About the March 8 and 9, 2021 Verkada camera hack
blog.cloudflare.com
blog.cloudflare.com
Cloudflare's post doesn't mention it, but the Twitter account that claimed credit for the hack (and made all kinds of ridiculous boasts like "we could have owned half the internet") has been suspended.[1] Before that the owner of the account posted plenty of personal information, including selfies.[2] A Mastodon instance is where they're posting stuff now.[3]
It really seems like this person is mentally ill and it's only a matter of time before they get in trouble with law enforcement. I mean, it's standard opsec to avoid posting your mailing address on your l33t h4x0r account.[4] I realize the address is a PO box, but this is practically begging the authorities to intervene.
1. https://twitter.com/nyancrimew
I suppose any attention getting action can also be a cry for help. It is of note of a pattern emerges in conjunction with hacks of political intent / hacktivism.
It could be from a rival hacker, an innocent doxxed third party, or just completely fabricated to send investigators down a rabbit hole.
Sharing potentially personal details at this point is irresponsible and just leads to witch hunts.
The same person who leaked 20GB of Intel data? https://securityboulevard.com/2020/08/intel-leak-20gb-of-sec...
He isn't even trying to hide and does everything in the open. Like this IG https://instagram.com/deletescape
He lives in Switzerland. Does Switzerland not care about shady internet things like this?
https://www.bloomberg.com/news/articles/2021-03-12/swiss-pol...
I appreciate that they have a zero trust model, but arguably, once you have access to the network, you are one step closer to using any zero-day to get further inside.
It's good on CloudFlare that they had security beyond that which protected their customers, but it is still very bad for Verkada and CloudFlare needs to decide if they are okay continuing with a camera setup that can provide easy access to hackers to their corporate network or not, and that wasn't touched upon in the article unfortunately.
There can still be an inside and outside, but the inside doesn't get special privileges just because they are inside.
So it's not like each employee connects directly to the public internet and all emails, files, attachments, wikis are all exposed to the public internet and exchanged over the public internet between employees. It's likely all these are still internal to the corporate network and not accessible from the public internet. But if you are inside the network, you don't default to having access to it all either, there is an additional access control in place no matter if it is inside or not.
Now depending how confident you are on your access control layer, I have seen some companies literally expose things to the public internet and allow employees to access it without a VPN from any computer or mobile phone connected to the public internet from anywhere. I guess you can consider that on the extreme end of zero trust.
But also the question here is does CloudFlare not consider inside camera feeds (which if employees go back to office could let you look at their screens) data that should itself be secured behind their zero trust access controls?
Regarding their zero-trust approach to networking I'm wondering what they're using to secure non-HTTP services. I know they have a product that forwards TCP traffic but I don't think you could use that for arbitrary traffic between endpoints?
https://developers.cloudflare.com/cloudflare-one/application...
While Verkada may have not been the best choice, I fail to understand why remote-accessible cameras are bad? In fact, I'd say they are crucial at the level of security & monitoring needed by a company like Cloudflare.
Because that access is not as limited as it sounds, that's why.
Not having remote accessible cameras would seemingly make using the cameras take longer or be less efficient. In turn, that might make detecting or tracking physical intrusions less efficient and/or less successful. Should Cloudflare take that trade off? I think it depends on their threat model.
It’s okay to name the products and why they are used but the posts lacks some subtlety.
Reminds me of podcasts where the guest gets into talking about their product / company way too early instead of focusing discussion on the problem space in general.
You don't get to say you robbed a bank because you were able to walk into the lobby after hours.
This was absolutely a breach of a device on their corporate network and should be treated as such. Just because the network wasn't interesting, doesn't mean the breach didn't happen.
I have sympathy for their IR team because this would just be a random Tuesday had it not made it to the press.
Maybe before selling us on the product, try Verkada? They seem to have a need.
The cameras trusted the Verkada password that Verkada gave to a couple of random teenagers on the internet.