4 ms·
I feel like a step is missing. How does one go from having access to Slack channels to exfiltrating scads of sensitive data? Did they impersonate the software
by Full_Clark 2y ago
I feel like a step is missing. How does one go from having access to Slack channels to exfiltrating scads of sensitive data?
Did they impersonate the software development manager in order to steal credentials? Did Disney integrate their sensitive data storage with Slack?
- aulin 2y agoGiven Slack is mentioned I'd guess credentials to some remote machine were regularly posted in a channel as a means to notify about periodic password changes.
- justsomehnguy 2y agoNow talking in #ds_it_helpdesk RoyD: hi guys this is roy. i have trouble with logging on says my password is wrong. i double checked it multiple times but it doest let me in. can you reset it to Mickey123? MarkP: hi. reset it for you, check now? RoyD: works now thanks This is a work of fiction. Names, characters, places and incidents either are products of the author's imagination or are used fictitiously. Any resemblance to actual events or locales or persons, living or dead, is entirely coincidental.
- hgyjnbdet 2y agoIf it was real RoyD would have asked for it to be reset to Mickey1928. Anything else and MarkP would have known it was a scam.
- ricktdotorg 2y agoDisney is almost certainly using SSO for their Slack auth. there's a high chance the Disney staffer was signed into a browser profile with active cookies for Disney ('s auth provider). assuming the game mod gave them filesystem access, they've got the cookies and can use them elsewhere. job done.
- exikyut 2y agoOh yikes. So the industry has basically just gone and reinvented the very premise Google built BeyondCorp to mitigate, starting back in 2009. IIUC the baseline premise was to move away from "login to the VPN and you're inside the corporate network and you can access everything". It was incredibly convenient but a logistical nightmare in practice. The BeyondCorp approach was to integrate authentication into each product so that the access control could be managed on a case by case basis. Google standardised on OAuth across the board, and had a centralised login protocol/API with a WAF etc, but each product called out to this, and policy was decided by the calling application. This approach shines through to the whole Login with Google ideology. Thinking about it, I wonder how much corporate/enterprise/even SOHO OAuth is effectively the inverse of this approach - login to eg Auth0 once and you immediately have access to all your apps. That approach isn't technically broken, but it feels a bit like there's an antipattern here in the encouragement of centralised policy management. That just encourages everyone to think about "login once!" just like the old VPNs. And it's just hilarious how everyone's just... wandered in this direction. First VPNs, then "centralised access bad", then BeyondCorp, then OAuth, then "login once!", and back to the beginning. At least the web gives you the tools to setup siloed authentication per app. VPNs don't provide that level of slicing and dicing. So it's easier to fix, and merely a (complex) security design problem now.
- zoover2020 2y agoAmazon is no different, needs a $bigCorp in your story there
- exikyut 2y agoIs Amazon on the "built a BeyondCorp clone" side, or the "Auth0 is the new VPN!" side?
- 12345ieee 2y ago> a logistical nightmare in practice Could you elaborate? I'd like to learn from the errors of the past
- _pdp_ 2y agoPretty much every company I've worked for had credentials and other sensitive information easily discoverable on Slack, making it a massive headache to clean up.
- m463 2y agoSlack has all kinds of integrations built-in. For example, paste a google docs link into slack, and you can preview and download the doc right there. There are all kinds of file sharing and app tie-ins.
- doctorpangloss 2y agoThe user probably had permissions to add Slack apps, which can then read anything.