Live data from Hacker News

A Data Leak Exposed the Personal Information of over 3k Ring Users

buzzfeednews.com

51–60 of 97 posts

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#51
post #5

Even if it was the official article title, "Data Leak" is extremely misleading; the attack is called credential stuffing and is unrelated to any sort of breach on Ring's end. Edit: finished reading the article, and the entire text is just as misleading as the title, credential stuffing happens all the time and really isn't newsworthy.

Thanks, so I didn’t have to read article. Really misleading title, I was thinking “...How do only 3k accounts leak...?”

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#52

It's fascinating how Ring's business model benefits from local crime prevalence, which in turn might lead people to invest in home security. It is also fascinating how media companies are likely to pounce on the slightest of flaws(some malignant, and some innocuous) with either Nest or Ring, since it feeds on people's sense of security/safety again, and thus are likely to lead to more clicks.

    It's fascinating how Ring's business model benefits from local crime prevalence, which in turn might lead people to invest in home security.

That's an interesting point. The whole Ring ecosystem is kinda boosted by Amazon's other business too: leaving boxes on peoples front porches to be stolen. Amazon really knows how to grow a circular ecosystem huh?

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#53

This seems important: "Ring does not alert users of attempted log-in from an unknown IP address, or tell users how many others are logged into an account at one time. Because of this, there is no obvious way to know whether any bad actors have logged into people’s compromised Ring accounts without their consent." I can understand not having 2FA turned on by default, but a bare minimum for this kind of service would b…

Due to the overwhelmingly high amount of attempted fraud in grey/black market VoIP stuff, it's pretty common for wholesale SIP trunking providers to now alert the account owner whenever the web account control panel is logged into from a new, unknown ISP and/or useragent.

These “boutique” SIP providers (as I call them, Telnyx, Voipo, VoIP.ms etc) could really learn from their larger telecom counterpoints by allowing users to whitelist what IP ranges users can even authenticate from. Heck, even Linode offers this.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#54
post #49

Not referenced in this article, but something I've been thinking about while reading about the security kerfuffle, why are people putting cameras in their kids rooms? I get the exterior, but why are they spying on their kids? I can't think of a security reason for it, it's just super controlling and creepy.

Baby monitors are a thing and have been for close to 80 years. Now that cameras and displays are cheap video is on there too.

I don't mean baby monitors, I mean cameras in the room of an 8 year old.

https://www.nbcnews.com/news/us-news/man-hacks-ring-camera-8...

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#55

Not referenced in this article, but something I've been thinking about while reading about the security kerfuffle, why are people putting cameras in their kids rooms? I get the exterior, but why are they spying on their kids? I can't think of a security reason for it, it's just super controlling and creepy.

“You had to live – did live, from habit that became instinct – in the assumption that every sound you made was overheard, and, except in darkness, every movement scrutinized.”

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#56
post #53

Earlier quoted context omitted.

Due to the overwhelmingly high amount of attempted fraud in grey/black market VoIP stuff, it's pretty common for wholesale SIP trunking providers to now alert the account owner whenever the web account control panel is logged into from a new, unknown ISP and/or useragent.

These “boutique” SIP providers (as I call them, Telnyx, Voipo, VoIP.ms etc) could really learn from their larger telecom counterpoints by allowing users to whitelist what IP ranges users can even authenticate from. Heck, even Linode offers this.

Vitelity has supported this for probably a decade.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#57
post #33
post #19

Earlier quoted context omitted.

> Not sure what security experts they talked to https://www.eff.org/about/staff/cooper-quintin

And here is his take on it. https://twitter.com/cooperq/status/1207780461834977281

His take is a result of him trying not to completely let go of the story he's already decided is significant. There is no story. There isn't really a great way to defend against credential stuffing attacks when the adversary has access to a huge residential proxy network and you don't want to greatly inconvenience your users. All major US banks are pretty vulnerable to credential stuffing attacks. If banks aren't going to defend against it, Ring isn't.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#58
post #42
post #10

Earlier quoted context omitted.

Maybe it's because literally every password protected service is vulnerable to users reusing passwords on other insecure sites. It would be like a website writing an expose on how ford trucks are killing hundreds of drivers and expecting a response from ford, but when you read the details it's because users are driving their trucks into brick walls, something that literally every car on the market is susceptible to.

MFA?

They do have MFA, but only via SMS.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#59
post #53

Earlier quoted context omitted.

These “boutique” SIP providers (as I call them, Telnyx, Voipo, VoIP.ms etc) could really learn from their larger telecom counterpoints by allowing users to whitelist what IP ranges users can even authenticate from. Heck, even Linode offers this.

Vitelity has supported this for probably a decade.

Good! It’s been a long while since I’ve managed anything clients using Vitelity trunks, but recall having a generally positive experience, glad to hear they still run a good ship to have at least this mechanism.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#60

It's fascinating how Ring's business model benefits from local crime prevalence, which in turn might lead people to invest in home security. It is also fascinating how media companies are likely to pounce on the slightest of flaws(some malignant, and some innocuous) with either Nest or Ring, since it feeds on people's sense of security/safety again, and thus are likely to lead to more clicks.

It's fascinating how Ring's business model benefits from local crime prevalence, which in turn might lead people to invest in home security. That's an interesting point. The whole Ring ecosystem is kinda boosted by Amazon's other business too: leaving boxes on peoples front porches to be stolen. Amazon really knows how to grow a circular ecosystem huh?

A friend of mine recently made the excellent point that Ring also provides Amazon with surveillance footage of their own delivery service employees. Synergy!
Post reply on HN