Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is the second Azure disclosure from the guys at Wiz, following the one with Cosmos DB few weeks ago. Now, it’s much more interesting when you take into account that Wiz was founded by the guys who sold a cyber security company, Adallom, to Microsoft and then served in senior roles around Microsoft cloud security post acquisition. Assaf Rappaport, Wiz CEO, served as fhe GM of the Cloud Security Group at Microsoft for five years [0].

I wonder what the people at Microsoft are thinking of this situation.

[0] https://www.linkedin.com/in/assafrappaport



I'm sure its awkward but they appear to be an equal opportunity reporter - https://www.wiz.io/blog/black-hat-2021-aws-cross-account-vul...

Their product is pretty interesting. I did a demo a while back and their approach of building a large graph and doing a good amount of reachability (network and entitelement) leads to some useful signal. It's not entirely novel, JupiterOne has been doing something in the same vein for years now but it seems to work well. Still feels a bit rough around the edges but i thought it was interesting and could work well in situations where simple checkbox-style config analysis falls short.


I was able to leverage JupiterOne to identify the misconfiguration mentioned in the Wiz article across all my AWS accounts in a single query. Pretty nifty.

They shared that query and a bunch more in this blog: https://try.jupiterone.com/my-bucket-my-data-or-is-it


Interesting. Would be curious to know what parts they worked at. GM seems high enough to know about "areas to look at".

Still doesn't excuse having such bugs in the first place though.


What's the implication? That faults were included or neglected to be sussed out by their next company?


Absolutely not. But it’s still kinda weird. Like Facebooks CISO leaving their post to found a company which promotes itself with Facebook CVEs. To quote Matt Levine, “I don’t know”.


> Now, it’s much more interesting when you take into account that Wiz was founded by the guys who sold a cyber security company

security people sell security company and create a security company. color me shocked.


Nice out of context quote.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: