Fintech App Switch Leaks Users’ Transactions and Personal IDs
vpnoverview.com
vpnoverview.com
>Grink updated their bucket security 22 days after we notified them of the breach.
Open S3 bucket, 22 day to fix is "as swiftly as possible"?
My hunch is it may have taken part of that time for them just to figure out how to secure the bucket properly, as well as keep their service functioning with the properly secured bucket.
I think many of these startups do just enough to get the service functional.
Bad choice.
I mean, they can prove on paper that they are secure. Who cares about reality any more.
I've grown a bit cynical as time goes on about this sort of stuff; not the need for the kinds of controls and checks behind SOC2, but cynical towards the lip service I continue to hear about it from the executives and leaders I find in many shops.
The "InfoSec/CyberSecurity/DevSecOps" director is often a glorified send button. "The SIEM said do this, send to Devops, the auditor said do this, send to Dvops, the vulnerability monitor noticed this, send to Devops, we were asked to provide evidence of this, send to Devops"...etc.
3 of the last 5 jobs I've been in since 2016 have had dedicated personnel with the words "Information Security" in their job titles, and all 3 of them were really good at sending me shit to do, talking about what they read in some infosec blog, and a CVE they read about.
But here's the thing, I think I have a really good reason for this cynicism and I don't know what how to resolve it:
I don't know how confident I would be if these individuals were actually expected to build and contribute to the security effort beyond "send to Devops", but maybe they're not supposed to? Are "DevSecOps" people expected to actually...be involved in engineering too? Or do they just sit at the periphery throwing vulnerability assessments and threat modeling work? I've honestly only ever had the latter.
Tried having this conversation with a friend who just finished an MSc in Cybersecurity and he seemed a bit offended by my inquiry, so I dropped it...but I am still insanely curious to know because I really doubt this experience is unique.
They only know to press some buttons and then send some reports.
I don't know of many developers, that in their day job, who pro- actively consider security. It's always "it's behind a firewall", or "it's for internal purposes", etc. Security practices need to be built in.
The best way I can think of to remedy this is to make university lecturers care as much about full stack security as say using goto or raw pointers or serverless or <insert flavour of the month>. I don't think a class on security would do it either.
A good way to fast track security practices in the universities would be to have actual hackathons that attempt to breach cs and it department computers... with extra points if you can make a clown of the head of the it dept or professor of security.
It'll take a few years, I admit, but things would eventually change. I can't see any other way, other than the general populace getting so sick of this stuff that legislation would be written to heavily penalise companies that are breached.
2c
I suggested this once actually at an org that made frequent use of Hackathons (as in we had one every quarter), basically an internal CTF challenge.
Executive paranoia took over and held strangled the life out of any good sense, nuance or reason, so of course in the end, we never did it.
Having been the only security guy in a large, and complex, engineering enterprise, it feels darned near impossible. Security is often just regarded as an added expense, until something happens.
It really does take buy-in from everyone, understanding security, being invested in security, and consistently accounting for security, for a program to be super effective. Otherwise security is left playing whack-a-mole, asking teams to fix all the things they constantly are finding out of compliance.
I should note, understanding the issues helps, as you can also tell them what findings are irrelevant in their specific context. For web app security for instance, many issues are browser-related, and may not matter for inter-system API calls.
Adages about being able to ISO 9001 certify a cement life jacket ^H^H^H SOC-2 certify an Open S3 bucket remain true, but there is a certain amount of deliberate intent required on both sides to complete the process. In other cases it can be used as an excuse to give security _some_, much needed reason for funding and effort.
Consider the people who cannot handle a SOC-2 audit. They exist, they walk among us and get funding.
Why did they store PII, Identity documents unencrypted?
What exactly was the reason for this breach?
Why did it take VPNOverview's team a day to notify them?
What did VPNOverview do with all that data until they notified Grink and afterwards?
Why did it take Grink 22 days to secure the files?
Why does the article describe the above as "as swiftly as possible"?
Can Grink be fined/sued over this, or is that only possible once there is 'actual damage' proven?
Because it’s easier to store and retrieve them unencrypted than encrypted
> Why did it take VPNOverview's team a day to notify them?
Sure, shoot the messenger. It does not say 24 hours. Maybe they discovered the breach at 10:00 PM local time and sent a notification at 6:00 AM the next morning.
That or we need to start fining heavily for breaches.
I don't know that the alternatives would be much better. People have inadvertently made folders on Apache wide open for decades now.
AWS does more than average to combat it, I'd say. E-mail notifications, default configs, scary warnings, etc.
People often aren’t starting with the AWS defaults, they are starting with an IaC (Cloud formation, CDK, Terraform) template they got from some other project.
There's also some configurations that require you to open access to the S3 bucket to get Cloudfront to point at it, because their Origin Access ID configuration doesn't work for all scenarios.
I know some of these things were sorted, but I don't have access to the old configurations to prompt me to remember what they are.
For static sites or other public access required files setting up cloudfront with an authenticated origin pull is pretty straightforward and in our case we use a terraform module to provision and secure the bucket/distribution. I think this come when you get dev/biz users with console access who are trying to "just get it done" when you are dealing with highly confidential or sensitive data, it's a recipe for leak.
But that would probably destroy the onboarding experience, how many tech firms release big products that should have authentication but really don't because of "ease of use"?
(Here's looking at you, ElasticSearch. Did they finally fix this?)
Like, what more can AWS do? Require a blood sacrifice? Call your boss?
So within the org I am part of it is actually absolutely clear what the basic security configuration is. But it is also such a hassle, that I at least (being a data analyst sometimes in need of a short one off project for testing) just don't use it anymore for anything ephemeral (living few days at most) without containing any real world data.
Securing the AWS instance would more often than not actually take nearly as much time as setting up a proof of concept project for a demo itself. More often than not that is only replicating an existing poc and changing a few images, fonts and a bit of text to make it look more like the client's pages/corporate identity.
Then a short demo in a meeting and after that a tear down. Worst case these demos are live for 3 days.
So security as well as compliance add 50 - 100% of effort in these cases. Making POCs on AWS just not worth the effort.
As much as I understand that anything more than a poc needs to be secured I would wish for a way of communicating that some things are just so temporary as to not warrant this overkill. But as this could be abused, there just isn't.
So tl;dr: Orga can ensure security and best practices in AWS if the invest to monitor and check automatically. But that does have other consequences as well.
[Edit] : typos
I shit you not. The other day, almost finished project was shown to our team to sign off on. It is only after some basic questions about the 'how exactly does it work' and some 'umms' from salesguy, we got a separate meeting with an actual tech guy, who started incorporating our requirements as a draft... and that was the end of the project. We actually have project manager after us for holding them back.
And this is not an unregulated Fintech.. I shudder to think what happens elsewhere.
I thought oxygen was going to get scarce enough for them to get triaged out of the queue a few years back, but that didnt pan out
I wonder if there should be some kind of channel to report this to AWS instead so they can temporarily shut off public access rather than wait for the service to get around to it. This doesn't seem too far fetched, since copyright holders are currently able to go after the hosting company for things like DMCA violations and PII seems more important than pirated movies whatnot.
(Obviously, this would likely break the outward facing part of the AWS customer's application, so there'd need to be verifications to prevent using the reports to DoS a service.)
And how many users just signed up to get the sign-up bonus and never used the app again?