4 ms·
Do they by any chance use a CDN for their cloud console? This has burned organizations so many times before where they cache the dynamic data and not static dat
by magicmicah85 3y ago
Do they by any chance use a CDN for their cloud console? This has burned organizations so many times before where they cache the dynamic data and not static data.
- twisteriffic 3y agoI wouldn't expect to be able to administer the resources if this was just a caching issue. Seeing them yes, administer them no. Unless their authx design is tragically bad.
- bink 3y ago"Full Access" could mean a lot of things. I don't see anything suggesting they could make changes (though I haven't read the entire thread). The user could just assume they have full access because they can see everything.
- fotta 3y agothere was a comment in one of the reddit threads that someone was able to create a vlan on someone else's network
- BHSPitMonkey 3y agoIt's hard to be certain while we're just speculation, but a view caching bug could make it _look_ like you're making changes to the other user's console even if they're actually going to your own console.
- EE84M3i 3y agoIt could also be caching something that contains a token that can perform other actions. The disparate reports of different pages and being able to navigate make it sound like this is at some API level, not literally caching the console page view.
- twisteriffic 3y agoThis is my line of thinking. It's bonkers if that's the case - sign of a completely broken mindset towards auth.
- kevincox 3y agoIf your login/access token request is cached this could happen. But that may qualify as "tragically bad".
- pixl97 3y agoYep, this would be my guess. Something like "UserID" gets cached per node and suddenly you're seeing the wrong persons data.
- larvaetron 3y agoThat was my first thought, it sounds similar to what happened with Klarna[1] a few years ago. [1] https://news.ycombinator.com/item?id=27301219 https://news.ycombinator.com/item?id=27301219