Note I shared internally after the Twitter hack

If you live on earth and are in tech, you know that Twitter was hacked via social engineering and access to internal systems. There is more unknown than known in this case.

Following that, I shared a note in our internal Slack.

 Twitter was hacked. Multiple verified account were tweeting about crypto. Twitter blames social engineering and access to internal system. This is your almost daily reminder why we scrutinize access to APIs and internal systems so much. Limiting the blast radius of an internal access is crucial to doing business in our environment.

Since day 0, we had an almost **extreme** view on security and access. When I started at the company as a senior DevOps engineer, I did not get any access. I was very surprised by it. I could not access APIs, could not access AWS, nothing.

The way to deal with this is to limit the blast radius via compartmentalization.

To be fair, you got access much more quickly than most...

To view or add a comment, sign in

More articles by Avi Zurel

  • The 3 W’s: A Simple Way to Solve Problems Smarter

    In engineering, we’re constantly tackling problems. But sometimes, what looks like a simple request actually hides a…

  • Analyzing GMail (Gsuite) with Python and Google Sheets

    Earlier this week, I published this tweet: I have a Gsuite account going back a few years for `kensodev.com`.

  • Our Ephemeral dev environments -driven by Slack

    In one of my recent posts (https://www.linkedin.

  • Investing in multi-cloud

    One of the goals for us this year is to invest in multi-cloud deployments. There are multiple reasons for this, I…

    1 Comment
  • How we deploy to production

    Yesterday, I was texting with a friend that asked me a question about the load on our ops team during COVID With remote…

    5 Comments
  • Managing a flexible cluster of micro-services - HOWTO in the wild

    We've been managing flexible clusters of micro-services for quite some time now. Over the years, we've learned some…

  • Dishes and Laundry

    I had a conversation today with one of my project managers. It made me think about this "dishes and laundry" term in…

    1 Comment
  • Adhesion

    I recently gave a short talk in our engineering all-hands. I got a ton of responses, leading me to think that this…

  • Managing CI Configurations At Scale - Globality

    Intro You often hear about scale issues when discussing capacity, traffic, users and other resource related topics and…

    3 Comments
  • Chat controlled RC car using a RaspberryPi

    I've been streaming myself coding on Twitch for the last couple of months. I wanted to build something really fun and…

    1 Comment

Explore content categories