U.S. Internet leaked years of internal, customer emails
krebsonsecurity.com
krebsonsecurity.com
Never had any takers.
Something that could work is including a random hash as a first hidden email inside of every client, and then regularly searching outbound traffic for that hash. But that would be rather expensive.
Not within the resources of all orgs of course, but there is a lot of low hanging fruit through code alone that improves outcomes. Effective web security, data security, and data privacy are not trivial.
You keep your business logic and account handling code on github?
Not an accusation, genuinely asking.
Even if they never got around to automating it and were highly laissez-faire, manually checking that account with those testcases say once a month would have caught this within 30 days. That still sucks but it's at least an order of magnitude less suck than the situation they're in now.
1) Are there any unexpected internet-facing services?
* Once per week (or per month, if there are thousands of internet-facing resources) use masscan or similar to quickly check for any open TCP ports on all internet-facing IPs/DNS names currently in use by the company. * Check the list of open ports against a very short global allowlist of port numbers. In 2024, that list is probably just 80 and 443. * Check each host/port combination against a per-host allowlist of more specific ports. e.g. the mail servers might allow 25, 465, 587, and 993. * If a host/port combination doesn't match either allowlist, alert a human.
Edit: one could probably also implement this as a check when infrastructure is deployed, e.g. "if this container image/pod definition/whatever is internet-facing, check the list of forwarded ports against the allowlists". I've been out of the infrastructure world for too long to give a solid recommendation there, though.
2) Every time an internet-facing resource is created or updated (e.g. a NAT or load-balancer entry from public IP to private IP is changed, a Route 53 entry is added or altered, etc.), automatically run an automated vulnerability scan using a tool that supports customizing the checks. Make sure the list of checks is curated to pre-filter any noise ("you have a robots.txt file!"). Alert a human if any of the checks come up positive.
OpenVAS, etc. should easily flag "directory listing enabled", which is almost never something you'd find intentionally set up on a server unless your organization is a super old-school Unix/Linux software developer/vendor.
Any decent commercial tool (and probably OpenVAS as well) should also have easily flagged content that disclosed email addresses, in this case.
3) Pay for a Shodan account. Set up a recurring job to check every week/month/whatever for your organization name, any public netblocks, etc. Generate a report of anything that was found during the current check that wasn't found during the previous check, and have a human review it. This one would take some more work, because there would need to be a mechanism for the human(s) to add filtering rules to weed out the inevitable false positives.
All you really care about is meeting whatever criteria the tender offer requires, any further work is wasted effort.
Incidentally, this is also why most government projects really suck on the UI front. There's no way to specify "have a good user experience" as an objective tender offer criterion, so this is not done. In tender proceedings, the lowest bidder meeting all the criteria always wins, so companies that care about actually doing good work quickly get outcompeted by companies that do the absolute minimum required.
https://docs.google.com/spreadsheets/d/1wgKe1VrfNF8Afav1aJtM...
One caveat: This list should not be considered exhaustive or complete by any means. e.g. changing the URL slightly by incrementing or decrementing a number in the URL caused a slightly different set of customers to be listed. I didn’t have a chance to go through it all before they took it down (note to self: pillage BEFORE burning).
Even if this were true, that is a pathetic response.
https://usinternet.com/privacy-policy/
https://en.wikipedia.org/wiki/EU–US_Privacy_Shield#Swiss–US_...
They do it to limit liability, but perhaps that should be the law for every business: As part of the responsibility as a custodian of other people's information, you need to minimize retention: Remove PII and other high-risk information asap, extract data needed for the long-term (rather than retaining the entire original record), delete the entire record when it's no longer used (easily determined by how often it's used).
In the networked, electronic era, data becomes much more powerful and control of it becomes much more elusive. That increases our responsibility.
Think of the clicks man!
Something deleted years ago can't be accidentally leaked or used against you unless someone thought to do so within the 30 day window. That's literally why the '30 day purge' exists to 'limit liability'.
that's specifically aimed at catching the stupid criminals that say things like "please shred all of the incriminating documents before we have to turn them over in discovery". or the emails that gets interrupted in a suspect thread that says "please call me" so that it's specifically not written.
we're sort of talking past each other
I’m talking about telling companies to do silly things so we all get more lulz.
Yes, we are talking past each other.
So there's less junk to sort through when things like this happen. Only the valuable stuff gets saved.
we'd get emails at the end of quarter that all of our testing instance VMs, emails, and other stuff was getting squashed at the end of the quarter, so save & archive.
in hindsight kinda liked the 30 days, it required that we kept meeting notes and other discussion in one place -- no email chains that went back to early last year. it's either in the wiki or it's not, and if it's not then it didn't happen, and we need to discuss.
And this is the entity, the gateway, that leaked all the emails.
In my opinion it is a huge epic fail when you pay a service to secure your emails that leaks them...
[edit: it reminds of I think McDonalds being told off in NZ for using "All Beef" branded hamburger patties or something in the 90s or something?]