Disney's Internal Slack Breached? NullBulge Leaks 1.1 TiB of Data
hackread.com
hackread.com
A tape sitting in Iron mountain would have a smaller attack surface and be compliant.
Potentially this breach will allow litigation that was financially infeesable for some people.
As a former WDIG employee I am not even suggesting anything concrete or that I have any knowledge of unlawful activity.
But as someone who also worked in the electronic evidence discovery field, the cost of blind discovery has a chilling effect on lawsuits.
Now that targeted discovery is possible, it will be within the budgets of more potential cases.
The forever retention was a marketing differentiator for Slack, so this type of events were a risk you have to accept.
But all about convenience and not compliance.
Conversely, offline doesn't mean unhackable/unleakable.
Why use passwords at all under that line of thinking.
That is why we talk about reducing attack surfaces.
For example, the financial companies I used to work for had a “standard practice” of archiving all e-mails and internal chats for 7-8 years. Not sure if phone calls on company equipment were recorded or retained though (may be a YMMV case).
This is why I separate work and personal assets. I never do work on personal devices nor do I use work devices for personal activities (ie, social media, e-commerce, shit posting). Also if I’m shit talking the boss’s boss. It’s never using work devices.
Have been asked a few times to use personal devices for work but absolutely refused. I would be asked to install their invasive spyware and root kits so they can abide by their draconian corporate policies. So far, they haven’t forced me otherwise I would have quit those companies long ago.
Banks are (or were) required, in America, to use write-once offline media for records [1].
Do you move all old files, emails, internal knowledge articles, code repos, chat messages, etc etc to cold storage? You can’t search for anything you’re looking for in OneDrive, Outlook or Slack if the data is in cold storage so are you going to develop custom applications to support the same search filters as each original source application, but which searches your cold storage?
Once a user finds something in cold storage, you have to load it back into the SaaS app to display it. Why? A variation of the following applies to all enterprise data: A Slack message has tons of important metadata tied to it besides the text content. For example Slack user Id of the message sender, channel ID it was in, file ids of any file attachments in the message, and so on. How do you load that back into Slack from your cold storage?
You can put any data in cold storage. In the real world, that often makes the data almost useless for employees.
It's wild that some don't get this. A couple years back some employees at my company were fired for doing just this over the same IM system we used to coordinate everything else.
For a front office role - archiving of; emails, internal chats, external chats, phone calls / squawk lines, browser history, pc screenshot every X interval, same for work laptop at home. Office cctv, room microphones, mobile phone calls + text messages + device monitoring to ensure no other apps.
> I never do work on personal devices nor do I use work devices for personal activities
This is now the way.
The shining poster boy for this would be Google, who told staff to disable logging when discussing sensitive topics:
https://www.techspot.com/news/102874-doj-alleges-google-dest...
They also told employees to never use certain keywords, so that records of conversations would not be found by legal teams using search tools, but also they wouldn't be shown talking like monopolists:
https://arstechnica.com/tech-policy/2023/09/google-hid-evide...
Do any large companies not delete everything at the first opportunity?
I know a lot of these types of entertainment companies employ things like keyloggers or remote screen viewers in case an employee is working on a writing project or drawing/painting a picture during their lunch hour, because if they are, everything they make, write, sketch or even jot down belongs to disney exclusively... and if they, say, bring that script to prospective publishers outside the company a year later, or try to sell a print of the artwork they created, they can intervene and stop you.
if you take a shit in their staff bathrooms, that turd belongs to them too.
Yeah. That’s how we got Cars 4.
0. https://news.bloomberglaw.com/antitrust/google-chat-deletion...
It is discrimination and it's totally illegal. I do personally find the "wokeness" of Disney also shows in their cartoons (it's just an opinion but several have that same opinion).
So for such things to happen, there may be a company culture of wokism in place at Disney.
If there's such a company culture and seen the size of the leak, it's very possible that they've been so dumb as to openly discuss how to be anti-white (e.g. both in hiring practices and in picking fictional characters) on their slack channels.
