Live data from Hacker News

Former Ubiquiti employee charged with stealing data and extorting company

justice.gov

131–140 of 244 posts

Re: Former Ubiquiti employee charged with stealing data and extorting company

#131

I've always been fascinated by the idea that intelligence lies within a spectrum. Someone might be incredibly smart about a narrow topic or field, yet be blind to their own stupidity within another realm. To me, this seems like a classic example. To quote the press release: "During the execution of that search, SHARP made numerous false statements to FBI agents, including, among other things, in substance, that he wa…

It's not really about intelligence. When faced correcting a false reality you have created, it can be quite hard to decide to phase change into telling the truth. The lies that come out come from not being prepared and not being a very good liar. For people who lie like this, a good way to think about it is as though it were a disease. Actually intelligent people just don't do things like this, even if they have nefa…

Yeah, he seems to have been operating under the illusion that he'll never get caught. Amateur mistake.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#132
post #130

Earlier quoted context omitted.

Which are those other brands and models, please? I am looking to upgrade my home setup to 10GbE LAN and apart from 2-3 switch models from Mikrotik I really can't see anything worthwhile (I don't want Cisco or TP-Link, they don't take security seriously).

Check out Aruba Instant On, they seem to be trying to jump the bandwagon with the single-pane-of-glass-management and target small businesses. Also Ruckus Unleashed seems to be similar and Juniper MIST.

Thank you! Never heard of them, will research them thoroughly now. Much appreciated.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#133
post #31
post #13

Mr. Sharp is apparently not so sharp. He carried out the attack from his home network. He connected directly for enough time that his bare IP was logged. The rest of the time, he carried out the attack using a commercially purchased VPN solution that was trivial to trace back to him via the purchase record. He lied to the FBI. (I have yet to understand why people talk to law enforcement instead of staying silent so a…

(I have yet to understand why people talk to law enforcement instead of staying silent so as to not implicate themselves.) When the FBI knock at the door you totally do the whole "no comment/talk to my lawyer" thing. But what happens next if you're actually part of an investigation is they hand you a grand jury subpoena (which they were going to do anyway, even if you just talked willingly, because they have already…

You left off the bit where they sieze all your assets in a civil forfeiture, and require you to go to court and prove, beyond reasonable doubt, your innocence so you can get your house and bank account back.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#134
post #100

He could've prevent all of this by a) making sure his traffic was blackholed when the VPN went down and b) adding another layer from a free service (like TOR or a proxy or another VPN). He also should've been actively using the VPN so his traffic patterns wouldn't stand out as much, and so his purchase would be justifiable. If he really did buy the VPN 6 months ahead then he was a fool to leave the subscription dorma…

> he also could've bought the subscription with stolen credit cards Now they're looking at you from two angels. Instead of all this jumping through hoops with anonymous VPN and payment methods, why not just do it from Starbucks?

Because the youtube videos I watch / podcasts I listen to say I NEED a VPN to keep my IP safe from being spied on.

But also starbucks / any shop / cafe / restraunt / apple store - or going for a drive and finding an open WiFi. Kinda wondering now how these places all handle their wifi being abused for crimes ...

Re: Former Ubiquiti employee charged with stealing data and extorting company

#135
post #90

Earlier quoted context omitted.

> wrote everything in Node, but absolutely _refused_ to use any existing libraries except for ones he personally wrote. He didn't "trust" them. Sounds like the single sensible thing he did. Have you seen the npm ecosystem?

Are node apps getting way more hacked than say php or java servers? Was his code any better?

Node apps tend to depend on a far, far wider pool of maintainers.

To illustrate: A new Ruby on Rails app has 1/10th the number of maintainers in its dependency list than a new create-react-app codebase.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#136
post #10

Earlier quoted context omitted.

It sounds like he got caught because his VPN dropped during some sort of outage. It's funny because I feel like "don't do crime from your home network" should be an incredibly obvious concept.

He also used keys as the "attacker" that were known to be his as a regular employee. That seems like a n00b move.

So he litterally signed the attack with his PGP key.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#137

The things that really jumped at me looking at his LinkedIn profile were 1) job hopper and 2) lots of overlapping - perhaps it was all part time gigs but some of the overlap surprised me. I was shocked at the number of sub-year positions.

Same thing - and yet still in demand from some decent names in there.

I thought it was meant to be hard out there in tech valley ?

Re: Former Ubiquiti employee charged with stealing data and extorting company

#138
post #90

Earlier quoted context omitted.

Are node apps getting way more hacked than say php or java servers? Was his code any better?

Node apps tend to depend on a far, far wider pool of maintainers. To illustrate: A new Ruby on Rails app has 1/10th the number of maintainers in its dependency list than a new create-react-app codebase.

A create-react-app app is not a node app (It has a node dev server, but it's a front-end JS app), so its a weird thing to reach for to illustrate a point about node apps.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#139

> SHARP used a virtual private network service that he subscribed to from a company named Surfshark to mask his Internet Protocol (“IP”) address when he accessed Company-1’s AWS and GitHub infrastructure without authorization. How did they know it was SurfShark?

Which discount code did he use?

Use CYBERWEEK19 for 85% your first years subscription.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#140
post #124

As a customer, the one thing I really want to know is whether or not the company is dealing with this in a manner that helps me decide if I should continue being a customer. Do they understand that they may need to fire the CEO given that the CEO probably is the weakest link here? Do they have sufficient liquidity and capital to invest in resetting the culture and hiring people who can turn this around?

Are you aware that the CEO owns about 90% of all Ubiquiti shares?
Post reply on HN