6 ms·
I was one of the people involved here (the guy quoted as saying "which means that whoever discovered this is looking at our code"). As the article noted, they
by mkjones 14y ago
I was one of the people involved here (the guy quoted as saying "which means that whoever discovered this is looking at our code").
As the article noted, they started the whole drill relatively early in the morning on a workday (a Wednesday, iirc, which are the days where we do not have meetings). About half an hour after we'd fixed the obvious problem and were starting to dig deeper, the guys organizing the whole thing stepped in and let us know it was actually a drill, but that we were going to keep treating it as if it were real.
It actually ended up being a super interesting and eye-opening experience, and drove good changes to some of our infrastructure. I had no idea we'd go so far as buying a 0-day and using it to test our own systems and response, but I think it shows that we don't screw around when it comes to making sure we're secure.
- JakeSc 14y ago> I had no idea we'd go so far as buying a 0-day Where did they get the 0-day?
- Swannie 14y agoThe phrase "if you have to ask the price, you can't afford it" comes to mind.... If you don't know where to aquire (buy) 0-days, then you probably shouldn't know.
- pja 14y agoThey're readily available, if you're willing to pay the price: http://www.forbes.com/sites/andygreenberg/2012/03/23/shopping-for-zero-days-an-price-list-for-hackers-secret-software-exploits/ http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...