告诉 HN:Porter 发生安全事件 (YC S20)
4 分•作者: leetrout•4 个月前
向团队致敬。Justin 很棒,我知道他们肯定承受了很大压力。<p>以下是我收到的来自 Porter 的电子邮件,为了符合 HN 的字符限制,我进行了删减。完整文本请访问:https://gist.github.com/leetrout/2d172d2b95e8d24af0f3de0d0b03561e<p>---<p>发生了什么<p>2026 年 4 月 13 日,Porter 团队检测到源自我们基础设施中过期的 AWS 访问密钥的未经授权的活动。检测到后,我们立即撤销了所有受影响的凭证,并启动了事件响应流程,其中包括全面调查。<p>自 4 月 13 日以来,我们没有发现 Porter 网络和系统中存在未经授权活动的进一步证据。我们与 Cloudflare 和 Amazon 紧密合作,基本完成了对我们环境的调查,并继续优先支持客户的响应工作。<p>我们确定威胁行为者在 2026 年 4 月 11 日 03:23 UTC 至 2026 年 4 月 13 日 15:24 UTC 之间活动。在此期间,威胁行为者利用 IAM 角色链从 Porter 的基础设施访问了 21 个客户云账户。目标群体中的一些客户确认成功检索了集群上的密钥。对于这些用户,我们目前没有证据表明密钥被滥用,或者除了通过此角色链检索密钥之外还采取了其他操作。特别是,没有证据表明对任何这些用户的客户基础设施进行了任何未经授权的修改。<p>通过相同的初始访问,威胁行为者访问了 Porter GitHub App 的凭证。在与 GitHub 团队合作后,我们了解到,向 GitHub API 端点发送了针对一些用户的请求。我们随后收到了确认,有三个客户存储库被克隆。用户配置的 Helm 覆盖和 Porter 集成(包括 Slack 和 AI 集成,针对少数用户)的凭证也被泄露。本周,所有拥有此类凭证的用户都已直接收到通知。<p>[略]<p>在随后的几天里,我们做了以下工作:<p>轮换了所有剩余的 Porter AWS 访问密钥,包括那些已知未受影响的密钥<p>在所有 Porter AWS 账户中部署了额外的日志记录和监控<p>建立了端点检测和响应、额外的实时警报、事件响应保留机制,以及与外部安全公司的 24x7 监控<p>进一步限制了入口网络流量<p>聘请了 Cloudflare、Latacora 和 AWS 来审计我们的配置<p>我们将在后续的详细报告中涵盖我们正在进行的全面补救措施,包括消除长期存在的访问密钥、实施最小权限、限制角色链以及扩展威胁检测。<p>Porter 客户应该做什么<p>我们已经根据所有客户的暴露程度,向他们传达了量身定制的行动项目。以下一般步骤适用于所有人:<p>审查 GitHub 活动日志<p>[略]<p>需要查找的关键事件:<p>意外的存储库克隆(“git.clone”事件)<p>向存储库添加新的部署密钥或 SSH 密钥<p>您不认识的 OAuth 应用程序授权<p>对分支保护规则或 webhook 配置的更改<p>轮换第三方凭证<p>轮换任何 Porter 集成的凭证,包括 Slack、警报服务和 AI 支持,这些凭证自 2026 年 4 月 14 日以来未更新。<p>如果需要,请聘请安全公司<p>[略]<p>接下来会发生什么<p>该事件是由于过时、权限过大的访问密钥造成的。我们的补救措施侧重于消除导致此次入侵发生的条件,而不仅仅是利用的特定载体。<p>我们将在未来几周内分享一份详细的报告,其中将涵盖我们的补救措施和正在进行的加固我们基础设施的努力。我们还计划在未来就我们的安全态势建立定期的透明度更新。<p>[略]
查看原文
Hug ops to the team. Justin is great and I know they have to be stressed from all of this.<p>Email I got from Porter follows, trimmed for HN character limit. Full text at https://gist.github.com/leetrout/2d172d2b95e8d24af0f3de0d0b03561e<p>---<p>What happened<p>On April 13th, 2026, the Porter team detected unauthorized activity originating from a stale AWS access key in our infrastructure. Upon detection, we immediately revoked all affected credentials and engaged our incident response processes, which included a comprehensive investigation.<p>Since April 13th, we have seen no further evidence of unauthorized activity within Porter networks and systems. Working closely with Cloudflare and Amazon, we have substantially completed the investigation of our environment and are continuing to prioritize supporting customers in their response efforts.<p>We have determined that the threat actor operated between 03:23 UTC April 11, 2026 and 15:24 UTC April 13, 2026. During this window, the threat actor leveraged IAM role chaining from Porter's infrastructure to access 21 customer cloud accounts. A few customers within the targeted group confirmed successful retrieval of on-cluster secrets. For these users, we currently have no evidence that secrets were abused or that other actions were taken beyond secret retrieval through this role chain. In particular, there was no evidence of any unauthorized modification of customer infrastructure for any of these users.
Via the same initial access, the threat actor accessed credentials for the Porter GitHub App. Working with the GitHub team, we learned that requests were made to GitHub API endpoints for some users. We have since received confirmation that three customer repositories were cloned. User-configured Helm overrides and credentials for Porter integrations, including Slack and AI integrations for a limited number of users, were also exposed. All users with such credentials were directly informed this week.<p>[snip]<p>In the days since, we have:<p>Rotated all remaining Porter AWS access keys, including those not known to be affected
Deployed additional logging and monitoring across all Porter AWS accounts
Established endpoint detection and response, additional real-time alerting, an incident response retainer, and 24x7 monitoring with an outside security firm<p>Further restricted ingress network traffic<p>Engaged Cloudflare, Latacora, and AWS to audit our configurations<p>We will cover the full scope of our ongoing remediation, including elimination of long-lived access keys, least-privilege enforcement, role chaining restrictions, and expanded threat detection in a detailed write-up to follow.<p>What Porter customers should do<p>We have communicated tailored action items to all customers based on their levels of exposure. The following general steps apply to everyone:<p>Review GitHub activity logs<p>[snip]<p>Key events to look for:<p>Unexpected repository clones ("git.clone" events)<p>New deploy keys or SSH keys added to repositories<p>OAuth application authorizations you don't recognize<p>Changes to branch protection rules or webhook configurations<p>Rotate third-party credentials<p>Rotate credentials for any Porter integrations, including Slack, alerting services, and AI support, that have not been updated since April 14, 2026.<p>Engage a security firm if needed<p>[snip]<p>What comes next<p>The incident resulted from a stale, overprivileged access key. Our remediation is focused on eliminating the conditions that made this compromise possible, not just the specific vector that was exploited.<p>We will share a detailed write-up in the coming weeks covering our remediation and ongoing efforts to harden our infrastructure. We also intend to establish regular transparency updates on our security posture moving forward.<p>[snip]