9 ms·
> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, w
by shiftpgdn 7y ago
> hacked into a cloud-computing company server, federal prosecutors in Seattle said
> the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers.
Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.
- united893 7y agoActually looks like she worked for Amazon on S3. So there might have been some insider knowledge. From the complaint below, and googling her name you can find her resume I won't link it here, but here's a screenshot of a snippet: https://i.imgur.com/NezWVKw.png https://i.imgur.com/NezWVKw.png
- kevin_thibedeau 7y agoLooks well qualified to run the coding bootcamp in her prison.
- giancarlostoro 7y agoOnly facing up to 5 years apparently. I wonder if that will change over time. Considering her hack is worse than what Aaron Swartz hacked (not PII) I cant believe she only gets 5 years.
- Reelin 7y ago> worse than what Aaron Swartz hacked (not PII) Violation of copyright would appear to be a significantly worse offense according to present US law.
- lmkg 7y agoIANAL, but I believe part of the issue is that breaching a hundred million records is one data breach, but exfiltrating a few thousand journals is one infringement per journal. In point of fact, the prosecutor on Swartz case (Stephen Heymann) had previous authored an article describing how the Internet age allowed crime to scale, enabling hackers to commit thousands of criminal acts per second. It's my personal belief that Heymann wanted to use Swartz' case as a validation of this belief. (Source: The Idealist: Aaron Swartz and the Rise of Free Culture on the Internet, ISBN 978-1476767727)
- javagram 7y ago“Up to” limits on sentencing are different from what people actually get. Swartz supposedly would have got 6 months recommended by the prosecutor. https://mashable.com/2013/01/17/aaron-swartz-prosecutor-ortiz/ https://mashable.com/2013/01/17/aaron-swartz-prosecutor-orti...
- cameronbrown 7y agoThat is a lot of buzzwords.
- joncrane 7y agoLooks like she only worked there until 2016? Or is that just a resume from 3 years ago?
- guessmyname 7y ago> Looks like she only worked there until 2016? Or is that just a resume from 3 years ago? The last commit in the Git repository where her resume is located shows this: commit 44e40140ab1ccdd47d8b56a8a78fc532d5b3386d (HEAD -> master, origin/master, origin/HEAD) Author: Paige Thompson <paige********@gmail.com> Date: Thu Jan 10 14:38:02 2019 -0800 update linkedin address diff --git a/cv.pdf b/cv.pdf index bf26140..add1ea9 100644 Binary files a/cv.pdf and b/cv.pdf differ If we assume this is the only repository she has, then the resume seems to be up to date.
- notus 7y agoOh cool I use the same LaTeX template as her for my resume. Mine is blue instead of pink though! https://github.com/posquit0/Awesome-CV https://github.com/posquit0/Awesome-CV
- heyoni 7y agoDon’t forget to mention that on your next interview!
- king_panic 7y agoftw
- uxp100 7y agoI feel modern CV is a little clumsy. Especially how it handles columns. You like this better? The example provided I don't love, but I'm not a designer, it looks good enough I think.
- cultus 7y agoI use it too. I think it looks good enough, definitely better than my last horrible-looking resume. It seems to work well with a bit more text compared to many.
- QuinnyPig 7y agoUnlikely. S3 was publicly rebuilt in the wake of the 2017 S3pocalypse.
- bagels 7y agoWhat does this refer to?
- x0x0 7y agoSome S3 eng accidentally dropped a big chunk of the servers that were the s3 equivalent of an hdfs nameserver, ie mapping blob name to location info, as part of an unrelated config change. While attempting to recover, the s3 team discovered and/or decided the nameserver needed a full restart. That's when they discovered the info in the nameserver had grown so large since the last full restart years previous that it took far longer than expected to restart the nameserver. Right around that point in time my guess is they realized just how shit their morning was going to be. And their afternoon. Somewhere in there, they realized that their health dashboard depended on s3 working. Though to be fair, as an aws customer, we -- along with the rest of internet -- were well aware that stuff was badly broken. I feel terribly for whoever did this, because IIRC, he or she just fat fingered part of a command in a standard playbook, and the config script had no safeguards. I personally took down a company you've heard of in the exact same way; I knocked all pops off the internet because the config script had a hard requirement around certain values that was neither communicated to me nor checked. And I was trying to figure out wtf I did to a system that I was not particularly familiar with while receiving forwarded texts from the CEO about cascading datacenter down alerts.
- mywittyname 7y agoIf you don't mind me asking, what was the punishment for what you did?
- x0x0 7y agoJust taking the company dark and being personally embarrassed. There was no punishment, though there was a lot of teasing. Also spending 4-ish weeks cleaning up the mess that was made.
- damontal 7y agoAre Git and SVN really considered IDEs?
- hermitdev 7y agoNot to anyone even remotely in the industry. I think the minimum to be considered an IDE, you need to be able to edit, possibly compile depending on the language, and run/debug from within the same tool. By last loose definition, I've joked my most used "IDE" would be bash. I can edit with vim, compile/link with make/gcc/ld, and debug using gdb or run my bins directly. I mean it's an integrated development environment in that I can access all of my tools from one centralized location, the bash shell, but certainly not integrated in the sense that I have a GUI that hides the nuances of commands of various tools behind menus and friendlier non-command-line names and making it appear that the half dozen or so tools are a single entity. I also use Visual Studio for Windows development and I've been switching between VS Code and PyCharm for Python development. But are git and svn an IDE? No. They are both merely source control management systems.
- efdee 7y agoAre they even considered programs?
- lanstin 7y agoyes, they are programs. They, like most of the truly important software, don't have a UI, but they run none the less.
- efdee 7y agoMy point was going to be that these are concepts and protocols rather than programs, and that you would use an actual program (eg TortoiseGit) to actually use it. But then I read your comment and realised in *nix the program is actually called "git". So I concede :-)
- slowdog 7y agoPretty much doubt there'd be much insider knowledge, guessing in 2015 a L4(entry) System engineer is going to be pretty much spending 80% of their time building new regions by hand... Not much really there to learn
- mc32 7y agoIf you put data in the cloud, make sure you encrypt with keys only you have even when they promise all sorts of assurances of oversight and process in addition to “we use AES”.
- giancarlostoro 7y agoThis right here. Take away any outsiders ability to access things. I also feel AWS and the rest should be able to notify you when files untouched en masse for years are being accessed and it should set off alarms like crazy. If not acted upon then its the issue of whoever got those emails.
- flatiron 7y agoYou can. It’s cloudwatch. Also at least put these things in glacier so you have some time between the download request and when they get the file to hopefully stop it.
- Graham24 7y agoIf you put data in the cloud... assume it is no longer private.
- pravinva 7y agoAs opposed to on your computer connected to the internet?
- yborg 7y agoI know that reading the actual linked content on HN is verboten, but the Bloomberg story says "Thompson was previously an Amazon Web Services employee. She last worked at Amazon in 2016, spokesman Grant Milne said. The breach described by Capitol One didn’t require insider knowledge, he said."
- dmix 7y agoThe parts about Amazon was added later after the article was originally published. Maybe they read HN and found her Gitlab account like was posted below before this was published. Most of those news sites back referral link lists.
- floatingatoll 7y ago“Didn’t require” is a very precise way of stating a truth about the vulnerability that was exploited, while neither confirming nor denying whether her role at Amazon was in some way responsible for her discovering the vulnerability. (If I could query all AWS permissions for publicly exploitable permissions, that would comply, for example.)
- Ajedi32 7y agoThe AWS spokesman quoted in the article also explicitly says it wasn't a vulnerability.
- floatingatoll 7y agoDo you consider an access control misconfiguration to be a vulnerability? Does Amazon? Point stands; they’re being very careful to say that there aren’t any CVEs, but they are also very carefully not saying whether she abused the privileges of her role to identify misconfigurations more rapidly than she could have otherwise.
- lanstin 7y agoDetailed knowledge of a system gives you all kinds of knowledge about how to exploit it. You don't need special access if you know X% of users misconfigure feature Y.
- deleted 7y ago[deleted]
- kevinsundar 7y agoGiven that they're on AWS and "The intrusion occurred through a misconfigured web application firewall that enabled access to the data" thats what im betting too.
- violetviolence 7y agoWell, if it was a misconfigured WAF (which usually is just a reverse proxy with mod_proxy) to an application then you would not need to gain access to any Tokens, etc. all you would need to do is gain access to the server. Or be able to use that WAF as a proxy to gain access to other http bound resources? From there any IAM role access the underlying server had, you would now have as well. And that would work with any sort of access (don't need root, etc.)
- deleted 7y ago[deleted]
- UnoriginalGuy 7y agoKind of like the AT&T "hack" wherein just changing the url leaked other customers info. They were still successfully prosecuted though. And AT&T received no punishment. When a company says jump the USG asks how high.
- aarbor989 7y agoNo way...I don't remember hearing about this. You mean changing the URL from like /data/customer/1 to /data/customer/2 ? And the person who did this was prosecuted? Jeez.
