Hacker News new | ask | show | jobs
by mkjones 4869 days ago
I was one of the people involved here (the guy quoted as saying "which means that whoever discovered this is looking at our code").

As the article noted, they started the whole drill relatively early in the morning on a workday (a Wednesday, iirc, which are the days where we do not have meetings). About half an hour after we'd fixed the obvious problem and were starting to dig deeper, the guys organizing the whole thing stepped in and let us know it was actually a drill, but that we were going to keep treating it as if it were real.

It actually ended up being a super interesting and eye-opening experience, and drove good changes to some of our infrastructure. I had no idea we'd go so far as buying a 0-day and using it to test our own systems and response, but I think it shows that we don't screw around when it comes to making sure we're secure.

1 comments

> I had no idea we'd go so far as buying a 0-day

Where did they get the 0-day?

The phrase "if you have to ask the price, you can't afford it" comes to mind....

If you don't know where to aquire (buy) 0-days, then you probably shouldn't know.

They're readily available, if you're willing to pay the price:

http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...