8 ms·
For people wondering about how they get access to these systems, it feels like they use the weakest human link in the chain. I checked their telegram group and
by nstart 5y ago
For people wondering about how they get access to these systems, it feels like they use the weakest human link in the chain.
I checked their telegram group and I can see that they specifically recruit people with access to VPNs/internal support systems. This okta breach seems to have happened through similar means. The group has made specific calls for access to gaming companies, hosting providers, telcos, call centers, and bpm providers. They offer payment.
It doesn’t feel difficult to see how some overworked, underpaid support agent (or even a well paid disgruntled one) might decide to go with this. Just takes 1 well placed agent to give creds and this group has access to a huge attack surface instantly. This might sound like an overreaction, but corporations in the future might need to make least privilege access and access logging everything a priority from day 1.
https://t.me/minsaudebr/162 https://t.me/minsaudebr/162 (Link to the recruitment message)
- zacmps 5y agoI wonder if it would be possible to counter this with policy, something like: > If you receive a credible bribe and report it immediately to X we will report to relevant authorities and provide a bonus equal to the value of the bribe (capped at Y).
- numpad0 5y agoSadly a whistleblower protection becomes an organized victim blaming too fast and easily
- sfe22 5y agoThis assumes money is the only factor and motivation.
- jjav 5y ago> This assumes money is the only factor and motivation. Only if you assert that it is only useful if it solves 100% of the cases. There are other motivations, but money is a big one. If you could block X% for a large value of X (I'd say easily > 50) then you're better off than before, even if some insiders driven by other motivations still remain.
- bawolff 5y agoI wouldn't say easily over 50%. For example https://www.varonis.com/blog/inside-world-insider-threats-part-motivation https://www.varonis.com/blog/inside-world-insider-threats-pa... says roughly about half, and that sample might be biased as i assume its easier to take someone to court if they did it for money. Still your point stands that money is a common factor. However you still have the problem that bribes usually aren't a one time payment but an ongoing thing, so a purely financially motivated adversary would take the total value into account.
- hetspookjee 5y agoTo add to the other comments this also assumes trust in the employer. If you’re disgruntled and don’t trust your employer than this policy falls flat.
- coder-3 5y agoEasy to game the system and offer credible bribes to yourself to collect the bonus. Just giving it some brief thought and it doesn't seem hard to make the chances of getting caught really low.
- zacmps 5y agoIf not for the threat of involving authorities I might agree with you. How many people would really risk up to 7 years imprisonment (my countries max) to make a bit of money?
- benbristow 5y agoA surprising amount of people, probably.
- reincarnate0x14 5y agoWith an incredibly low chance of being caught? Many people. Factor in that the initial ask is often something that seems relatively victimless, or at least, not hurtful to any specific person, and ethical flexibility is even easier to come by. Most people worldwide will take the moral equivalent of a bribe. It may require a sum so large as to be implausible for it to ever happen, but anybody that tells you they wouldn't at least consider illegal activities for life-altering amounts of money is statistically a liar. Millions of people have done and will continue to do it for seemingly trivial amounts of money.
- johncoltrane 5y ago> How many people would really risk up to 7 years imprisonment (my countries max) to make a bit of money? The prisons of your country are full of such people.
- raducu 5y agoThis sounds like trying to get rid of rats by paying for dead rats, someone will start farming rats. I see only trouble with this approach. Just hire good people, treat them right, have sensible audit and monitoring procedures.
- spacemanmatt 5y agoI have read more than one story of rat-catching incentives ultimately leading to discovery of rat farming.
- more_corn 5y agoYou used the “just” word there. Minimizing the difficulty of complex problems is a good way to discredit yourself.
- markus_zhang 5y agoHow do you tell competent employees from incompetent ones? By the number of certificates? By the number years in industry? By school? By leetcode score? By salary asked? It's very difficult.
- earth_walker 5y agoBy paying attention. edit: By which I mean 1) audit your processes and 2) get to know your people. Processes require good engineering to thrive; people require good management. When you confuse the two, you get problems.
- andrenotgiant 5y agoSounds like a recipe for a "Cobra Effect"[1] where suddenly, credible bribes grow by 10x! [1] https://en.wikipedia.org/wiki/Perverse_incentive https://en.wikipedia.org/wiki/Perverse_incentive
- legostormtroopr 5y agoIn the Cobra scenario, breeding a Cobra has no "cost" beyond the breeding of a Cobra. If you reported a fraudulent bribe, which was reported to the police there is a risk the briber and you both are arrested.
- spacemanmatt 5y ago
- belter 5y agoAnother misaligned incentive is to have a Bug Bounty program, but offer ridiculous low compensation, for highly critical findings that show complete compromise of your platform. That will make it clear you don't take security as a high priority, and the Bug Bounty was just to hit a compliance check list. Some will take it as a sign they should poke further your system, or shop around for others paying better.
- jsiepkes 5y ago> or shop around for others paying better. That's kind of a weird moral take on things. If you don't like the bounties offered then simply don't invest time in the platform looking for things to exploit.
