20 votes

Slack Security Incident for Keybase CEO

10 comments

  1. vakieh
    Link
    As annoying as it is that yet another company has pants on head retarded security practices surrounding responsible disclosure, finishing up this post with a thinly veiled advertisement for a...

    As annoying as it is that yet another company has pants on head retarded security practices surrounding responsible disclosure, finishing up this post with a thinly veiled advertisement for a commercial product seems rather poor form and leaves me questioning the entire thing.

    22 votes
  2. [9]
    Wes
    Link
    That seems like an overreaction, even from a security-conscious person. Throwing away $5,000 worth of hardware (instead of... unplugging them) without any real evidence they'd been infected.

    In the subsequent days and weeks, I reset all of my passwords, threw away all my computers, bought new computers, factory-reset my phone...

    That seems like an overreaction, even from a security-conscious person. Throwing away $5,000 worth of hardware (instead of... unplugging them) without any real evidence they'd been infected.

    16 votes
    1. [4]
      9000
      Link Parent
      In his defense, his threat model, as the head of a well-known company that makes tools for people who need high levels of encryption, is very different from your threat model or mine. Like,...

      In his defense, his threat model, as the head of a well-known company that makes tools for people who need high levels of encryption, is very different from your threat model or mine. Like, targeted attacks by nation states are probably in-scope.

      23 votes
      1. [3]
        Deimos
        Link Parent
        I agree. It seems crazy at first blush, but they're a security company. They've taken over $10M in funding and have a significant number of employees and offices in four of the most expensive...

        I agree. It seems crazy at first blush, but they're a security company. They've taken over $10M in funding and have a significant number of employees and offices in four of the most expensive cities in the US (NYC, Seattle, Chicago, and SF).

        $5000 is nothing compared to the risk of the company's CEO being compromised. That has the potential to be a company-ending event, and it's absolutely not worth taking that chance (however unlikely it is) to save $5000.

        22 votes
        1. [2]
          rkcr
          Link Parent
          By that token, why spend $5k on a new computer but not any money on a new phone?

          By that token, why spend $5k on a new computer but not any money on a new phone?

          5 votes
          1. 9000
            Link Parent
            No, yeah, that's fair. Unless he has a very minimal set up on his phone (and maybe even then), I would likely have suggested a new phone if he's getting all new other hardware.

            No, yeah, that's fair. Unless he has a very minimal set up on his phone (and maybe even then), I would likely have suggested a new phone if he's getting all new other hardware.

            4 votes
    2. [4]
      rkcr
      Link Parent
      I'm confused why Max didn't just reformat his computer... unless someone spiked his hardware, that would fix any potential intrusion.

      I'm confused why Max didn't just reformat his computer... unless someone spiked his hardware, that would fix any potential intrusion.

      8 votes
      1. stu2b50
        Link Parent
        They could've have a rootkit, bios exploit, etc. Unlikely, but $5000 is nothing for him or his company, so why take the risk?

        They could've have a rootkit, bios exploit, etc. Unlikely, but $5000 is nothing for him or his company, so why take the risk?

        11 votes
      2. sqew
        Link Parent
        Based on his position as the CEO of a security/encryption company, his threat model is definitely different from most of ours, and someone having "spiked his hardware" (think nation-state level...

        Based on his position as the CEO of a security/encryption company, his threat model is definitely different from most of ours, and someone having "spiked his hardware" (think nation-state level stuff, like the Equation Group's hard drive firmware malware) is definitely not out of the question.

        5 votes