致力于为用户提供真实的
主机测评数据及优惠信息

[经验] [WSJ独家]阿里巴巴**因警方数据泄露事件被**当局约谈

网友 spotlight 说:

*帖最后由 spotlight 于 2022-7-15 10:24 编辑

今日国际头条新闻

WSJ中文版:https://cn.wsj.com/articles/%E9%98%BF%E9%87%8C%E5%B7%B4%E5%B7%B4%E9%AB%98%E7%AE%A1%E5%9B%A0%E8%AD%A6%E6%**%B9%E6%95%B0%E6%8D%AE%E6%B3%84%E9%9C%B2%E4%BA%8B%E4%BB%B6%E8%A2%AB%E4%B8%AD%E5%9B%BD%E5%BD%93%E5%B1%80%E7%BA%A6%E8%B0%88-11657841106

路透社头条转载 https://www.reuters.com/technolo**/alibaba-exe**-summoned-by-shanghai-**tho**ties-over-data-theft-p**be-wsj-2022-07-14/?utm_so**ce=newsletter&utm_medium=email&utm_campai**=technolo**-**undup&utm_term=Technolo**%20Roundup%20-%202021%20-%20Master%20List

WSJ英文版全文:https://www.wsj.com/articles/alibaba-executives-called-in-by-china-**tho**ties-as-it-investigates-histo**c-data-heist-11657812800?mod=la****_headlines

&*uot;该云所使用的技术已经过时数年,且缺乏基*的安全功能,他们在该公司托管的其他十多个***中也发现这一情况。&*uot;

请问各位MJJ,你们托管在阿里云上的数据还安全吗?

edit: 中文版不全,很多人问为什么阿里有责任,我把英文版的部分放上来

As the investigation continued, Alibaba Cloud ordered staff to review details such as the database architect**e and config**ations in contracts with key clients, especially those with dedicated p**vate cloud reso**ces such as ** agencies and financial institutions, according to employees familiar with the matter and a cloud customer.

Neither Alibaba nor the Shanghai police have commented on the discovery by cybersecu**ty researchers last week that the dashboard for the stolen police database had been left without a pa**word.

According to researchers at LeakIX and Secu**tyDiscovery, **o cybersecu**ty companies that scan the web for unsec**ed databases, the dashboard lacked a pa**word, and there wasn’t a way to add one.

Both the database that Alibaba p**vided for sto**ng the data and the dashboard for acce**ing and managing it were using versions of the p**ducts that were s***ral years outdated, the researchers said. Those versions didn’t include any secu**ty feat**es, such as pa**word p**tection, without a separate add-on that was n***r installed, they said.

The mi**ing add-on didn’t matter for the database, which was kept on a sec**e p**vate ******, but the dashboard was set up on the public internet, acting like an open door to the data v**lt and allowing the information inside to be exported unencumbered.

The database was also mi**ing an up-to-date secu**ty certificate, a uni*ue digital identifier used to encrypt web traffic that has become standard practice. Alibaba last deployed a new certificate in September 2017, which expired a year later and was n***r renewed, according to the researchers.

The reliance on an expired certificate didn’t increase the vulnerability of the database but indicates that upkeep had been neglected, said Gregory Boddin, LeakIX’s chief technolo** officer. “There was no maintenance whatso***r on it,” he said, for at least the past fo** years.

LeakIX and Secu**tyDiscovery both said they found 13 other Alibaba-hosted databases that used the same outdated version of the database and dashboard p**ducts, and that had been set up identically with the database on a p**vate ****** and the dashboard on the public internet. All 13 also shared the same certificate that then expired, which bucks best practices for secu**ty, Mr. Boddin said.

Nearly all had been left open upward of a year, according to LeakIX’s records. Two contained ***n **** data than the 23 terabytes stolen f**m the Shanghai police: One had over 60 terabytes, while the other had over 92 terabytes.

“Even one day is enough for a database of such size to be grabbed and collected by malicious actors,” said Bob Diachenko, owner of Secu**tyDiscovery.

In early July, shortly after the leak be*** gaining widespread attention on social media, Alibaba cut public acce** to all 14 databases, Me**rs. Boddin and Diachenko said.

Alibaba founder Jack Ma was an early evangelist of the use of data in policing and social cont**l. In 2016, he delivered a speech to 1.5 million political and legal officials in which he said ****ysis of vast *uantities of data would **** the public secu**ty agencies track down thi***s and predict ter****st attacks before they happened.

Alibaba Cloud is the biggest public cloud-******* p**vider in China, but it lags far behind compe*****s like Huawei Technologies Co. in cate**ng to clients who demand their own p**vate cloud ******s, according to **-backed think tank CCW Research. Alibaba’s cloud busine** t**ned a p**fit in the *uarter ended March, ****** it the first Chinese cloud-******* p**vider to make money f**m the cash-b**ning sector.

Alibaba previously has faced scrutiny over its data-secu**ty practices. In December, the Chinese ministry in charge of technolo** suspended a cybersecu**ty partnership with Alibaba’s cloud-computing unit for six months after Beijing alleged the company failed to report a global sof**are vulnerability to it in a timely manner.