- belter 5y agoThat was not a statement about my morals, was about the moral of others...
- xvector 5y agoCompanies with insulting bug bounty programs deserve to get hacked.
- hakre 5y agoThe Bug Bounty Program effectively protects them from that. You wouldn't know how insulting that is before going through a good of paperwork that legally tames your desires.
- krageon 5y agoOr you could foster a good personal relationship with your employees. If that's impossible for you, some will inevitably hate you enough that they will take the bribe anyway.
- pid-1 5y agoIf you have access to valuable assets of a company, you must be handsomely paid to avoid stuff like bribes. Industries ex software know that since time immemorial. Prob the software way of solving that is with least privileged access, automatic auditing and approvals. I wonder why not even security companies are doing that correctly though.
- thinkharderdev 5y agoFor insider attacks auditing is really critical. At some level there will always have to be human beings with superuser access. But if every admin access and action is logged, audited and tied to a specific person then it becomes very hard to abuse that access without getting caught.
- lupire 5y agoSuperusers can disable logging, but yea the risk can be reduced.
- lupire 5y agoSame reason why everything is shoddy: customers buy the cheapest or free solution and don't care if it fails. Why should a business care if it gets hacked? It's the users that suffer and they don't have an alternative.
- pimterry 5y agoYou can even go further: tell your employees that you'll be sending out fake test bribe offers, which they'll be expected to report, and that they'll be rewarded for doing so. Similar to how IT in many large companies nowadays runs internal phishing tests. That changes the risk/reward, so while every reported bribe is a nice cash bonus, accepting any received bribe becomes significantly riskier, and by 'practicing' bribe reporting it becomes the default reaction.
- deleted 5y ago[deleted]
- dhx 5y agoThe screenshots show the account of someone who has a LinkedIn profile identifying themselves as a Tier 2 Technical Services Engineer [1] working for an outsourced services provider in Costa Rica. They've been in the job for just over a year according to LinkedIn. This person states they provide troubleshooting assistance to Okta customers, and therefore may have needed elevated permissions over a number of Okta internal systems. This raises a number of architectural questions for Okta: - Can a support engineer for customers in one region access the systems/databases relied upon by customers in other regions? - Do employees get notified when their account is logged into or used (e-mail/SMS/otherwise)? - Do customers get notified when a support engineer accesses (with privileges) a system/database the customer relies upon? [1] https://work180.com/en-US/for-women/job/215617/tier-2-technical-support-engineer-remote-elig https://work180.com/en-US/for-women/job/215617/tier-2-techni...
- toyg 5y ago> Can a support engineer for customers in one region access the systems/databases relied upon by customers in other regions? My (admittedly outdated) experience is that this is always the case, regardless of any assurance vendors might have provided to the customer. In the end, people have to get stuff done, and offshore bodies are just too cheap to pass on. Things might have changed a bit since GDPR but, in practice, I expect there will always be "channels" for people to reach out cross-region.
- donalhunt 5y agoAlso "timezones". Just because a customer is based in Europe doesn't mean they don't need to get a hold of support at 03:00 local time. Even small, growing, startups now have HQs in one part of the world and staff across the globe due to the ease of movement many enjoy.
- draw_down 5y ago“Do they have access” is one thing, but what happens when they use the access? Is there any logging or proactive monitoring? A single support account reading say 10x the normal number of accounts per day, with a different geographic distribution than the norm, should ring alarm bells. It’s not enough to say “well shucks they have access to the data, guess we’ll do nothing”
- vinay_ys 5y agoPeople outsource auth to a specialised company (okta) and they outsource tier-1/2 support to a specialised company (because they are a multi-tenant B2B SaaS co.) If this were not a SaaS product, instead was a well-tested, audited and certified software package that was bought and run in-house by FTEs (and audited periodically), this additional complexity could have been avoided and this breach would have been much harder. As an industry I don't know if we have made rational choices along the way.
- emteycz 5y agoAs an industry, we have abundance of choice. You're not practically nor theoretically locked to SaaS vendors - there are equally good self-hosted open source auth solutions. A portion of our industry seems to be bad at risk calculation, but that's not inherent to the SaaS model - this app very well could've been made with strictly separated tenants.
- gnz11 5y agoRealistically though we are often locked into terrible software that no one wants because a SVP was wined and dined by the vendor.
- sofixa 5y agoFor most companies, hiring good quality FTEs is complicated, and very expensive. It makes sense, in many cases, to delegate some things to external vendors ( SaaS companies). There is a line to be drawn somewhere, and it will vary between companies and industries - e.g. a tech company could probably easily handle auth in-house, while i wouldn't expect a law firm or whatever to handle that ( and i wouldn't want them to).
- maxerickson 5y agoYeah, it's not surpising at all that someone managed to build a business selling auth for less than hundreds of thousands of dollars a year.
- 5y ago
- syngrog66 5y agowhen I'm reading any public chat speculating about how X was hacked, and I see the phrase "their Telegram group" I generally stop reading. lol (not a criticism of the comment above me, btw. not point I was making.)
- sackerhews 5y agoWhat point where you making?