If you are getting powned by running random executables found on usb drives, passkeys aren’t going to save you. Same if the social engineering is going to get you to install random executables.

If you're getting pwned a physical Security Key still means bad guys don't have the actual credential (there's no way to get that), and they have to work relatively hard to even create a situation where maybe you to let them use the credential you do have (inside the Security Key) while they're in position to exploit you. These devices want a physical interaction (this is called "User present") for most operations, t…

Malicious binary steals browser cookies giving attacker access to all active sessions?

Re: Kurt Got Got

#97
post #70

Fly has consistently surprised me at how late they have been to doing the "standard company" stuff. Their sort of lack of support engineering teams for a while affected me way more though. You gotta take the Legos away from the CEO! Being CEO means you stop doing the other stuff! Sorry! And yes they have their silly disclaimer on their blog, but this is Yet Another "oh lol we made a whoopsie" tone that they've taken…

I don't know where the official list of "standard company" stuff is, but I'd wager that for small to medium sized tech companies, it's relatively unsurprising for "leadership" to still be in the weeds on various operational projects and systems.

Re: Kurt Got Got

#98
post #80
post #70

Fly has consistently surprised me at how late they have been to doing the "standard company" stuff. Their sort of lack of support engineering teams for a while affected me way more though. You gotta take the Legos away from the CEO! Being CEO means you stop doing the other stuff! Sorry! And yes they have their silly disclaimer on their blog, but this is Yet Another "oh lol we made a whoopsie" tone that they've taken…

We've had an unusually large security team for the size of our company since 2021. I'm sorry if you don't like the way I communicate about it but I have no plans to change that. We take security extremely seriously. We just didn't take Twitter that seriously. The "CEO" thing is just a running joke. Kurt's an engineer. Any of us could have been taken by this. I joke about this because I assume everybody gets the subte…

I'm not talking security, which I generally feel like is probably being done correctly.

I was thinking about, IIRC, back in 2023[0], where you all were suffering a lot of issues. And I _believe_ I saw some chatter about Fly building out a team of support/devops-y/SRE engineers around that time. And I had just assumed up until there that, as a company about operations, that you would already have a team that is about reliability.

I am not a major user of you (You're only selling me like 40 bucks a month of compute/storage/etc), but I had relatively often been hitting weird stuff. Some of it was me, some of it was your side. But... well... I was using Heroku for this stuff before and it seemed to run swimmingly for very long. So I was definitely a bit like "oh OK so you just didn't care about reliability until then?" I mean this lightly, but I started basically anti-recommending you after the combo of the issues and the statements your team was making (both on this kind of operations and also communications after the fact).

I think you all generally do this better now though, so maybe I'm just bringing up old grudges.

> You apparently took it on the surface level, and believe I'm actually dunking on Kurt.

No, I took it in the same tone I take a lot of your company's writing.

> The "CEO" thing is just a running joke. Kurt's an engineer.

I think if you are the CEO of a company above a certain (very low!) headcount you put down the Legos. There are enough "running a company" things to do. Maybe your dynamics are different, since your team is indeed quite small according to the teams page.

Every startup engineer has had to deal with "The CEO is the one with admin rights on this account and he's not doing the thing because somehow we haven't pried the credentials from him so that people doing the work does it". And then the dual of this, "The CEO fixes the thing at 2AM but does it the wrong way and now thing is weird". A way you avoid this is by yanking all credentials from the CEO.

I'm being glib here, because obviously y'all have your success, the Twitter thing "doesn't matter", etc. I just want to be able to recommend you fully, and the issues I hit + the amateur hour comms in response (EDIT: in the past) gets on my nerves and prevents me from doing it!

Anyways, I want you all to succeed.

[0]: https://community.fly.io/t/reliability-its-not-great/11253

Re: Kurt Got Got

#99
post #87
post #85

Earlier quoted context omitted.

I guess I'm just saying "1Password with autofill" will help more than "1Password without autofill". We can always make mistakes of course. And yeah, sometimes we just haven't done something.

I'm saying: an intervention was required here, and that intervention was not changing how we use auto-fill. Doing that would be playing to lose.

Makes sense, think we might have been talking past ourselves. Agreed on what you all actually did being right.

Re: Kurt Got Got

#100
post #95

I don't know the gullibility of the average tech CEO but this doesn't strike me as a very convincing phishing attempt. * "We've received reports about the latest content" - weird copy * "which doesn't meet X Terms of Service" - bad grammar lol * "Important:Simply ..." - no spacing lol * "Simply removing the content from your page doesn't help your case" - weird tone * "We've opened a support portal for you " - weird…

I think you'll be led astray thinking this is CEO-specific. The whole theory of phishing, and especially targeted phishing, is to present a scenario that tricks the user into ignoring the red flags. Usually, this is an urgent call to action that something negative will happen, coupled with a tie-in to something that seems legit. In this case, it was referencing a real post that the company had made. A parallel exampl…

I razz CEOs in jest, but my point is: This is an example of a good phishing attempt? ChatGPT could surely find and fix most of the red flags I called out. Perhaps the red flags ensure they don't phish more people than they can productively exploit.
Post reply on HN