5 ms·
I love how pwned corporations can now use their loss as a marketing story. "We got hacked but our product saved us! Here's how you can get hacked and live to te
by deft 6y ago
I love how pwned corporations can now use their loss as a marketing story. "We got hacked but our product saved us! Here's how you can get hacked and live to tell the tale too, first step is just Trust Us."
EDIT: reading the comments here now, and CF is astroturfing the thread. LOL.
- bredren 6y agoI also thought this rode the line a little bit on the marketing side and maybe a tad light on the security incident response side. It’s okay to name the products and why they are used but the posts lacks some subtlety. Reminds me of podcasts where the guest gets into talking about their product / company way too early instead of focusing discussion on the problem space in general.
- lupire 6y agoCF's blog post is terrible because they are saying "hacking our junky outsourced cameras doesn't give you access to anything else" without addressing the risk that all the rest of their stuff may be as junky as the cameras that they completely failed to audit the security of.
- nlh 6y agoI honestly don't see how CloudFlare is a "pwned corporation" in this situation. Their security vendor got pwned. Nothing from CloudFlare was accessed other than security footage (from the vendor). You don't get to say you robbed a bank because you were able to walk into the lobby after hours.
- mike_d 6y ago> You don't get to say you robbed a bank because you were able to walk into the lobby after hours. This was absolutely a breach of a device on their corporate network and should be treated as such. Just because the network wasn't interesting, doesn't mean the breach didn't happen. I have sympathy for their IR team because this would just be a random Tuesday had it not made it to the press.