Live data from Hacker News

Former Ubiquiti employee charged with stealing data and extorting company

justice.gov

171–180 of 244 posts

Re: Former Ubiquiti employee charged with stealing data and extorting company

#171
post #93

Earlier quoted context omitted.

Reminded me when I watched people try and get out of jury duty by claiming biases. A big part of the lawyers job is to question people. Their stories fell apart pretty quickly.

That’d be interesting to see. Once I got quizzed when boarding ElAl flights. They have well trained interrogators. It turns out a complicated life story and ADHD method of story telling doesn’t make them happy. A lot of “I said X because the full story is way too complicated, so here’s the full version” ;)

Very similar approach. Repeated questioning to try and poke holes in your story.

People think they can stand up to it but it’s hard when it’s someone whose full time job is exposing fake stories.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#172
post #168

Ex-Ubiquiti employee here. Nick Sharp wasn't just a senior software engineer. He was the Cloud Lead and ran the whole cloud team. His LinkedIn profile will confirm it. This is why he had access to everything. Nick had his hands in everything from GitHub to Slack and we could never understand why or how. He rose to power in the company by claiming to find a vulnerability that let him access the CEO's personal system,…

How does one weaponize slack? Github maybe I can understand, but I don't understand how you can weaponize slack.

Lots of credentials end up getting shared over slack. If you own slack you probably own a few other systems.

Also, extortion. I'm always amazed at what people will say over Slack DMs, seemingly not realizing that it all is accessible by the company.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#174
post #168

Ex-Ubiquiti employee here. Nick Sharp wasn't just a senior software engineer. He was the Cloud Lead and ran the whole cloud team. His LinkedIn profile will confirm it. This is why he had access to everything. Nick had his hands in everything from GitHub to Slack and we could never understand why or how. He rose to power in the company by claiming to find a vulnerability that let him access the CEO's personal system,…

How does one weaponize slack? Github maybe I can understand, but I don't understand how you can weaponize slack.

ChatOps would be one way.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#175

Earlier quoted context omitted.

Which are those other brands and models, please? I am looking to upgrade my home setup to 10GbE LAN and apart from 2-3 switch models from Mikrotik I really can't see anything worthwhile (I don't want Cisco or TP-Link, they don't take security seriously).

Aruba Instant On. (It's owned by HP) The name is bit misleading though. Especially the first time it can take quite some time for devices to be fully updated and manageable. Regarding support wise: I've had one malfunctioning switch (POE just stopped working) and it was replaced within 24 hours, so that's nice.

Does Aruba instant on allow for multiple VLAN solely for wireless clients by SSID?

I love Meraki stuff, so I looked into Meraki Go, and they handicapped Meraki Go by only allowing VLAN for devices with wired connections to the switch. I want the ability to setup a wireless SSID, apply a VLAN to it, and have any wireless devices connected to that SSID be on that VLAN.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#176
post #168

Earlier quoted context omitted.

How does one weaponize slack? Github maybe I can understand, but I don't understand how you can weaponize slack.

Lots of credentials end up getting shared over slack. If you own slack you probably own a few other systems. Also, extortion. I'm always amazed at what people will say over Slack DMs, seemingly not realizing that it all is accessible by the company.

Real question not trying to be cute, it's just been 4+ years since I've been inside a company actively using slack.

Is that (creds) considered safe/secure these days? Is it common place? I kinda figured slack might get to be a 1password on top of everything else, so it's interesting to hear it's happening.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#177
post #176

Earlier quoted context omitted.

Lots of credentials end up getting shared over slack. If you own slack you probably own a few other systems. Also, extortion. I'm always amazed at what people will say over Slack DMs, seemingly not realizing that it all is accessible by the company.

Real question not trying to be cute, it's just been 4+ years since I've been inside a company actively using slack. Is that (creds) considered safe/secure these days? Is it common place? I kinda figured slack might get to be a 1password on top of everything else, so it's interesting to hear it's happening.

> Is that (creds) considered safe/secure these days?

No, definitely not. It's just super convenient and happens all the time at every organization.

The most recent Twitter breach involved a credential shared in a Slack channel. Security teams have a hard time monitoring Slack and the default settings are pretty bad (infinite session length, infinite message retention).

Re: Former Ubiquiti employee charged with stealing data and extorting company

#178
post #43

He could've prevent all of this by a) making sure his traffic was blackholed when the VPN went down and b) adding another layer from a free service (like TOR or a proxy or another VPN). He also should've been actively using the VPN so his traffic patterns wouldn't stand out as much, and so his purchase would be justifiable. If he really did buy the VPN 6 months ahead then he was a fool to leave the subscription dorma…

Why a stolen credit card? Just buy gift visa card with cash.

For what its worth, most online sites will not accept gift visa/mastercard cards any more. It would be nice if there was a site that listed all the sites that do still accept them.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#179

So what's a good alternative to Ubiquiti hardware? Is there some guides/community for standard x86_64/arm64 computers and PCIe cards to be used as professional-grade routers and wifi access point at a low price range? Turris Omnia looks pretty cool but it's really too expensive for non-profits. Is OpenWRT or OPNSense the way to go? Or is there some more generic web dashboard you can run on any GNU/Linux or BSD system…

How about mikrotik, https://mikrotik.com/ I am a satisfied user of their software (and hardware) for the past 10years. If you don't mind the rather rustic interface, it should be as closest to a professional grade cisco as you can get.

Certainly better than Juniper SRXs and Cisco Firepowers, however if you have a lot of mangle rules you'll run into issues. Had a large amounts of drops and even more reorders with just 600M going through a 1036 with c.200 mangle rules.

Haven't run into any issues with Fortigates, yet. Time will tell.

Thats for Firewall/nat/router style devices, for wireless we've got a large number of unify flying saucers. I've use mikrotik wireless in the past, but it's not on the same level at all.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#180
post #176

Earlier quoted context omitted.

Real question not trying to be cute, it's just been 4+ years since I've been inside a company actively using slack. Is that (creds) considered safe/secure these days? Is it common place? I kinda figured slack might get to be a 1password on top of everything else, so it's interesting to hear it's happening.

> Is that (creds) considered safe/secure these days? No, definitely not. It's just super convenient and happens all the time at every organization. The most recent Twitter breach involved a credential shared in a Slack channel. Security teams have a hard time monitoring Slack and the default settings are pretty bad (infinite session length, infinite message retention).

Should there be a chat bot for this? "Hey, I see you just shared a credential, I'll remind you in 5 minutes to delete it, if the message is not deleted I'll alert a member of the security team" kinda thing?
Post reply on HN