Paige Thompson convicted over data theft from AWS user accounts
techmonitor.ai
techmonitor.ai
https://ejj.io/blog/fixing-capital-one
The linked Wyden letter makes for interesting reading too:
> "While it is likely that Amazon has known that its AWS product was vulnerable to SSRF attacks since the first high-profile demonstration by a security researcher in 2014, the company has certainly known since mid-2018 at the latest. In August of 2018, Amazon's security team was contacted by email by a cybersecurity expert, who recommended that Amazon adopt the same cybersecurity defense against SSRF already used by Google and Microsoft. A copy of that email is attached. Amazon failed to act on this third-party report and has not provided an explanation for its inaction."
Does anyone know if this is fixed by AWS now?
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configur...
> The breach has so far cost US bank Capital One, one of the 30 institutions affected, more than $270m in compensation and regulatory fines.
The bank claims that it is hacker's fault.
But isn't it wrong? Bank was fined and sued not for having been a victim of a hack but for not storing data securily, not configuring the cloud accounts properly. For not following required procedures. Therefore, as I understand, the bank should have been fined even if there were no breach.
Or are they blaming the hacker for exposing the violations? Do they assume that it is ok to violate regulations as long as nobody knowns about it? That's ridiculous.
The bank indeed was guilty of not properly securing customer data. The breach exposes this, and the bank was fined and sued accordingly.
Thompson is also guilty of wire fraud for the breach. You can't steal stuff just because it's easy.
It doesn't have to be one or the other. The bank was negligent, and Thompson is a fraudster.
> The bank claims that it is hacker's fault.
I don't see that claim in the article.
> Here is something that doesn't feel right.
I totally agree, it's a strong indicator of an oligarchy. Same as Chevron basically putting a lawyer in jail for suing them on behalf of the people's whose lands they poisoned. Threats to wealth are punished by our "justice" system more severely than similar crimes.
the insecure configuration is not tied to the hack, and was only exposed because of it.
the insecure configuration was there, independent of the hacking, yes, but it was unknown.
so, the hacker only made regulators aware of the problem, and that's what Capital One blames the hacker for. regulators would not have known if the hacker didn't take advantage of their insecure configuration, and now, regulators are fining them.
to you and me, the fault is on capital one for having the insecure configuration, and on the hacker for exploiting it.
to capital one, they did nothing wrong, and were only punished because of the actions of someone else.
To be clear, "they" is the feds. Wire fraud is a federal crime. The federal government brought this case against Thompson.
> Sketchy skit
> don't go to jail please
To which Thompson responded with:
> wa wa wa wa wa wa wa wawaaaaaaa
> I'm like > ipredator > tor > s3 on all this shit ..
> I wanna get it off my server thats why Im archiving all of it lol
> its all encrypted
But ... they posted it on their own GitHub and Twitter accounts ... With their full name in it ... and posted it on a semi-public Slack channel...
I'm not a security expect, but I think may be an op-sec flaw somewhere here...
[1]: https://www.justice.gov/usao-wdwa/page/file/1194001/download
Isn't there a third option, fully anonymous disclosure by a grey hat?
Seems like the best outcome would be from showing it to a scrupulous journalist who protects sources, and it looks like you're discounting that.
Any advice on how to safeguard against this?
If possible, use VPC endpoints and lock down the bucket to only allow access from them.
"Is it really the theft that cost the person the valuables stored at home, or the fact that they didn't have live armed guards or didn't store it in a vault? While the thief is obviously in the wrong here, you doubt it makes sense to pin the whole sum on him."
"Is it really the rapist that cost the person's life, or the fact that they weren't fully armed and were not at home after sunset? While the rapist/murderer is obviously in the wrong here, you doubt it makes sense to pin the whole sum on him."
These are not accidents like parking a car at the edge of a cliff and forgetting to put it in gear and set the parking brake.
These are deliberate premeditated actions by another party exploiting some weakness or error. Of course it helps to avoid weakness or errors, but the point of a civilized society is to not have to live like we're constantly under assault in an armed camp.
The criminal is a criminal, and the entire amount rests on his/her head.
That said, it is also appropriate for those who lost to analyze the losses and improve their situation. If there was already a spec or procedure to handle this, and it was not followed, then it would not be surprising to see some workers and managers retrained or sacked. But zero of this reduces the criminal's responsibility or liability.
I suppose that if there is anyone to blame for shortcomings incurring costs, it is the criminal herself. Aside from deciding to do the crime in the first place, she also had bad enough opsec to get caught, and that will come with a price.
>> These are not accidents like parking a car at the edge of a cliff and forgetting to put it in gear and set the parking brake.
They left S3 buckets parked on the edge of a cliff with (the personal information of) customers sitting in the passenger seat, and failed to stop them (from being publicly visible) with security.
Sounds exactly like your example.
Or to put it another way, if someone breaks into the bank and steals your valuables from your deposit box, are you going to blame the thief, the bank, or both?
My beef is with the comment that somehow the criminal is less responsible for the crime. It is not like they entrapped the person to do the crime.
If someone walks into the bank and the doors are wide open, no one is there, and the vault is just open, so they decide to grab some visible valuables, how much responsibility is actually on the thief?
I mean obviously there is some responsibility, but how much is more of a moral judgement than anything else.
Agree, it's all judgement, and there's clearly a broad spectrum. Some good example points on it might include:
* Implemented all possible security measures, above and beyond reasonable, but were breached by a nation-state actor.
* Took reasonable professional-standards measures, but were breached by professional thieves.
* Took most standard measures, missed some, but were breached by a modestly skilled thief.
* Were somewhat negligent and some people found an unlocked door and stole the goods.
