Live data from Hacker News

A Data Leak Exposed the Personal Information of over 3k Ring Users

buzzfeednews.com

71–80 of 97 posts

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#71

This seems important: "Ring does not alert users of attempted log-in from an unknown IP address, or tell users how many others are logged into an account at one time. Because of this, there is no obvious way to know whether any bad actors have logged into people’s compromised Ring accounts without their consent." I can understand not having 2FA turned on by default, but a bare minimum for this kind of service would b…

Tin foil hat theory: They purposely don't show you this stuff because their security is garbage and it'd alert too many people of their shortcomings and negligence.

[deleted]

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#72
If you hold sensitive customer data, you should idiot-proof your security, even if you can't help the better idiots. It's silly to even call these users idiots, when the service could implement several features to make them safer--whether or not they are idiots is totally beside the point. They're customers.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#73

It's fascinating how Ring's business model benefits from local crime prevalence, which in turn might lead people to invest in home security. It is also fascinating how media companies are likely to pounce on the slightest of flaws(some malignant, and some innocuous) with either Nest or Ring, since it feeds on people's sense of security/safety again, and thus are likely to lead to more clicks.

It's fascinating how Ring's business model benefits from local crime prevalence, which in turn might lead people to invest in home security. That's an interesting point. The whole Ring ecosystem is kinda boosted by Amazon's other business too: leaving boxes on peoples front porches to be stolen. Amazon really knows how to grow a circular ecosystem huh?

Less cynically, if Ring suppresses package theft then people might be willing to order more packages.

tbh I prefer your version though.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#74
post #31

Earlier quoted context omitted.

> credential stuffing happens all the time and really isn't newsworthy. If a bad thing happens all the time and people are unaware of it, calling attention to it is entirely newsworthy. To you, as a jaded security person who understands that there are systemic risks to any network-connected service and nobody is good at defending against them, perhaps it's perfectly normal. To a customer who is making the decision be…

Under that justification, it would require at a bare minimum giving the reader the proper context, e.g., "similar non-breach threats exists for a large number of common online services, such as [list examples the reader is likely to know]".

Sure, but also, my impression is that similar threats do not exist for e.g. Google (because of heuristics on login attempts, scans on the backend for breached passwords, aggressive and un-silenceable notifications about new logins, a well-staffed security team, etc.). So an accurate statement is that most online services that do not specifically invest in account security are vulnerable.

Then customers can decide whether they want an internet-connected home security system from a company that doesn't invest heavily in account security.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#75
post #62

Earlier quoted context omitted.

How does this work if you're traveling? Logging in from a mobile phone?

Typically you have your own IP pbx such as an asterisk system which lives in one place on static v4/v6 IPs, it connects to your upstream sip trunk. Your own clients such as zoiper on Android connect to that.

I thought about using asterisk or something but does that noticeable latency when connecting remotely? Right now I connect directly to my sip provider on the go via an android sip client whereas running my own PBX would add another hop and was concerned how much this impacts latency.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#76
post #75

Earlier quoted context omitted.

Typically you have your own IP pbx such as an asterisk system which lives in one place on static v4/v6 IPs, it connects to your upstream sip trunk. Your own clients such as zoiper on Android connect to that.

I thought about using asterisk or something but does that noticeable latency when connecting remotely? Right now I connect directly to my sip provider on the go via an android sip client whereas running my own PBX would add another hop and was concerned how much this impacts latency.

I'll open myself up for correction on the matter, but it's been my experience that these days Asterisk is more useful as and often more commonly deployed as a feature server (hunt-groups, ring-groups, call trees etc), at least for a broad majority of use cases where SIP is even a part of the conversation. Personally I'd not recommend one try rolling their own Ast based phone system for production/enterprise unless you just really want to and have literally no other projects to deliver back to the org.

Otherwise, what you're doing is perfectly fine and well enough: connect to your SIP trunk via credentials using a local client and you've more or less got a working, accessible phone number. Unless you truly have a need for Asterisk features, don't bother.

I happen to know first hand of a "voice company" that has a pretty sizeable footprint in the travel/hospitality industry making several million dollars a year and one of their products amounts to nothing more than configuring IVRs and charging through the nose to host them using what is (in my opinion alone) a thoroughly overly-complicated Asterisk infrastructure and similarly overly-complicated dial plans.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#78
post #37
post #31

Earlier quoted context omitted.

> credential stuffing happens all the time and really isn't newsworthy. If a bad thing happens all the time and people are unaware of it, calling attention to it is entirely newsworthy. To you, as a jaded security person who understands that there are systemic risks to any network-connected service and nobody is good at defending against them, perhaps it's perfectly normal. To a customer who is making the decision be…

I really hope physical proximity is also some kind of handshake with the device, and not spoofable in-app "GPS"

I hope physical proximity does not mean standing in front of the door. Outside.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#79

Earlier quoted context omitted.

I don't mean baby monitors, I mean cameras in the room of an 8 year old. https://www.nbcnews.com/news/us-news/man-hacks-ring-camera-8...

So that they can be watched from elsewhere in the house...

Obviously, but the question is why parents would do this.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#80
post #55

Not referenced in this article, but something I've been thinking about while reading about the security kerfuffle, why are people putting cameras in their kids rooms? I get the exterior, but why are they spying on their kids? I can't think of a security reason for it, it's just super controlling and creepy.

“You had to live – did live, from habit that became instinct – in the assumption that every sound you made was overheard, and, except in darkness, every movement scrutinized.”

Orwell didn't know we'd have IR illumination on cameras...
Post reply on HN