160 points by eccgecko 3 days ago | 52 comments | View on ycombinator
mewse-hn 3 days ago |
6thbit 3 days ago |
> the Tanstack compromise is very likely to have been the leak vector
....appears to have been backdoored to extract an API key with authorization to read the private codebase.
...
> immediately rotated all required tokens & credentials to prevent further incidents.
Rotating the API key doesn't quite put them in a position to "prevent further incidents" does it? The next PyPI/npm supply chain issue will just get the new key?I suppose whatever they use that key for should be reviewed and re-scoped if possible?
Does github let you restrict where you can originate requests using a given API key? or are we just not there yet?
sandeepkd 3 days ago |
Turns out they are not really a security company, just an aggregator of bad IPs. Ideally this kind of aggregator problem is best suited for a trusted not-for-profit company where providing the data needs some level of credibility and querying the data costs you nominal fee to keep the setup floating.
itintheory 3 days ago |
sidcool 3 days ago |
giancarlostoro 3 days ago |
Sweepline 2 days ago |
Sorrel47 2 days ago |
9029 3 days ago |
[0] https://en.wikipedia.org/wiki/2024_CrowdStrike-related_IT_ou...
okokwhatever 3 days ago |
xyst 3 days ago |
On the flip side, there was allegedly no PII leaked. But this event is still a red flag as it means their internal ops are absolutely shit. So it’s another vendor receiving a PNG flag.
CrowdSec. CrowdStrike.
laurennorthwood 3 days ago |
JonathanCross 3 days ago |
gleezard 3 days ago |