* Created an attractive nuisance, too tempting for some people to avoid, and some people looted the place.
* Left the goods out on the sidewalk and were surprised when people helped themselves.
In all but the last sidewalk example, I'd say the taker has full responsibility as a thief - an honest person would not get involved, and a skeptical person would wonder if it was a honeytrap.
All but the last two examples require not only dishonesty, but also require specific planning and actions to get the goods. In all but the last two examples, I'd say that the taker is responsible for their acts, and nothing about the owner's actions mitigates that.
That said, the protector of the goods also has full responsibility for taking appropriate measures for the reasonably foreseeable threats.
I guess I'd put it as responsibility is not divided but added or multiplied by the parties.
It is laughable to hold those who make S3 buckets public accountable yet underplay the contribution of interface design. It's as if the NTSB had a report template with only a single checkbox for "pilot error".
Not so long ago this wasn't the case and various grey hat services would let you explore public buckets via a nice interface / API. What you could find was pretty shocking.
The idea of "don't use it if you don't know how" still applies though. In this world so many things can go wrong if you don't understand what button does what but that's not an excuse imho - AWS isn't designed for non technical people.
2) at a bank's scale it should not be using the console for anything in production.
You'll also have very little visibility in how to effectively test your configuration and ensure the security you _think_ you have is actually in place and functioning correctly.
CloudFormation (the AWS-provided IaC product) may have something, though.
https://news.ycombinator.com/item?id=31809259
(Deadline to opt-out is less than month away.)
While the metadata service isn't technically a vulnerability, it's poorly designed. Not enough thought went into its security, but too much relies on it for them to disable the current version overnight. Any changes are going to take many years.
This kind of thinking strikes me as exactly how Amazon gets away with this stuff.
Roughly here, you get:
6 base sentence level for 2B1.1 crimes
+20-28 victim loss(!)
+4 multiple victims
+2 sophisticated means or multiple jurisdictions
+2 trafficking in access devices (incl. account numbers)
+4 (maybe) jeopardizing the safety of a financial institution
+2 PII
+4 malware (the indictment more or less demands this one)
+2 obstruction or destruction of evidence
Assume no criminal history for the defendant, then, without replicating the whole table, level 10 is 6-12 months, level 20 is 3 years, level 30 is 7-9 years, and level 40 is 25-30 years.> +2 trafficking in access devices (incl. account numbers)
FWIW, the jury found her not guilty on these particular counts (9 and 10).
https://storage.courtlistener.com/recap/gov.uscourts.wawd.27...
Ultimately though I think it'll come down to how much money Capital One lost dealing with this and the aftermath (again, I assume less the fines and lawsuit).
I'm also probably (I hope) wrong about the 2b1.1 loss calculation here; I read the USSC primer on it and it's not super clear but leans me towards the idea that a penalty assessed on Capital One for doing a poor job securing their data can't be included in a loss assessment against Thompson, and I'm not clear that the damages for a settled lawsuit over same could apply either.
So total losses could be in the single-digit millions (as a general rule of thumb, you can't get convicted in federal court of hacking a real company and incur less than ~100k in damages, simply because of the cost of insurance-mandated forensics investigations --- here I don't really see any chance that the "actual damages" could have been less than 7 figures given the magnitude of what was stolen).
There is also, per the USSC document, a formula for computing damages "per access device", where "access device" is a term of art that includes account numbers, so that could also generate a nosebleed sentence.
For no reason whatsoever, just based on doing this exercise for every 18 USC 1030 case that's been in the news for the last decade or so, my wild-ass underinformed guess is that the sentence will end up under 10 years, but more than 5.
https://twitter.com/80snewsscreens/status/153451127149155532...
but with 'Forum Sentencing Expert'
AKA: Capital One left customer data in a publically available s3 bucket.
I'm not defending what this "hacker" did at all but this is 100% the company's fault. That $270M? That's from fines and settling a class action by their customers. Again, not defending the hacker but all the hacker really did was shine a light on this (doesn't appear they sold/used the data unless I'm missing something).
That’s not what happened, that’s uninformed forums speculation that you’ve seen repeated often enough you assume it’s true.
Krebs and one of Cloudflare’s PMs have both gone into some depth about this - it involved an SSRF attack against a non-public S3 bucket among other things. Krebs’ article is particularly interesting as it has screenshots of tweets from her describing the process.
https://ejj.io/blog/capital-one
https://krebsonsecurity.com/2019/07/capital-one-data-theft-i...
The hacker was very smart
The hacker chained together "about 6 or 7" different exploits to get to the data. Note, this means it is much harder than "leaving an S3 bucket public"
The hacker tried to sell the data, but couldn't find a buyer before being found out
VPN isn't cruise control to anonymity. Being based in a country without an extradition treaty to the US probably offers much better protection e.g. Russia, China.
The $ 270m is an estimate (on the low side) of the total cost to the bank, based on being fined $ 80m by the regulator and paying $ 190m to affected customers as settlement in a class action lawsuit.
https://krebsonsecurity.com/2019/08/what-we-can-learn-from-t...
She worked at AWS while stealing data stored on AWS S3. Even if those buckets were publicly open, common Joe did not knew it nor their names.
Why would you consider it irrelevant?
According to the article she only worked at AWS for a year and hadn't worked there for 4 years before executing this attack.
The only argument for relevance would be that she learned 'secret' knowledge about the internal workings of S3 that helped her execute the hack.
I don't think they're intentionally using the original meaning of the word "hack", as in "focused on outcome not methodology" but trying to paint this as some sort of evil mastermind who somehow defeated the security of (what I assume was) wide-open public S3 buckets?