6 ms·
Writeups and actions like this from cloudflare are exactly why I trust them with my data and my business. Yes, they aren’t perfect. They do some things that I
by BytesAndGears 3y ago
Writeups and actions like this from cloudflare are exactly why I trust them with my data and my business.
Yes, they aren’t perfect. They do some things that I disagree with.
But overall they prove themselves worthy of my trust, specifically because of the engineering mindset that the company shares, and how serious they take things like this.
Thank you for the blog post!
- el-dude-arino 3y ago[flagged]
- _heimdall 3y agoWhat are they now, if not an engineering company?
- el-dude-arino 3y ago[flagged]
- dang 3y agoTheir CTO restores vintage laptops, still runs a Minitel, tests prime numbers for fun, programmed a KIM-1 with a hex keypad as a kid, and fixes hard drives with woodworking tools: Restoration of an IBM Thinkpad 701C Butterfly-keyboard laptop - https://news.ycombinator.com/item?id=39128387 https://news.ycombinator.com/item?id=39128387 - Jan 2024 (42 comments) Using my Minitel 1B over the phone network in 2023 - https://news.ycombinator.com/item?id=38291493 https://news.ycombinator.com/item?id=38291493 - Nov 2023 (0 comments) My primality testing code is faster than Sir Roger Penrose's - https://news.ycombinator.com/item?id=38274642 https://news.ycombinator.com/item?id=38274642 - Nov 2023 (25 comments) My 1976 KIM-1 - https://news.ycombinator.com/item?id=38161617 https://news.ycombinator.com/item?id=38161617 - Nov 2023 (31 comments) Retrieving 1TB of data from a faulty drive with the help of woodworking tools - https://news.ycombinator.com/item?id=37160783 https://news.ycombinator.com/item?id=37160783 - Aug 2023 (186 comments) ... and that's just a recent random sample! There's a reason why his site has been posted to Hacker News over 600 times. I don't know if you could pick a worse example.
- _heimdall 3y ago> a vessel of shareholder value, nothing more. This is my general opinion of publicly traded companies, i.e. the primary product is their stock, but I personally haven't seen anything out of the ordinary with Cloudflare compared to other big tech companies. I wouldn't say they aren't engineering companies though. There's plenty of engineering that goes on there, its just no longer the top priority once the company has gone public (same to some extent with VC investors).
- Xeyz0r 3y agoNobody is perfect, but Cloudflare indeed inspires confidence. Especially thanks to cases where they don't hesitate to talk about the issue and how they resolved it. It's precisely these descriptions of such situations that demonstrate their ability to overcome any challenges.
- overstay8930 3y agoWe're one of their larger enterprise customers and stuff like this makes it easy to get renewals approved easily, keeping engineers in the loop makes it such an easy sell.
- nimbius 3y agoThen, the advertisement worked. - Insist that you have better integrity than your competitors - share a few operational investigations after your latest security event what cloudflare doesnt do is provide their SOC risk analysis as a PCI/DSS payment card processor. Cloudflare doesnt explain why they ignored/failed to identify the elevated accounts or how those accounts became compromised to begin with. They just explain remediation without accountability. They mention a third-party audit was conducted, but thats not because they care about you. Its because PCI/DSS mandates when an organization of any level experiences a data breach or cyber-attack that compromises payment card information, it needs to pass a yearly on-premise audit to ensure PCI compliance. if they didnt, major credit houses would stop processing their payments.
- eastdakota 3y agoI was the one who made the call to bring in CrowdStrike. It had zero to do with PCI/DSS or any other compliance obligation. It was to 1) bring in a team with deep experience with a broad set of breaches; and 2) to make sure our team didn’t miss anything. The CrowdStrike team were first class and it was good to confirm they didn’t find anything significant our team hadn’t already. And, for the sake of clarity, no system breached touched customer credit card or traffic information.
- deleted 3y ago[deleted]
- elitistphoenix 3y agoWas the self hosted environment running a AV like the Crowdstrike agent? Or was it running different AV and that's why you chose to use Crowdstrike as someone different? I guess no need to specific names. I'm just using that as examples.
- tptacek 3y agoWhat's an AV going to do about the fact that Okta got popped?
- encom 3y agoBetter hope you stay on their good side, and don't say anything their CEO doesn't approve of.
- zelon88 3y agoYou actually believe that an intruder gained access to their KB/Tickets and didn't manage to get valuable information? That's not what Jira is for. If you know what Jira is for, and you're willing to run it on-prem, then you know the purpose of doing all that work is because you have something valuable to store in there. I don't believe they didn't lose anything. That's not how this works, and most Jira/Confluence I've seen is loaded with secrets.