7 ms·
Binance CEO confirmed this version: https://twitter.com/cz_binance/status/1543905416748359680 https://twitter.com/cz_binance/status/1543905416748359680
by haasted 4y ago
Binance CEO confirmed this version: https://twitter.com/cz_binance/status/1543905416748359680 https://twitter.com/cz_binance/status/1543905416748359680
- throwaway787544 4y agoStarting today, this will be known as "Shanghai'd credentials" and be reason #1 why we use ephemeral credentials (e.g. AWS STS/SSO) rather than static credentials (e.g. IAM Users)
- throwaway2037 4y agoI never heard about "ephemeral credentials" before your post. I have some Googling to do!
- krageon 4y agoIt's essentially an access token with a very short expiry time.
- toomuchtodo 4y agoThe other term of art is “dynamic secrets.” https://www.vaultproject.io/use-cases/dynamic-secrets https://www.vaultproject.io/use-cases/dynamic-secrets
- 0des 4y agoGood lookin out, thanks for the link
- compumike 4y agoDoesn't the client still need to know a long-lived secret (or a long-lived refresh token) in order to generate the ephemeral credentials?
- toomuchtodo 4y agoIt can either use a secret injected into an env var to bootstrap rotating ephemeral/refresh tokens or use a role provided by the environment (which can also provide short lived tokens), depending on your runtime environment and use case (on prem, cloud, k8s, etc). Static, long lived secrets with limited governance that have no conditional access guards are weapons of mass self destruction.
- robonerd 4y agoKeeping secrets in environmental variables has always seemed dodgy to me. Unless specifically cleared, they get inherited by all child processes. Maybe there are never any child processes in your application, or that could be desired behavior in some circumstances, but generally it seems like asking for trouble.
- toomuchtodo 4y agoIts safety is proportional to your isolation model. Never use env vars for secrets when you’re executing arbitrary code, for example.
- RajT88 4y agoThere's also the reverse issue - if they change after your process is started. Refreshing an environment variable that has changed is (for me) a line I won't cross. Time to write the app a different way, once that becomes a concern.
- steelaz 4y agoWe got rid of all IAM users used by applications and moved to role-based access. Nowhere in the application do you need to enter AWS credentials. AWS SDK will attempt to discover short-lived credentials for you and will assume the role specified at the infrastructure layer, e.g. in a task definition.
- LilBytes 4y ago
- stefan_ 4y agoThis is not at all the takeaway from this. It's "this shitty developer should not have had access to this data in the first place". With a nuance of "this database probably shouldn't exist in this form in one place to begin with".
- babelfish 4y agoLet's not. After the whole "China Virus" shit propagated by the right, I'd prefer if we tried not to associate vulnerabilities with specific people.
- bequanna 4y ago
- xfitm3 4y agoI don't believe this comment is made in good faith, there is nothing wrong with the "right" and it's senselessly adding fuel to our political division.
- malcolmgreaves 4y agoThere is something deeply wrong with the authoritarian politics of the right and its casual use of racism to further political control. > it's senselessly adding fuel to our political division. This comment, whether you realize it or not, is coming from a place of extreme social privilege. Remember that for the majority of people, politics is not a game. It is serious. People lose their rights to live the life they want all the time. Sometimes those politics turn violent and people lose everything.
- markdown 4y agoIt's not a new word. https://dictionary.cambridge.org/dictionary/english/shanghaied https://dictionary.cambridge.org/dictionary/english/shanghai... https://www.urbandictionary.com/define.php?term=Shanghaied https://www.urbandictionary.com/define.php?term=Shanghaied
- malcolmgreaves 4y agoThat's not an argument for continuing to use a word.
- markdown 4y ago
- brianpan 4y agoSpeaking as an Asian American, no, let's not do that.
- throwaway787544 4y agoOk; could you suggest an alternate? Would be handy to have a shorthand to refer to the incident
- shirleyquirk 4y agonot their job. How about you come up with something catchy?
- brianpan 4y agoHow you come up with a name is up to you and how you use it. Personally I would go with "July 2022 Shanghai National Police database leak" because I'm not having any conversation where a cute codename would be less confusing. At work we codename security issues we are working on for Slack channels, etc. We use unrelated names that you could get from a name generator.
- xwolfi 4y agoWhy ?
- snovv_crash 4y agoShanghai'd is already a phrase that means something else, anyways.
- 72736379 4y agoThis is less a confirmation but more of a "piggybacking".
- manuel4sk 4y agoI don't know this guy, but how can he confirm this? does he possess any inner information? why I got the feeling that he is so eager to put a conclusion on this when it is still open for debate at this stage.
- haasted 4y agoBinance is the largest cryptocurrency trading platform globally. According to this tweet [0] they have a "threat intelligence" department that continually monitors for potential issues. It makes sense that they would be on the lookout for leaks of this nature, as they are highly dependent on correctly verifying and identifying their customers. [0] https://twitter.com/cz_binance/status/1543700689611792386 https://twitter.com/cz_binance/status/1543700689611792386