isd changed the topic of #sandstorm to: Welcome to #sandstorm: home of all things sandstorm.io. Say hi! | Have a question but no one is here? Try asking in the discussion group: https://groups.google.com/group/sandstorm-dev | This channel is logged at: https://freenode.irclog.whitequark.org/sandstorm/
griff_ has quit [Quit: griff_]
griff_ has joined #sandstorm
<JacobWeisz[m]> Yeah, if someone gets into your on-premise camera system, good chance they can get into a lot of other sensitive stuff too, you're already hosed.
<simpson> Important food for thought for those of us designing cap-safe homelabs.
<simpson> Be like the video-game designs: Access to your security cameras is not a winning condition, just another capability. (But don't actually encourage hackers with Mario-style lessons or Zelda-style rewards~)
DanC has quit [*.net *.split]
griff_ has quit [Quit: griff_]
<kentonv> oh hey you guys were talking about the camera thing
<kentonv> JacobWeisz[m], they got a root shell on a security camera. That's it. We don't grant our security cameras access to prod.
<kentonv> (but obviously I do agree that cameras probably shouldn't be IoT...)
<kentonv> also the facial recognition thing was apparently just false. We do not use facial recognition. I was actually kind of disappointed by that. I think private office security cameras are a great use case for facial recognition -- to identify people who shouldn't be there and flag them to security. People walk right in to tech company offices all the time, "tailgate" someone with a badge, and then swipe a laptop.
<JacobWeisz[m]> I figured only internal IT folks would know how much risk that poses in a given environment. I would hope/assume Cloudflare segments its network reasonably.
<JacobWeisz[m]> And yeah, I don't think entry/exit to secure buildings is a place where you scream privacy violation. Everyone knows they're being logged when they swipe a badge in.
<kentonv> Well, I think these cameras are not just at the entry/exit. I mean, I don't personally know details of the system but I've seen cameras in all the work areas.
<JacobWeisz[m]> I think people can imagine horror stories about micromanagers and clocking bathroom visits, but I can't imagine Cloudflare being that sort of work environment.
<kentonv> but the whole point is definitely to track intruders, not employees
<kentonv> heh, yeah, certainly not
griff_ has joined #sandstorm
<JacobWeisz[m]> This is a good advertisement for your capability security model stuff nonetheless. :D
<kentonv> it's also a good advertisement for..... Cloudflare's Zero Trust security products. :)
<kentonv> ("Zero Trust" is some sort of marketing term that apparently means "you don't get anything just by being on the corp network, you have to authenticate to services")
<JacobWeisz[m]> True. Anything adequately assuming your internal network is untrustworthy should handle a stray camera being accessible relatively handily.
<JacobWeisz[m]> The potential scary condition would be if the camera platform had any credentials stored for any sort of integrations. Since we can assume the attacker could probably access any data stored with that platform via the admin account.
<JacobWeisz[m]> At least in the Windows world, most things which integrate with AD have at least a user account with minimal credentials, occasionally you find some that needs much higher permissions. Sometimes it's Microsoft Exchange. :o
<JacobWeisz[m]> (My on-prem is always better narrative might've taken a small beating this past week...)
kawaiipunk has quit [Quit: Leaving this Club]
kawaiipunk has joined #sandstorm
griff_ has quit [Quit: griff_]
TMM has quit [Quit: https://quassel-irc.org - Chat comfortably. Anywhere.]
TMM has joined #sandstorm
griff_ has joined #sandstorm
vertigo_38 has quit [Quit: Bridge terminating on SIGTERM]
jryans has quit [Quit: Bridge terminating on SIGTERM]
abliss has quit [Quit: Bridge terminating on SIGTERM]
isd has quit [Quit: Bridge terminating on SIGTERM]
JacobWeisz[m] has quit [Quit: Bridge terminating on SIGTERM]
JacobWeisz[m] has joined #sandstorm
vertigo_38 has joined #sandstorm
jryans has joined #sandstorm
isd has joined #sandstorm
abliss has joined #sandstorm
xet7 has quit [Quit: Leaving]
xet7 has joined #sandstorm
TMM has quit [Quit: https://quassel-irc.org - Chat comfortably. Anywhere.]
TMM has joined #sandstorm
griff__ has joined #sandstorm
griff_ has quit [Read error: Connection reset by peer]
griff__ has quit [Ping timeout: 246 seconds]
griff_ has joined #sandstorm
griff_ has quit [Quit: griff_]
griff_ has joined #sandstorm
xet7 has quit [Remote host closed the connection]
griff_ has quit [Quit: griff_]
griff_ has joined #sandstorm
sy has left #sandstorm [#sandstorm]
griff_ has quit [Quit: griff_]
griff_ has joined #sandstorm