To paraphrase a well-known meme: *"You never go full woke: Disney went full woke".
So much for "having empathy for someone outside my identity group".
Given that many such comments also amount to gaslighting, that's what bothers people about the whole idea. It was a good experiment, but it's time to end the policies and the attitude it brings. There are better things to argue over, this isn't one of them.
It's anti-White, Europhobic, misandry, etc.
Maybe go read the stuff and find this darning evidence instead of just running your mouth about Disney with a bunch of accusations?
(ComfyUI_LLMVISION is probably what caused this breach)
1) There are very few consequences. At worst, a hacker will get 5-7 years, and the chance of getting caught is low.
2) Security is very very very hard. The defender must get everything right. The attacker only needs to find one flaw.
3) Security does not just depend on security staff. It depends on every software engineer, operations (or devops) engineer, every software dependency, every piece of hardware, etc. If one of these people or dependencies has a problem, the whole system can be cracked. Examples of problems include writing insecure code, getting hacked, not removing old employees from an ACL or group, installing a tool with a back door, etc.
The point is security is hard and it depends on people doing the right thing. It's very hard to get people to do the right thing.
The opening salvo in the article is:
>> A self-proclaimed hacktivist group named NullBulge, aiming to “protect artists’ rights and ensure fair compensation for their work,” claims to have breached Disney and leaked 1.1 TiB (1.2 TB) of the company’s internal Slack infrastructure
Which seems more financial.
There's a constant fight of giving and removing access from an army of people. Additionally, there are often efforts to push these higher risk people into more confidential areas because the push to cut costs. Make one exception and then a "but this person has access" is sure to follow.
Maybe a dumping tool that uses a stolen api key? Rate limiting and monitoring on slack’s part could help…
Not sure why they would dox him, maybe to throw him under the bus after he found out he got pwned and cut them off?
Disney doesn’t just use one Slack instance across the whole company and everyone knows to not put pre-release content on my public platforms.
Maybe they compromised an instance owned by DTSS (Disneys centralized IT entity), but this would have little to do with Disney Studios like they imply.
Its pretty standard in the industry to only store pre-release content on airgapped systems.
> Its pretty standard in the industry to only store pre-release content on airgapped systems.
Unreleased narrative content isn't actually valuable, so nobody actually cares. I mean of course they say it's valuable. But there are aspects of value that are objective, and I am saying objectively, not in some aspirational sense, it's not valuable. And anyway, surely, how did such pre-release content get on such airgapped systems? They have tens of thousands of vendors, and those people talk, and they have ordinary desktop computers. They make mistakes all the time. It doesn't really matter.
Their business communications are valuable. So people hacked that.
I understand there is a lot of gestural, performative security measures in the industry, I belong to it. At the end of the day, Disney (Hollywood) asks too much from IT for too little money, does not attract talent comparable to a middle-of-the-road Series A startup in San Francisco, and is led by people who don't value technology (on average).
Source: I was an employee at the time and my only data leaked was HR data sent to the primary company.
LOL.
If you think that this should be the yard stick, you certainly think too highly of the tech industry, to the point of delusion.
SV VC startup land is the exception that proves the rule. It unfortunately gives everyone here a massively overinflated sense of worth.
“Everyone gets paid exactly what they’re worth”, “market forces”, blah blah blah. But the reality is that you just won’t find nearly as much easy, dumb money anywhere else. Hearing kids that’ve been spoiled by the SV startup scene whinge here about things that are completely typical of even the most cushy tech jobs jobs ANYWHERE ELSE is so telling.
https://www.electoralintegrityproject.com/eip-blog/2022/6/13...
https://www.pewresearch.org/short-reads/2016/10/31/u-s-elect...
https://citizen-network.org/library/global-ranking-of-electo...
It will be interesting to see what happens here. Information that leaks could actually impact share price.
I think at least some legal systems agree with my interpretation, but the U.S. is insane.
I did mention that I considered the U.S. interpretation insane, didn't I?
IANAL, but I think this description is overbroad. There is a "work for hire" doctrine in copyright law that assigns copyright to the employer, but I believe by default that only applies to works of authorship within the scope of an employee/contractor's assigned duties, with any broader scope needing to be explicitly assigned by contract. I would expect internal communications in general to be covered by an NDA or some concept of privacy rights, depending on the context.
Have you ever worked in entertainment?
I can’t guard the front door effectively.
Nor, I can easily guard the back doors.
Will data breaches like these: AT&T, Ticketmaster, and now Disney—-a nail in Security coffins for SaaS?
so all of those basics are going to magically happen when you move your data on-prem?
I don't know why but I find this funny.
70 million year old evolutionary technical debt rearing its head, yet again.
fingers arent innately binary, you can curl them and point them.
wrist orientation relative to the hand and at that point you can count up to 2048 without resorting to too much more than a set of two rules (past instinctual counting)
They never have the opportunity to question the sensibility of one or the other.
The argument is that the base10 interval makes no sense with computers, because they're physically base2.
You can't really have 10 without wasting 2, and that's why it made sense to use 1024 instead of 1000.
Personally I feel the pushback against gibi/mibi/kibi overblown. It's ultimately better to be coherent everywhere and always specify everything with decimals/rounded over random context dependent decisions. But still, the original argument for 1024 made sense too.
1 or 8, depending.
Unless you have some well known powers of 2 you have to calculate anyway.
To be able to convert easily from byte to gibibyte, mebibyte, gibibyte, etc. is a bigger benefit. Just moving the decimal sperator to convert the units is big advantage of the metric system.
Practically, physical objects need built. If you're not doing it yourself you've got to work within the limits of your suppliers or push them.
But if you are doing data storage, there are many natural power-of-two structures. Using 1024-based prefixes with them often leads to more convenient numbers.
But, if someone asks me for a good explanation why 1 KB != 1000 bytes, I don't have a good answer. I know about powers of 2, but why are powers of 2 more important than "kilo" meaning 1000 like it does in every other context?
It's like if a kilometer wasn't 1000 meters, because of the way car odometers worked, or the shape of the tires or something. Why would technical details about a car change the meaning of "kilometer"?
> why are powers of 2 more important than "kilo" meaning 1000 like it does in every other context?
Like a lot of arguments, we're arguing over the definition of a word here ("kilobyte"), nothing more. I'm asking why technical details about a computer are so important they can override the generally understood (and well defined) meaning of that word.
Because the technical details about a computer are important when describing its technical characteristics.
In short, context matters, and we adapt the meaning of words by the context they're used in all the time. It's ordinary.
In fact, it's so ordinary in this particular case, that all we humans did it for decades, before a weird group not representing the existing organic consensus came along and decided the terms absolutely must be changed, and presented us with extremely silly-sounding ones to replace the existing ones, that of course few adopted, leading to the situation we have today where the existing terms are used interchangably to mean both things, and there is now a greater ambiguity around them than existed before.
It wasn't perfect before, but the "solution" made it worse.
Therefore, it sucks in practice at meeting its goal, no matter how much sense it may make to the minority that thinks "gibibyte" is something anyone would ever want to say in public, other than in a funny voice to a dog or a baby.
And, whenever pressed for clarification, the oil people admitted "yes, technically our unit should be noted as 'oil barrels' which are different from the normal kind, but we like to just say 'barrels' because it's easier".
Reflexive answer: gold (well obviously gold is heavier than feathers)
Logical answer: neither (1 pound = 1 pound)
Actual trick answer: feathers (precious metals used troy weights instead of the one just about everything else used, and 1 pound in the troy system weighs less than 1 pound in the other one)
These numbers being a power of two seems pretty important, important enough that we redefine words to match powers of 2. Then, when we look at the exact number of bytes, it's not a power of 2.
But come on, are you really saying that 1100 0000000000 0000000000 0000000000 bytes of RAM isn't close enough to being a power of two to prove the same point?