- otterley 7y agoMisconfigured WAF - see my comment elsewhere here. Correction: according to the complaint, the defendant is alleged to have assumed an IAM role in the context of Capital One's account whose policy provided access to the S3 bucket in question. So it wasn't that the S3 bucket was public, but rather, that there was some vulnerability she took advantage of by which she obtained indirect credentials to it. (Complaint, page 6, lines 14-27.)
- samstave 7y agoI wonder what data was in the bucket?
- jlgaddis 7y ago> The largest category of data stolen was supplied by consumers and small businesses when they applied for credit cards from 2005 through early 2019, the bank said. It included personal identification data, including names, addresses, phone numbers and dates of birth, and financial data including self-reported income, credit scores and fragments of transaction history. > About 140,000 Social Security numbers were accessed, as well as 80,000 bank account numbers from credit-card customers, the bank said. I haven't yet read (all of) the complaint but I presume it goes into even more detail than the article did.
- deleted 7y ago[deleted]
- pmredux 7y agoMight have been an SSRF exploit if the WAF was accepting parameter values that were then used to expose IAM credentials via the EC2 metadata service. See https://ejj.io/blog/capital-one https://ejj.io/blog/capital-one for a good write-up.
- daenz 7y agoIf the Seattle "Paige T." is the person with a public Linkedin profile, their recent job history includes "Systems Engineer" at AWS. That could be connected with the breach.
- bilbo0s 7y agoWoah man. You could be costing some unfortunate woman her job here man. Kind of like when that lady cop broke into that black guy's apartment and blew him away. Then all these people on social media started posting pictures of his coworker on social media and almost cost the woman her position at PwC. We should try to be a little more responsible than that.
- filoleg 7y agoWasn't her name that the parent comment referenced originally posted in the news article? If that's the case, I would blame the news article and not the parent. Especially since they said "could" and not "yep, that's her".
- daenz 7y agoI think you're overreacting. Their name is public, and I didn't link to the public profile, nor did I say the public profile was the person in question. Only that if it is them, then having a work history of AWS adds an interesting dimension.
- itake 7y agoAccording to the publicly released report, the woman that was arrested used to work for the "cloud computing company" that was involved. https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl=0 https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...
- EE84M3i 7y agoThe court filing directly says "s3", so yeah, it's Amazon.
- deleted 7y ago[deleted]
- onetimemanytime 7y agoGood thing they didn't mention it by name ;)
- roseway4 7y agoPer the complaint, it doesn't sound like the bucket was exposed to the world. Rather, security credentials were "obtained": > Capital One determined that the first command, when executed, obtained security credentials for an account named XXXX-WAF-Role, that in turn, enabled access to certain of Capital One's folders at the Cloud Computing Company. Unsure how one would obtain credentials for an IAM Role, but the above verbatim from the complaint. * edited to reflect this is lifted from the complaint, not indictment.
- toomuchtodo 7y agoIt's possible an STS token was obtained using the role. If you're not monitoring where those tokens are issued to and used from, you're gonna have a bad time. https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credenti...
- samstave 7y agoI recall a newbie dev at our company some years back accidentally posted creds in code to github. I have talked about this here before - but - we had paid for 200 repos.. problem was he made a new repo, which became 201 - which since we had only paid for 200, github auto makes the next one public. Bots slurp these and hunt... They used those creds to launch like 1700 gpu machines across the globe for a bitcoin mining network... The culprit was from germany... We got it cleared and AWS forgave all the charges.
- scarface74 7y agoIt doesn’t matter. There is never a reason for credentials to be anywhere near your repository. If you’re running locally, you should have your credentials in your home directory (via aws configure). If you are running your code on AWS either on an EC2 instance, lambda, or Docker you should be using the role associated with the execution environment. Every SDK that I have used let’s you use a constructor without a parameter and can get your credentials from the config file/role.
- 7y ago
- jorblumesea 7y agoNot sure if this is a reputable source: https://heavy.com/news/2019/07/paige-adele-thompson/ https://heavy.com/news/2019/07/paige-adele-thompson/ But sounds like she's an engineer that used to work in aws, specifically S3. If true, seems likely as she would have insider knowledge of existing attack vectors and possibly vulns. Maybe even using something we discovered while on the job.
- bifrost 7y agoIf this is true, this is a great reason for people to stop using S3 or to start doing daily bucket audits. Or you know, not store PII in the cloud poorly.
- klarrimore 7y agoThe suspect had previously worked for AWS as well.
- gingabriska 7y agoThere are more details on dailymail article: https://www.dailymail.co.uk/news/article-7299511/Ex-Seattle-tech-worker-arrested-Capital-One-hack-U-S-Justice-Dept.html https://www.dailymail.co.uk/news/article-7299511/Ex-Seattle-...
- eden_hazard 7y agoWhat do these queries look like...