Last year, under pre****e f**m a local telecom regulator, the company disclosed a 2019 incident in which an employee had leaked client contact information to a dist**butor.

Earlier this week, the Shanghai **tho**ties announced a cybersecu**ty review of key websites and platforms belonging to ** agencies, state-owned companies, big tech firms and other entities, with a particular focus on any that contained personal data on **** than one million people.
网友 88232128 说:

阿里巴巴:自己把密码贴到**dn,关我屁事!

网友 神秘北极圈 说:

这个不是**的漏洞吗?怪阿里巴巴吗?

网友 larry 说:

神秘北极圈 发表于 2022-7-15 10:09
这个不是**的漏洞吗?怪阿里巴巴吗?
网友 **ofredinand 说:

这个好象是**的问题吧

网友 logic90 说:

*帖最后由 logic90 于 2022-7-15 10:43 编辑

88232128 发表于 2022-7-15 10:16
阿里巴巴:自己把密码贴到**dn,关我屁事!
网友 朕*你无罪 说:

约谈而已。。。又不是什么问题。气氛都烘托到这了。不处理又不行。。交点罚款。罚酒三杯吧

网友 东方红 说:

我想看国内媒体版,最好是胡叼盘版。

网友 silence 说:

larry 发表于 2022-7-15 10:15
数据存在你阿里云,泄露了你就要负责,不需要解释。
网友 StarkSands 说:

果然铁拳打起来是毫不讲理的。***被盗是不是可以捶银行。

网友 滚来滚去 说:

办事不行,甩锅最在行

网友 狂人 说:

哪里都不安全 听天由命吧

网友 Apian 说:

安全是相对的,没有绝对的安全。。。。

网友 YorkZhao 说:

套路云狗都摇头

网友 farnan 说:

  背锅侠

网友 霜浪 说:

我的115网盘就是在阿里云上的

网友 lsp** 说:

阿里吃了好几次铁拳了吧

网友 静香 说:

阿里云狗都不用
**aliyun.com

网友 滚来滚去 说:

办事不行,甩锅最在行

网友 dalky 说:

**ofredinand 发表于 2022-7-15 10:11
这个好象是**的问题吧
网友 silence 说:

larry 发表于 2022-7-15 10:15
数据存在你阿里云,泄露了你就要负责,不需要解释。
网友 StarkSands 说:

果然铁拳打起来是毫不讲理的。***被盗是不是可以捶银行。

网友 cla** 说:

约谈, 不是追责,顶多就谈谈事情怎么发生的,后面怎么避免这个问题,走个过场。

网友 hjh142857 说:

为什么不去锤**dn我不李姐

网友 huiyi 说:

88232128 发表于 2022-7-15 10:16
阿里巴巴:自己把密码贴到**dn,关我屁事!
网友 logic90 说:

*帖最后由 logic90 于 2022-7-15 10:43 编辑

88232128 发表于 2022-7-15 10:16
阿里巴巴:自己把密码贴到**dn,关我屁事!
网友 绿岛小夜曲 说:

**者应该判*刑,**把***城楼的牌子换成那颗头,挂上一个星期,以供后人警示。

网友 chief567 说:

约谈又不是因为23T的那个,都没认真看?

网友 bbcnn 说:

主要责任应该是为什么公网能访问。。。

网友 ******ck 说:

叫什么叫?
不找个背锅的!!
我怎么能下得了台?
开什么玩笑?不找你背锅。难道找我吗?

网友 萌十七 说:

10e那事?

网友 晴晴晴 说:

听我说 谢谢你

网友 orwtmc 说:

larry 发表于 2022-7-15 10:15
数据存在你阿里云,泄露了你就要负责,不需要解释。
网友 orwtmc 说:

silence 发表于 2022-7-15 10:31
你自己把密钥放**dn,数据被别人偷了,还怪阿里吗
网友 louiejordan 说:

这*作,看不懂啊

网友 jiao13**0095** 说:

需要一个背锅的,只让那个泄露密钥那一个人抗的话事儿有点大,找阿里背锅吧正好借此机会打压垄断企业,一举两得

网友 akkba 说:

锅, 总得有人背不是

网友 **n 说:

阿里是出来背锅的
**会背这个锅吗?怎么可能

网友 gales**r 说:

这逻辑无敌了,可能脸面没地搁了,自己找台阶下

网友 jshkk 说:

不对警察局追责吗?

网友 阿里云 说:

我好冤啊

网友 lokinT 说:

就硬要背锅

网友 larry 说:

orwtmc 发表于 2022-7-15 11:54
这个就跟 你自己把家门钥匙丢在地上 家里东西被偷了 你还要问这个锁为什么能开 一样 …

赞(0) 打赏
未经允许不得转载:爱主机 » [经验] [WSJ独家]阿里巴巴**因警方数据泄露事件被**当局约谈
分享到: 更多 (0)

评论 抢沙发

  • 昵称 (必填)
  • 邮箱 (必填)
  • 网址