Even if it was the official article title, "Data Leak" is extremely misleading; the attack is called credential stuffing and is unrelated to any sort of breach on Ring's end. Edit: finished reading the article, and the entire text is just as misleading as the title, credential stuffing happens all the time and really isn't newsworthy.
A Data Leak Exposed the Personal Information of over 3k Ring Users
51–60 of 97 posts
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#52It's fascinating how Ring's business model benefits from local crime prevalence, which in turn might lead people to invest in home security. It is also fascinating how media companies are likely to pounce on the slightest of flaws(some malignant, and some innocuous) with either Nest or Ring, since it feeds on people's sense of security/safety again, and thus are likely to lead to more clicks.
It's fascinating how Ring's business model benefits from local crime prevalence, which in turn might lead people to invest in home security.
That's an interesting point. The whole Ring ecosystem is kinda boosted by Amazon's other business too: leaving boxes on peoples front porches to be stolen. Amazon really knows how to grow a circular ecosystem huh?Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#53This seems important: "Ring does not alert users of attempted log-in from an unknown IP address, or tell users how many others are logged into an account at one time. Because of this, there is no obvious way to know whether any bad actors have logged into people’s compromised Ring accounts without their consent." I can understand not having 2FA turned on by default, but a bare minimum for this kind of service would b…
Due to the overwhelmingly high amount of attempted fraud in grey/black market VoIP stuff, it's pretty common for wholesale SIP trunking providers to now alert the account owner whenever the web account control panel is logged into from a new, unknown ISP and/or useragent.
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#54Not referenced in this article, but something I've been thinking about while reading about the security kerfuffle, why are people putting cameras in their kids rooms? I get the exterior, but why are they spying on their kids? I can't think of a security reason for it, it's just super controlling and creepy.
Baby monitors are a thing and have been for close to 80 years. Now that cameras and displays are cheap video is on there too.
https://www.nbcnews.com/news/us-news/man-hacks-ring-camera-8...
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#55Not referenced in this article, but something I've been thinking about while reading about the security kerfuffle, why are people putting cameras in their kids rooms? I get the exterior, but why are they spying on their kids? I can't think of a security reason for it, it's just super controlling and creepy.
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#56Earlier quoted context omitted.
Due to the overwhelmingly high amount of attempted fraud in grey/black market VoIP stuff, it's pretty common for wholesale SIP trunking providers to now alert the account owner whenever the web account control panel is logged into from a new, unknown ISP and/or useragent.
These “boutique” SIP providers (as I call them, Telnyx, Voipo, VoIP.ms etc) could really learn from their larger telecom counterpoints by allowing users to whitelist what IP ranges users can even authenticate from. Heck, even Linode offers this.
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#57Earlier quoted context omitted.
> Not sure what security experts they talked to https://www.eff.org/about/staff/cooper-quintin
And here is his take on it. https://twitter.com/cooperq/status/1207780461834977281
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#58Earlier quoted context omitted.
Maybe it's because literally every password protected service is vulnerable to users reusing passwords on other insecure sites. It would be like a website writing an expose on how ford trucks are killing hundreds of drivers and expecting a response from ford, but when you read the details it's because users are driving their trucks into brick walls, something that literally every car on the market is susceptible to.
MFA?
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#59Earlier quoted context omitted.
These “boutique” SIP providers (as I call them, Telnyx, Voipo, VoIP.ms etc) could really learn from their larger telecom counterpoints by allowing users to whitelist what IP ranges users can even authenticate from. Heck, even Linode offers this.
Vitelity has supported this for probably a decade.
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#60It's fascinating how Ring's business model benefits from local crime prevalence, which in turn might lead people to invest in home security. It is also fascinating how media companies are likely to pounce on the slightest of flaws(some malignant, and some innocuous) with either Nest or Ring, since it feeds on people's sense of security/safety again, and thus are likely to lead to more clicks.
It's fascinating how Ring's business model benefits from local crime prevalence, which in turn might lead people to invest in home security. That's an interesting point. The whole Ring ecosystem is kinda boosted by Amazon's other business too: leaving boxes on peoples front porches to be stolen. Amazon really knows how to grow a circular ecosystem huh?