HNHacker News
TopNewBestAskShowJobs

retrovm

270 karma · joined November 5, 2019

submissionscomments
retrovm··on Former Twitter Employees Charged with Spying for Saudi Arabia
Pretty much nobody at Google has that kind of access. You can be an SRE of just about anything at Google and never access user data. The "break-glass" means of emergency access is ridiculously booby-trapped. A person wanting to do this thing has to 1) badge into a special room, at which time both production security and privacy incident teams are notified, 2) use a special hardware security device that is used for no other purpose than to activate a VPN box with a hard-line into the production network. By the way if a random Googler just rolls up to a datacenter without a reason to be there, that also triggers privacy incident response, even though physical access to production storage is virtually useless due to all the encryption.

I would say it is much more likely that Google will accidentally lose the organizational ability to become root-in-prod, than it is that a person has done this thing without being noticed.

In short, insider risk cannot be mitigated with hiring practices. You need robust technical measures against insider risk.

retrovm··on Former Twitter Employees Charged with Spying for Saudi Arabia
That's exactly my point. In a company like Twitter there is some person or probably many people who are "the dba" and accessing a mysql directly or even using tools to access the underlying storage is an event of no discernible consequence. By contrast in a Google-style stack there is no person who is "the DBA", making it far easier to audit. A Gmail admin might need to unwrap the encryption keys that protect your attachments to, for example, diagnose a message-of-death that is crashing their backends, but that event would be so rare as to be easily audited, and it would tie a specific actor to a specific victim. Also I would say a custom auditing stack is way more resilient to things like just deleting the logs off the server, restarting the server without auditing, and whatnot.
retrovm··on Former Twitter Employees Charged with Spying for Saudi Arabia
It seems like there is an inverse relationship between sophistication and risk. If everything is full-custom then it may be quite easy to integrate auditing tools for who accessed user data. If an org uses mostly off-the-shelf software then it's pretty much impossible to audit e.g. who connected to what mysql server and ran which queries. So I'd be a lot more worried about a Twitter (fairly unsophisticated deployments of standard software stacks), moderately worried about Facebook (hacks upon the usual stack) and not very worried about Google (literally everything written in-house).
retrovm··on Intel publishes misleading benchmarks against AMD
If your threat model is "all the threats all the time" then I assume you also wear a helmet when walking down the street.
retrovm··on The Windows Update Marathon in a VM: From Windows 1.01 to XP
Is MS Virtual PC really this slow? On VMWare Workstation I can install Windows 3.11 in about 7 seconds, not the 6 minutes this author is showing.
← PreviousPage 2 of 2