Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
c0njecture
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
c0njecture
2y ago
They don't have customer key access and can't assume customer identity but ultimately yes, via a multi-eye approval process there is access to the prod infra - but this is extremely tightly secured, and not something a phishing at
2.
▲
by
c0njecture
2y ago
It is not standard operating procedure, and demos wouldn't be done with production data. In fact, most enterprises would have contracts in place with Snowflake that explictly state that Snowflake staff can not be granted access to thei
3.
▲
by
c0njecture
2y ago
It's not a new tiny company. It's about 12 years old with 7000 employees. They know they are dead if they are not hot on security, so at the moment I would take this story with a big pinch of salt. Quite possible certain customer
4.
▲
by
c0njecture
2y ago
There's no evidence of that at all. The screenshot shows a few Snowflake professional services demo accounts only. These are accounts used by the sales engineer to demo features to customers. It's possible the attacker was able to
5.
▲
by
c0njecture
2y ago
Snowflake internal staff do not have access to read customer data, unless a customer grants it. Customers can use their own KMS to generate table keys. Snowflake has a lot of security features. But still, customers may well misconfigure the