‹ BackHN Continuity

Thread

CrowdSec Source Code Leak

160 points · 57 comments · eccgecko

  1. sandeepkd · · focus · HN ↗
    On the funny side, reading the website tagline, apparently they claim to know who is attacking you, they just happen to miss out on who attacked them.

    Turns out they are not really a security company, just an aggregator of bad IPs. Ideally this kind of aggregator problem is best suited for a trusted not-for-profit company where providing the data needs some level of credibility and querying the data costs you nominal fee to keep the setup floating.

    1. Meneth · · focus · HN ↗
      I suppose CrowdSec isn't used to analyze GitHub's traffic, so they wouldn't have much info to go on.

      If they had self-hosted their own repos, they might have had more luck.

      1. sandeepkd · · focus · HN ↗
        It wasn't the Github that was compromised, it was the access to their private repository that was compromised so somewhere down the line the security best practices are in question for sure. Self hosted repos available on public internet would have met the same fate, may be worse, given github does provides some level of security.

        Even regarding the blast radius, I do not really believe any company is honest about it. They do not have tools to verify it, if the user information was accessed with leaked token or real token. The thing that works in their favor is that no one else can verify it either which absolves them from any responsibility. Any platform engineer knows that your CICD system has the keys to the kingdom.

        1. strictnein · · focus · HN ↗
          The article you're commenting on says how they were compromised.

          > The thing that works in their favor is that no one else can verify it either which absolves them from any responsibility

          That's not how this works, at all. You need to have enough evidence that you can confidently demonstrate that there is no sign of a broader breach. If you get sued and can't do that, you're in trouble, because being unable to do that shows that you were acting negligently.

      2. nicce · · focus · HN ↗
        GitHub Enterprise has at least some level audit log
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.