TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Sega Europe suffers major security breach

185 pointsby aaronwpover 3 years ago

9 comments

ff7c11over 3 years ago
By temporarily defacing the Sega website and modifying files I think they have crossed the line. Enumerating what access they have, rooting through S3 and reporting it is OK, but by messing around like script kiddies they can no longer claim good faith. Publicising that you've illegally defaced the website is a little silly. Of course, Sega should not have got themselves so completely owned. Sega deserved to be punished, but these VPN twits have clearly committed a crime and Sega should maybe sue their company.
评论 #29740362 未加载
评论 #29741403 未加载
评论 #29740070 未加载
评论 #29739937 未加载
评论 #29740083 未加载
评论 #29745964 未加载
评论 #29740339 未加载
aaronwpover 3 years ago
Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums.<p>All the keys and services are secure and the breach is closed.
评论 #29739130 未加载
评论 #29740095 未加载
评论 #29739035 未加载
评论 #29740119 未加载
评论 #29739040 未加载
评论 #29739258 未加载
0xbadcafebeeover 3 years ago
A good example of how the <i>usability</i> of your product directly affects security.<p>AWS has multiple forms of credentials. IAM Users (static keys tied to a specific user identity) are one form. But you can also authenticate via SAML or OIDC. If you use SAML&#x2F;OIDC, you can enforce temporary IAM credentials, audit who authenticated, expire credentials, enforce password rules &amp; MFA, etc.<p>Because IAM Users are the <i>easiest thing</i> to set up, that&#x27;s what everyone does. And that leads to compromises. If, on the other hand, IAM Users were <i>more difficult</i> to set up than SAML&#x2F;OIDC, then everyone would use SAML&#x2F;OIDC and temporary credentials. And that would mean giant compromises like these would be much rarer, because it would eliminate the easiest form of compromise: people putting static, non-expiring keys where they shouldn&#x27;t be.<p>So when you develop a thing, think about the consequences of it, and design it so that users are more inclined to use it in a way that leads to good outcomes. That might even mean making parts of it intentionally hard to use.
评论 #29739888 未加载
rosndoover 3 years ago
It’s hilarious to see people generating content like this to push their VPN affiliate marketing schemes.
评论 #29740115 未加载
politelemonover 3 years ago
If I&#x27;m understanding correctly, a whole bunch of credentials, like IAMs, DB passwords, Steam keys, and MailChimp keys were lying around in S3 buckets.<p>But I don&#x27;t understand the use case, what would be the purpose of uploading those details into S3 buckets? Or I suppose I&#x27;m trying to reverse engineer the situation where the dev&#x2F;ops team decided to do this.
评论 #29740370 未加载
评论 #29740361 未加载
评论 #29740471 未加载
评论 #29741574 未加载
isbvhodnvemrwvnover 3 years ago
If you&#x27;re running on AWS, why would you even have long-lived credentials in your images?
评论 #29740226 未加载
batch12over 3 years ago
So the breach referenced was a breach by the researchers, not a malicious third party (that we know of)? I would have called it exposure or a vulnerability since breach has a specific meaning that I am not sure this fits. Maybe I am being pedantic.
评论 #29739847 未加载
ipaddrover 3 years ago
Another grow marketing hack successful. Double if their is a lawsuit.
swdev281634over 3 years ago
Was not the best idea to do that. Sega is very traditional Japanese company. Consequences are likely to follow, but not the legal ones.