Live data from Hacker News

A Data Leak Exposed the Personal Information of over 3k Ring Users

buzzfeednews.com

11–20 of 97 posts

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#11
post #5

Even if it was the official article title, "Data Leak" is extremely misleading; the attack is called credential stuffing and is unrelated to any sort of breach on Ring's end. Edit: finished reading the article, and the entire text is just as misleading as the title, credential stuffing happens all the time and really isn't newsworthy.

No, actually the article claimed the opposite: the attack was likely NOT credential stuffing..

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#12
post #5

Even if it was the official article title, "Data Leak" is extremely misleading; the attack is called credential stuffing and is unrelated to any sort of breach on Ring's end. Edit: finished reading the article, and the entire text is just as misleading as the title, credential stuffing happens all the time and really isn't newsworthy.

If we read the same article, we’d have been agreeing that it said it was unlikely to be credential stuffing.

> Security experts told BuzzFeed News that the format of the leaked data — which includes username, password, camera name, and time zone in a standardized format — suggests it was taken from a company database. They said data obtained via credential stuffing —when previously-compromised emails and passwords are used to get access to other accounts — would likely not display RIng-specific data like camera names or time zone.

> “One could argue that the person maybe got these through credential stuffing,” Cooper Quintin, a security researcher and senior staff technologist at the Electronic Frontier Foundation, told BuzzFeed News. “But if that was the case, why did that person go through and add the information about names of camera and time zones?”

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#13
post #5

Even if it was the official article title, "Data Leak" is extremely misleading; the attack is called credential stuffing and is unrelated to any sort of breach on Ring's end. Edit: finished reading the article, and the entire text is just as misleading as the title, credential stuffing happens all the time and really isn't newsworthy.

No, actually the article claimed the opposite: the attack was likely NOT credential stuffing..

After reading the article, it's pretty clear that it was credential stuffing and that the writer didn't take the time to understand how it worked. Not sure what security experts they talked to, but credential stuffing absolutely can get all the information described, and the whole part about wifi connected devices is completely unrelated.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#14
post #5

Even if it was the official article title, "Data Leak" is extremely misleading; the attack is called credential stuffing and is unrelated to any sort of breach on Ring's end. Edit: finished reading the article, and the entire text is just as misleading as the title, credential stuffing happens all the time and really isn't newsworthy.

If we read the same article, we’d have been agreeing that it said it was unlikely to be credential stuffing. > Security experts told BuzzFeed News that the format of the leaked data — which includes username, password, camera name, and time zone in a standardized format — suggests it was taken from a company database. They said data obtained via credential stuffing —when previously-compromised emails and passwords ar…

All of that information is extremely common when it comes to aggregated information sold/shared for credential stuffing, there's nothing that sticks out as odd or out of place in any of this. It can all be pulled through scripts, there's no extra effort needed.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#15

Earlier quoted context omitted.

No, actually the article claimed the opposite: the attack was likely NOT credential stuffing..

After reading the article, it's pretty clear that it was credential stuffing and that the writer didn't take the time to understand how it worked. Not sure what security experts they talked to, but credential stuffing absolutely can get all the information described, and the whole part about wifi connected devices is completely unrelated.

I'm not making any guesses what actually happened.

Just stating that you misrepresented what the article actually said when you wrote "the attack is called credential stuffing". Your sentence gives impression that the article would have said it, but the article made a point for the opposite.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#16
post #8

So 3k people who installed neighborhood surveillance devices have suffered a loss of privacy? Can't seem to find much sympathy.

Almost everyone who gets a ring or other smart door bell is getting one to see who is knocking on their door, not to spy on their neighborhood

The Neighbors app is filled with posts about "suspicious" people walking down the street. People are very much using these devices to surveil their neighborhood.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#17
post #8

Earlier quoted context omitted.

Almost everyone who gets a ring or other smart door bell is getting one to see who is knocking on their door, not to spy on their neighborhood

The Neighbors app is filled with posts about "suspicious" people walking down the street. People are very much using these devices to surveil their neighborhood.

I didn't say no one is using it to surveil their neighborhood. I said most people aren't. What percentage of Ring users do you think are posting in the Neighbors app?

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#18

Earlier quoted context omitted.

After reading the article, it's pretty clear that it was credential stuffing and that the writer didn't take the time to understand how it worked. Not sure what security experts they talked to, but credential stuffing absolutely can get all the information described, and the whole part about wifi connected devices is completely unrelated.

I'm not making any guesses what actually happened. Just stating that you misrepresented what the article actually said when you wrote "the attack is called credential stuffing". Your sentence gives impression that the article would have said it, but the article made a point for the opposite.

The Amazon spokesperson directly said it was credential stuffing--the article was trying to argue that it was more than that in an extremely misleading way.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#19

Earlier quoted context omitted.

No, actually the article claimed the opposite: the attack was likely NOT credential stuffing..

After reading the article, it's pretty clear that it was credential stuffing and that the writer didn't take the time to understand how it worked. Not sure what security experts they talked to, but credential stuffing absolutely can get all the information described, and the whole part about wifi connected devices is completely unrelated.

> Not sure what security experts they talked to

https://www.eff.org/about/staff/cooper-quintin

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#20
It's fascinating how Ring's business model benefits from local crime prevalence, which in turn might lead people to invest in home security.

It is also fascinating how media companies are likely to pounce on the slightest of flaws(some malignant, and some innocuous) with either Nest or Ring, since it feeds on people's sense of security/safety again, and thus are likely to lead to more clicks.

Post reply on HN