Live data from Hacker News

A Data Leak Exposed the Personal Information of over 3k Ring Users

buzzfeednews.com

81–90 of 97 posts

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#81

This seems important: "Ring does not alert users of attempted log-in from an unknown IP address, or tell users how many others are logged into an account at one time. Because of this, there is no obvious way to know whether any bad actors have logged into people’s compromised Ring accounts without their consent." I can understand not having 2FA turned on by default, but a bare minimum for this kind of service would b…

I've recently had a similar problem with Spotify. My account was stolen. In part because I did not have 2FA turned on... because the app doesn't offer it for some reason. And, in part, because whoever logged into my account from a different IP and device supposedly didn't trip any of their security measures. So I was never even told that someone took hold of my account until I tried to get on. It's baffling to me tha…

I'm curious as to how stolen Spotify accounts are monetised? What's the value of them?

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#82
post #32

Earlier quoted context omitted.

The Amazon spokesperson directly said it was credential stuffing--the article was trying to argue that it was more than that in an extremely misleading way.

It's in Amazon's interest to argue that it wasn't a failing on their part.

I mean, being this susceptible to credential stuffing is a failing on their part, too.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#83
post #81

Earlier quoted context omitted.

I've recently had a similar problem with Spotify. My account was stolen. In part because I did not have 2FA turned on... because the app doesn't offer it for some reason. And, in part, because whoever logged into my account from a different IP and device supposedly didn't trip any of their security measures. So I was never even told that someone took hold of my account until I tried to get on. It's baffling to me tha…

I'm curious as to how stolen Spotify accounts are monetised? What's the value of them?

Free music.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#84
J Cox did some analysis of the dumps, writing:

"I just ran these in a script I wrote to process them through HaveIBeenPwned in bulk. Every single email except ~20 was already compromised. These Ring dumps going around (+Buzzfeed prob) are highly likely password reuse; not evidence to suggest internal DB"

source https://twitter.com/josephfcox/status/1207864924459978752

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#85
post #63

Earlier quoted context omitted.

I've recently had a similar problem with Spotify. My account was stolen. In part because I did not have 2FA turned on... because the app doesn't offer it for some reason. And, in part, because whoever logged into my account from a different IP and device supposedly didn't trip any of their security measures. So I was never even told that someone took hold of my account until I tried to get on. It's baffling to me tha…

2FA for spotify? I'm curious where you draw the line for 2FA. Should every app (and web app) have 2FA?

If it involves money (paid service, even if the hijacker never gets access to your actual card data and can't make any payments) or private data (name, address, etc.) then it really should.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#86
post #74

Earlier quoted context omitted.

Under that justification, it would require at a bare minimum giving the reader the proper context, e.g., "similar non-breach threats exists for a large number of common online services, such as [list examples the reader is likely to know]".

Sure, but also, my impression is that similar threats do not exist for e.g. Google (because of heuristics on login attempts, scans on the backend for breached passwords, aggressive and un-silenceable notifications about new logins, a well-staffed security team, etc.). So an accurate statement is that most online services that do not specifically invest in account security are vulnerable. Then customers can decide whe…

Agreed

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#87
post #81

Earlier quoted context omitted.

I've recently had a similar problem with Spotify. My account was stolen. In part because I did not have 2FA turned on... because the app doesn't offer it for some reason. And, in part, because whoever logged into my account from a different IP and device supposedly didn't trip any of their security measures. So I was never even told that someone took hold of my account until I tried to get on. It's baffling to me tha…

I'm curious as to how stolen Spotify accounts are monetised? What's the value of them?

Sell them on the black market to other people for dirt cheap like Netflix accounts used to (may still be?) done with.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#88

This seems important: "Ring does not alert users of attempted log-in from an unknown IP address, or tell users how many others are logged into an account at one time. Because of this, there is no obvious way to know whether any bad actors have logged into people’s compromised Ring accounts without their consent." I can understand not having 2FA turned on by default, but a bare minimum for this kind of service would b…

I've recently had a similar problem with Spotify. My account was stolen. In part because I did not have 2FA turned on... because the app doesn't offer it for some reason. And, in part, because whoever logged into my account from a different IP and device supposedly didn't trip any of their security measures. So I was never even told that someone took hold of my account until I tried to get on. It's baffling to me tha…

Same thing happened to me... I just noticed one day that my recent music was a bit odd, completely different to what I usually listen to. I changed my password, but 2FA should be a given at this stage.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#89
post #79

Earlier quoted context omitted.

So that they can be watched from elsewhere in the house...

Obviously, but the question is why parents would do this.

Probably because they have multiple rooms in their homes.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#90
post #85
post #63

Earlier quoted context omitted.

2FA for spotify? I'm curious where you draw the line for 2FA. Should every app (and web app) have 2FA?

If it involves money (paid service, even if the hijacker never gets access to your actual card data and can't make any payments) or private data (name, address, etc.) then it really should.

I agree for the most part about the money part. I would still want the option for them to not allow me to upgrade plans without re-entering my credit card info. But with regards to personal information, that is almost everything I log into. And those companies share your personal info anyway, so it just gives you a false sense of privacy/security.
Post reply on HN