Live data from Hacker News

$5,000 Security Breach

blog.joemoreno.com

1–10 of 26 posts

Re: $5,000 Security Breach

#2
I love how everything is now "heart bleed bug !!!"

We've seen this story over and over on HN, I am not saying it's the case, but usually it's about AWS credential accidentally reveled on source control systems..

Re: $5,000 Security Breach

#3
>'They' spin up spot instances which isn't subject to Billing Alerts. You'll need to cancel those spot instances, revoke your AWS credentials, and change your account password," he said.

This doesn't make sense at all. Amazon should let us if monthly bill > X send me a priority email and phone call. Why do they hide behind these dark patterns? I thought they were better than that.

Re: $5,000 Security Breach

#5
The instance was spun up on April 2, but Heartbleed wasn't disclosed for almost a week later. I highly doubt anybody used the Heartbleed 0-day to access your account.

Re: $5,000 Security Breach

#6

>'They' spin up spot instances which isn't subject to Billing Alerts. You'll need to cancel those spot instances, revoke your AWS credentials, and change your account password," he said. This doesn't make sense at all. Amazon should let us if monthly bill > X send me a priority email and phone call. Why do they hide behind these dark patterns? I thought they were better than that.

The fact of the matter is amazon is a giant company and cannot thoroughly think through each piece of logic in their system.

The reward for focusing on this before-hand is much lower than just writing a check for $5k to this person and then fixing later (lot of $5k checks from amazon today. Wheres mine?)

Re: $5,000 Security Breach

#8
post #5

The instance was spun up on April 2, but Heartbleed wasn't disclosed for almost a week later. I highly doubt anybody used the Heartbleed 0-day to access your account.

According to Cloudflare (http://blog.cloudflare.com/answering-the-critical-question-c...), exploiting heartbleed may actually be very difficult. So yeah, it's very unlikely for that to have happened.

Re: $5,000 Security Breach

#10
Is it too pedantic to want the tech support to just say they were probably mining cryptocurrency instead of bitcoin? It's most likely the intruder was mining either litecoin or whatever coin is most profitable for the month. I know it's all very much the same but they were almost certainly not mining bitcoin.

A $5,000 AWS instance would mine about $1 worth of bitcoin and would not be worth the time logging into someones account.

Post reply on HN