Politics

Security ends where the credential does not expire

The Column – Cyber ​​Security Week

Years pass but the things that happen are always the same: a 2022 credential, created for a limited pilot project, still valid four years later. We have no idea whether it was a password, token, or other technical secret, nor why that access wasn’t revoked. We know, however, that the inevitable happened: someone unauthorized used it.

The news dates back to a few weeks ago and concerns Klue, a Canadian market and competitive intelligence company, which detected unauthorized activities in its infrastructure dedicated to integrations. The attacker would have managed to obtain some OAuth tokens used to connect Klue to customer systems, including Salesforce, a well-known cloud service. For clarity, you can imagine a token as a delegation: it allows a service to log in without asking for a username and password every time. It’s convenient, at least until it ends up in the wrong hands.

The sequence is simple and disturbing: an old credential opens Klue’s infrastructure; the infrastructure holds customer tokens; tokens open Salesforce environments; data comes out of those environments. It wasn’t necessary to take over each company one by one. It was enough to hit the point where many had concentrated a part of their trust. The digital supply chain resembles a string of Christmas lights, the kind that, when one light bulb burns out, the others stop working and so we discover that interdependence distributes services but concentrates the consequences.

The organizations involved also include cybersecurity companies. Smiling is understandable, but it would be a tasteless smile. They too, like any other organization, live on delegations, integrations and suppliers; no matter how good they are at protecting their perimeter, they can do little when the enemy gives the house keys to the person who comes to clean your house.

Another “already seen film” customers downplay. The stolen data mainly includes names, emails, telephone numbers, job roles, business data and support ticket details. Thus LastPass, a well-known provider of secure credential management, excludes the involvement of password vaults and its core infrastructure; Snyk, a security platform, mainly talks about commercial data and a limited number of tickets. Someone, mistakenly, could consider it as second-class data. To build a good phishing message you don’t need to know who knows what secrets: all you need is the right name, the right role, the right customer and a real problem already reported to support.

Klue said it has revoked credentials and tokens, removed unauthorized code, disabled potentially affected integrations and launched an investigation. It also notified law enforcement, contacted affected customers and announced a review of credential management, vendor access and monitoring. It is the necessary response, but the decisive point comes before the accident: every temporary project should have temporary access, every delegation a deadline, every pilot project a closure procedure. Let’s say that a four-year-old credential does not belong to any of these best practices. The lesson is always the same. In digital, trust is not a feeling: it is an authorization with an expiration date.