Our starting point is that a kilobyte is 1000 bytes, but then people say "that's not close enough to 1024, which is a power of 2", and so we redefine the word "kilobyte" to mean 1024, etc. Then I buy a device with a gigabyte and it doesn't have 1,000,000,000 bytes, and it doesn't have exactly 1,073,741,824 (2^30) bytes either, it has some other random number.
So we started with Système International units and a common understanding of what they mean. Computer people said, "that's not close enough, let's redefine standardized words so they will be exact", and then they use those redefined words in an inexact way.
And for the sane normie people, a kilobyte is still 1000 bytes.
Cute.
But no, being a few percent off is very different from saying "it's not a pure factor of two, it's a very small number multiplied by a very large power of two".
Your GPU has an exact multiple of 2^30 bytes of memory.
If you want to talk about a USB drive, then to do that properly we need the size and count of chips inside a real model.
So clearly the right thing to do here to clear up any confusion is to introduce the concept of computer-sized bytes, and metric bytes. Metric bytes would be 0.9765625 of a regular computer byte, so 1000 MB would be 1000 Metric Bytes, or 1024 * 0.9765625 = 1024 Bytes.
Thus hard drives could be rated at 1,000 GMB, for 1,000 giga metric bytes, which would really be a 1 TMB drive or 1 tera metric bytes, which is the same as 1024 giga regular-computer-sized-bytes, or 1024 GRCSB.
Totally straightforwards and not confusing to anybody.
> GMB
Gigamegabytes, perfectly reasonable.
I think you meant 42 gallons.
The alternative, would have been to use something else than kilo, mega ect., that represented the base 2 magnitudes. It would be awkward to say you have 8.306.688 bytes of ram if you need to be exact.
"kibibyte" sounds like a dog treat not a unit of measurement.
The best I've seen is just to have the base as a subscript, like `kB_2` (2 is subscript) or `kB_10`. Though in practice I have yet to come across a situation where the difference a) matters and b) isn't clear from the context.
eg. Long Kilobytes, LKB or KKB
So perhaps a terabyte could be a "bin fourty", or a "two-to-fourty", etc. (Although as it linguistically relaxes into Tootafortie, it'll sound goofy too.)
You're saying that units-of-10 in English (and using Arabic numerals) will "not work" for other languages, when the international status-quo we're complaining about is already powers-of-1000 in Greek which are then mutated with Latin?
Why do you think there's a (new) problem?
Financial motivations
Nation-state sponsored/cyberwarfare
Corporate espionage
Hackivists
Resource theft
Gamer issues
Financial theft and nation-state attacks are easily the largest portion of cybercrime. Decades ago, the lone, solitary youth hacker powered by junk food was an adequate representation of the average hacker. They were interested in showing themselves and others that they could hack something or create interesting malware. Rarely did they do real harm.
Today, most hackers belong to professional groups, which are motivated by taking something of value, and often causing significant harm. The malware they use is designed to be covert as possible and to take as much of something of value as is possible before discovery.It appears that this is actually the case here, as it's supposedly about artist's rights.
"hacktivists"?
One question is whether there is one massive slack, or multiple different ones. I'd certainly hope that sensitive stuff is limited to a separate slack, for extra insulation.
They mention a name, and a google search shows that person works in Disney IT, so maybe their credentials were leaked and they had admin access to the slack. In that case, relying on slack permissions to limit the scope of a breach isn't really going to work.
apparently, the hackers don't really seem to consult the artists they're purportedly trying to help by doing this, because none of them want to see their work leaked like this. I think these hackers just selfishly want to see the materials behind cancelled shows they were looking forward to.
-publicly announce that you've breached X amount of data, and provide hashes of the files and tell the breached entity to confirm the hashes are accurate otherwise you'll publicly dump; -publicly prove you've accessed the files in a way that requires breach notification laws to be triggered -- so the company is forced to post embarrassing announcements but the actual risk to the underlying people in the dataset is reduced
what I don't understand is why you have to screw over all of the little people and individuals by just making everything public.
How do you know what their goals are?