Discussion about this post

User's avatar
John Wessel's avatar

As far as the whole snowflake thing:

1) it’s absolutely terrible that everyone locks up SSO in their enterprise tier. If that feature was illegal to paywall security would be better for everyone.

2) part of snowflakes big success IMO was the database was no longer behind the firewall - it was in the cloud. You could get data in and out without a 2 week process for the network team to adjust the firewall or setup a ssh tunnel. The other part was you signed up for it like any other SaaS app - MFA optional. That’s the part that probably needs to be handled with more secure defaults. Like MFA required unless an admin turns it off… or something like that.

Expand full comment
Kendall Willets's avatar

It looks like you win the "coincidentally correct" prize, as Wired is reporting that a hacked Snowflake service partner was storing customer credentials in Jira tickets.

Expand full comment
9 more comments...

No posts