The Critical Security Flaws that Resulted in Last Friday's Hack
blog.cloudflare.com
blog.cloudflare.com
I'm surprised that Google doesn't detect two people fighting for control of one account. They could have easily detected ping-pong sessions and and locked both parties out of their accounts for a couple of hours. Or they could have penalized the newly added recovery address by forcing an exponential delay between resets using that address. This is not the first time I've heard of somebody breaking into a Gmail account while the account owner is using that very same account.
Edit: semi-tongue-in-cheek per comments below; as a CloudFlare customer I went to the blog when this first came up expecting to see something but bounced when the first post was a discussion of SSL BEAST since that was the hotness back in the fall of 2011.
I do believe it was not planned, but I also feel that vulnerability disclosures should be pinned for a while somehow if possible. I think one way this is done is having a separation between 'new feature' blog and 'ops' blog.
I think being among the top stories on Hacker News will take care of people seeing it. And, for the record, I voted the breach story up.
And now I will shamelessly take this moment to request a few features related to account security :-).
* Alerting: SMS or e-mail notification when an unrecognized device logs into my account or when records in my domains change.
* 2-factor Authentication: Prompt for a code delivered via SMS, e-mail, Google Authenticator, or DUO Security to login from an unrecognized device.
* Login Accounting: Let me see what IPs logged into my account, when, geoip info for each, and preferably what actions they took while logged in. Provide an API for this info so I can write an automated script to analyze it for suspicious events.
If you end up making any of these features, it would be cool to open-source a library you used to do it. There are a bunch of large SaaS providers out there that use features like these but they're all homegrown implementations afaik.
Btw, the Google Apps Admin Audit API exists but I have never seen anyone do anything with it and it makes me sad. A few hours with [name a scripting language] and you could probably have a pretty robust Google Apps monitoring system, but no one seems to care: https://developers.google.com/google-apps/admin-audit/get_st...
There are lessons to be learned from both incidents.
And it's probably safe to assume that once you control the admin email account for a site, it's game over. You could request resets from other providers
Just found out: Uplink is on Steam, and in the Ubuntu Software Center now.
What customer was the target?
Update: Done.
Also, nice job, kevin.
Capitan Crunch called...
It also sounds like he didn't have 2 factor setup on his personal gmail account. I wonder if that would of helped.
Just kidding, this is a great level of detail and much appreciated, to understand CloudFlare's process and how to protect against or recognize these tactics elsewhere.
Domain Name: UGNAZI.COM
Registrar: ENOM, INC.
Whois Server: whois.enom.com
Referral URL: http://www.enom.com
Name Server: LEE.NS.CLOUDFLARE.COM
Name Server: RUTH.NS.CLOUDFLARE.COM
Status: clientTransferProhibited
Updated Date: 29-may-2012
Creation Date: 22-jan-2012
Expiration Date: 22-jan-2013And now I know about the Google Authenticator app. Fancy little thing, that; glad to find out about it.
But yeah... I don't like the idea of using Gmail for this either.
Goes to show, it's always who you know (or it's bullshit, which is less likely). Or I don't have enough users.