I want to raise a concern about operational security in the recent status updates.
Transparency during incidents is appreciated, but the last few posts have exposed details that should be internal only.
Specifically:
1. Provider name and datacenter location
2. Hardware status and upgrade timeline
3. Mitigation methods and proxy architecture
4. Minute-level attack windows that let an attacker measure what worked and what didn't
None of this information helps users. All of it helps attackers. Keep in mind that every public post is read by the adversary too.
Users need two things from a status update:
1. Reassurance that the team is actively working the problem.
2. A rough ETA for resolution. (if it does not enable another attack)
That's it. No infrastructure specifics required for credibility.
I'd recommend pulling the operational details from the existing posts as well. Even after an incident winds down, those details remain searchable and useful to copycats.
<Edit_1> "It's technically discoverable" and "we confirmed it publicly" are different threat levels.
Recon still takes time and has a cost. Free confirmation eliminates it. </Edit_1>
Please keep your cards closer to your chest.
For what it's worth, I loved Turtle WoW and want to see Octowow thrive. If the team wants another set of eyes on the mitigation approach, I'm happy to help where I can.