8 ms·
I don't work for Snowflake but I spend a lot of time working with them and their SE organisation. When working and building demos with clients, SEs create demo
by hangtime79 2y ago
I don't work for Snowflake but I spend a lot of time working with them and their SE organisation.
When working and building demos with clients, SEs create demonstration environments on the same $400 Snowflake demo accounts anyone can. To build demos the client would grant access to that SE. The SE would take some of the data to the demo environment and then work on it. This is further confirmed by the name of the environment Hudson Rock just published.
As far as I can tell, this is a process issue of clients not expiring an ID of someone who they were sharing data with and a threat actor swiping credentials. There is nothing novel about this as there is no exploit.
Also congrats Hudson Rock you just outed a person who was taken due to having malware on their computer. This is no different then if you gave a contractor credentials and they had those swiped. Dicks.
- waihtis 2y agoThe whole blog post reeks of extreme self-congratulation and youre right, a total scum move to expose the victim. Altogether very weak performance from Hudson Rock.
- deleted 2y ago[deleted]
- p0seidon 2y agoIt seems somehow like an Indiehacker page, probably taken too lightheartedly. Additionally, the related pages have no real contact details.
- ExoticPearTree 2y agoSnowflake’s customers are the victim, not Snowflake.
- waihtis 2y agoBy victim I referred to the Snowflake employee that had their credentials taken
- abadpoli 2y agoJust because there isn’t a “novel exploit” doesn’t mean this isn’t a big deal. Snowflake is susceptible to their SE’s having credentials stolen. These credentials can bypass MFA. And per the article, they have no expiry. That’s strikes one, two, and three. Snowflake’s security practices lead to a situation where their customers are either required, or at minimum encouraged, to share access to broad datasets with Snowflake employees. That’s strike four. Yes, there is also issue here that the customers are responsible themselves for not granting too broad access, and that’s on them. But it’s also on Snowflake for not having a better system that doesn’t require this access, or at minimum not having better oversight and control over this transitive access. Once these accounts are granted access to a customer’s data, they aren’t “demo accounts” anymore. They’re real accounts, with real, very valuable data, and they should be treated as such. Edit to add: it is worth noting that Snowflake claims the demo account did not have access to customer data and wasn’t the source of the leak, which is in contradiction with what the attackers claim.
- bawolff 2y agoIndeed, the less novel the exploit the more embarassing it is. Data stolen because of some crazy multi-exploit zero day chain. Well that is understandable, i don't blame the company. Data stolen because no 2FA support? In 2024 that is just embarassing.
- p0seidon 2y agoYes, that's also what I think must have happened—missing 2FA. But it seems it's also not mandatory within Snowflake accounts also, from what I understand from the general message. I've never used Snowflake and assumed that because you push all your data into it, it probably has 2FA enabled by default. Is it optional?
- Galanwe 2y agoI don't quite understand how Snowflake works. My understanding was that you had to grant storage access (e.g. S3) and compute access (e.g. EC2) from your account to Snowflake, which would then use said resources to perform queries that you issue from their hosted web UI. In that case it would mean stealing the Snowflake demo account of a SE should not expose your data unless you forgot to revoke their access to your underlying resources. Can someone explain if that is how it works?
- alias_neo 2y agoI just had a quick read through a couple more posts on HR, and a lot of them end with something along the lines of "heh, should have bought protection from us", reeks like a racket.
- clwg 2y agoThis is the description of one of Hudson Rock's main products, "Bayonet". "Imagine getting access to a lead-generation platform featuring hundreds of thousands of compromised companies around the world with active vulnerabilities that you can convert into customers." I've seen and dealt with a couple of these types of companies. It's a pretty sleazy tactic, and it's low skill/effort from a technical point of view as well.
- clwg 2y agoDoing some more digging, this is where the data is sourced "Hudson Rock acquires and purchases compromised data directly from top-tier threat actors operating in closed circle hacking groups. What sets our data apart is its quality in providing high accessibility to hacker groups looking for potential targets, and the speed in which we make it available to clients compared to other threat intelligence companies. Our operational knowhow, and our boots-on-the-ground approach to cybercrime originates from the IDF's 8200 Cybercrime division, and its efforts to thwart nation-state adversaries and professional threat actors." https://cavalier.hudsonrock.com/docs https://cavalier.hudsonrock.com/docs This would imply that they are financially engaging with and supporting cyber criminals.
- senderista 2y agoAbout as ethical as those other 8200 alums, NSO. The ethics of the IDF on full display.
- logrot 2y ago[flagged]
- catchnear4321 2y agoassuming seeing “dicks” upset you, and you think “cunts” would upset someone else, this seems less like equality and more like an attempt at hurting others due to hurt. or are you truly glad?
- logrot 2y agoI don't know who you think are "due to hurt" and doubt HN is the right place for that discussion. I'm certainly not interested.
- KingOfCoders 2y ago"I'm certainly not interested." You started it?
- catchnear4321 2y agoand yet, here we are. you used the word for attention. you got it. buyer’s remorse?
- Ylpertnodi 2y ago'Cunt' seems to really upset America. In the Uk, Aus, NZ etc it's as much offensive as any other term of endearment.
- catchnear4321 2y agooh it is just a word, some letters, some sounds. less about the item, more the claimed reason for use.
- jupp0r 2y agoAgreed, mentioning the login name of the compromised account seems really unprofessional and unnecessary.
- BlackjackCF 2y agoThis was a really effective anti-ad for Hudson Rock.
- p0seidon 2y agoGenerally, I like the page and the openness of the API behind it. It is much more common for people to talk about haveibeenpwned as a source for leaked credentials, but the site claims to have over 20 million computer entries from log stealers ... and every computer has XX password.. But yes probably this was written in a hurry to catch the wave?
- bredren 2y agoThe entry seems written by someone lacking maturity. The candor in the screencap'd chat conversation is novel, and will probably drive clicks. But in its unedited form serves as dirty laundry, and including the language from the threat actor is both unnecessary and inappropriate. I can't tell if the threat actor agreeing HR would have potentially helped avert this problem is a good endorsement or not. On one hand testimony from a threat of a product's effectiveness would be good, but on the other, this is a little up close and personal of an endorsement from someone actively ransoming so many companies and putting so much data at risk.
- wannacboatmovie 2y ago> But in its unedited form serves as dirty laundry, and including the language from the threat actor is both unnecessary and inappropriate. A threat actor has intent to hold a company ransom for $20 million and your first reaction is to feign offense that the word 'retarded' appeared in a chat log? These are not charm school graduates.
- p0seidon 2y ago