TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Data Breach Exposes Thousands of Job Seekers Citing Top Secret Government Work

94 点作者 nthcolumn超过 7 年前

8 条评论

tarr11超过 7 年前
Setting permissions on s3 buckets is absurdly complicated.<p>Though it&#x27;s no excuse, it&#x27;s not surprising people leave it open, it&#x27;s too hard to figure out how to lock it down.<p>Amazon needs to share some of the blame here and create a sane UI.
评论 #15159732 未加载
评论 #15159657 未加载
warent超过 7 年前
Well if Google Reviews are anything to go by, McDonalds is more pleasant than working at&#x2F;with TigerSwan.<p>Also, it&#x27;s amusing that they&#x27;re blaming this mysterious third-party &quot;TalentPen&quot; whose search results are so scant that they have this very article as one of the top hits. Wouldn&#x27;t TigerSwan be equally liable for vetting their vendors?
评论 #15159604 未加载
graystevens超过 7 年前
AWS S3 storage, as mentioned previously in this thread, are a real treasure trove of leaks and breaches. I have been scanning them as part of a project and regularly have to reach out to businesses to tell them they&#x27;re leaking information publicly.<p>You name it, I&#x27;ve probably come across it - lots are for hosting static content of websites which is pretty common, but there are also website and database backups, user uploaded content (from a sensitive &#x27;dating&#x27; website), development and staging environments with sensitive internal information, a sea of CVs etc.<p>The hardest part is trying to responsibly disclose this stuff to the businesses - trying to find a security contact is often impossible, leaving it up to info@ or support@ emails.<p>And obviously AWS aren&#x27;t the only cloud storage provider out there... there is more to be found with the other providers.
mindcrime超过 7 年前
S3 is awesome. You can find all sorts of interesting stuff by adding site:s3.amazonaws.com to a google search. You&#x27;d seriously be amazed (or not) at the stuff people leave in open S3 buckets.
yeukhon超过 7 年前
Time Warner Cable also had the same data breach. I wonder by passwordless did they mean someone was able to do a ls command on the bucket and was able to download as a public&#x2F;anon user (direct s3 link)? If this was done I bet you someone probably didn&#x27;t have time to implement secure link, just decided to make the bucket open.
评论 #15159714 未加载
评论 #15159608 未加载
zie超过 7 年前
Putting top secret anything on the Internet seems like the opposite of a good idea.
评论 #15159377 未加载
评论 #15168113 未加载
评论 #15161134 未加载
andy_ppp超过 7 年前
If you are a spook I wonder how you give references? And if you’ve done anything good you can’t write it on your CV without breaking the law.
评论 #15159435 未加载
评论 #15159453 未加载
评论 #15159437 未加载
评论 #15160019 未加载
评论 #15159382 未加载
mindslight超过 7 年前
URI or GTFO. What use is &quot;reporting&quot; on the snake oil industry&#x27;s own FUDmongering press releases? &quot;Permissions are hard, let&#x27;s go shopping!&quot;<p>Let&#x27;s see some independent analyses of this dataset. Start turning on the right lights and the roaches will scatter.