Live data from Hacker News

A Data Leak Exposed the Personal Information of over 3k Ring Users

buzzfeednews.com

61–70 of 97 posts

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#61
post #49

Earlier quoted context omitted.

Baby monitors are a thing and have been for close to 80 years. Now that cameras and displays are cheap video is on there too.

I don't mean baby monitors, I mean cameras in the room of an 8 year old. https://www.nbcnews.com/news/us-news/man-hacks-ring-camera-8...

So that they can be watched from elsewhere in the house...

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#62
post #53

Earlier quoted context omitted.

Due to the overwhelmingly high amount of attempted fraud in grey/black market VoIP stuff, it's pretty common for wholesale SIP trunking providers to now alert the account owner whenever the web account control panel is logged into from a new, unknown ISP and/or useragent.

These “boutique” SIP providers (as I call them, Telnyx, Voipo, VoIP.ms etc) could really learn from their larger telecom counterpoints by allowing users to whitelist what IP ranges users can even authenticate from. Heck, even Linode offers this.

How does this work if you're traveling? Logging in from a mobile phone?

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#63

This seems important: "Ring does not alert users of attempted log-in from an unknown IP address, or tell users how many others are logged into an account at one time. Because of this, there is no obvious way to know whether any bad actors have logged into people’s compromised Ring accounts without their consent." I can understand not having 2FA turned on by default, but a bare minimum for this kind of service would b…

I've recently had a similar problem with Spotify. My account was stolen. In part because I did not have 2FA turned on... because the app doesn't offer it for some reason. And, in part, because whoever logged into my account from a different IP and device supposedly didn't trip any of their security measures. So I was never even told that someone took hold of my account until I tried to get on. It's baffling to me tha…

2FA for spotify? I'm curious where you draw the line for 2FA. Should every app (and web app) have 2FA?

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#64
post #63

Earlier quoted context omitted.

I've recently had a similar problem with Spotify. My account was stolen. In part because I did not have 2FA turned on... because the app doesn't offer it for some reason. And, in part, because whoever logged into my account from a different IP and device supposedly didn't trip any of their security measures. So I was never even told that someone took hold of my account until I tried to get on. It's baffling to me tha…

2FA for spotify? I'm curious where you draw the line for 2FA. Should every app (and web app) have 2FA?

I'd argue, in 2019, every app/service that requires a login should offer a 2FA option to add an additional layer of security - the person logging in most likely is the owner of the 2FA device.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#65
post #62
post #53

Earlier quoted context omitted.

These “boutique” SIP providers (as I call them, Telnyx, Voipo, VoIP.ms etc) could really learn from their larger telecom counterpoints by allowing users to whitelist what IP ranges users can even authenticate from. Heck, even Linode offers this.

How does this work if you're traveling? Logging in from a mobile phone?

Self-Managed VPN, in our case.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#66

This seems important: "Ring does not alert users of attempted log-in from an unknown IP address, or tell users how many others are logged into an account at one time. Because of this, there is no obvious way to know whether any bad actors have logged into people’s compromised Ring accounts without their consent." I can understand not having 2FA turned on by default, but a bare minimum for this kind of service would b…

Tin foil hat theory: They purposely don't show you this stuff because their security is garbage and it'd alert too many people of their shortcomings and negligence.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#67

This seems important: "Ring does not alert users of attempted log-in from an unknown IP address, or tell users how many others are logged into an account at one time. Because of this, there is no obvious way to know whether any bad actors have logged into people’s compromised Ring accounts without their consent." I can understand not having 2FA turned on by default, but a bare minimum for this kind of service would b…

Tin foil hat theory: They purposely don't show you this stuff because their security is garbage and it'd alert too many people of their shortcomings and negligence.

Well, if we want to tin foil hat theory it, then it's because the device can't differentiate between user access, police access and other hacker access.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#68

Earlier quoted context omitted.

Tin foil hat theory: They purposely don't show you this stuff because their security is garbage and it'd alert too many people of their shortcomings and negligence.

Well, if we want to tin foil hat theory it, then it's because the device can't differentiate between user access, police access and other hacker access.

Damn, you just took it to a whole other level, that's a good one

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#69
post #62
post #53

Earlier quoted context omitted.

These “boutique” SIP providers (as I call them, Telnyx, Voipo, VoIP.ms etc) could really learn from their larger telecom counterpoints by allowing users to whitelist what IP ranges users can even authenticate from. Heck, even Linode offers this.

How does this work if you're traveling? Logging in from a mobile phone?

Typically you have your own IP pbx such as an asterisk system which lives in one place on static v4/v6 IPs, it connects to your upstream sip trunk. Your own clients such as zoiper on Android connect to that.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#70
post #63

Earlier quoted context omitted.

2FA for spotify? I'm curious where you draw the line for 2FA. Should every app (and web app) have 2FA?

I'd argue, in 2019, every app/service that requires a login should offer a 2FA option to add an additional layer of security - the person logging in most likely is the owner of the 2FA device.

Maybe not every app but definitely one through which I make any type of payment. Spotify wants me to buy Premium, Spotify should offer me security.
Post reply on HN