Live data from Hacker News

Former Ubiquiti employee charged with stealing data and extorting company

justice.gov

191–200 of 244 posts

Re: Former Ubiquiti employee charged with stealing data and extorting company

#191

Earlier quoted context omitted.

Alas not true. The higher your market cap, the more money you can raise by printing more stocks.

By the time you're publicly traded you're not looking to raise money via equity as you have excellent access to loans by that point. You're not talking about a startup that can't get a loan.

These loans are often convertible bonds so the stock performance does impact the companies access to low interest rates.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#192

I do that that the media that breathlessly amplified this persons attack should learn from it. In particular, As much as I like and appreciate his reporting, Brian Krebs was the key person amplifying this message - which makes him a unwitting accomplice to many billions of dollars of damage to ubiquiti shareholders. Responsible disclosure exists for a reason.

What's really unproven here is the idea that Ubiquiti lost billion of dollars in stock value over these messages. Seems pretty unlikely.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#193

Earlier quoted context omitted.

Aruba Instant On. (It's owned by HP) The name is bit misleading though. Especially the first time it can take quite some time for devices to be fully updated and manageable. Regarding support wise: I've had one malfunctioning switch (POE just stopped working) and it was replaced within 24 hours, so that's nice.

Are their 10GbE switches fan-cooled? I really would like a quiet device for a bedroom.

I have a 16 port 10 gbit Ubiquiti switch, and it has fans. But they only ever spin up when I (re)boot the device.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#194
post #110

Earlier quoted context omitted.

1. You don't have to say it aggressively. Politely say, "I need to talk to my lawyer before answering questions." 2. “The suspect conveniently had a receipt in their pocket placing them elsewhere at the exact time of the Y crime. It was the only receipt in his pocket! Seems suspicious to me. He plainly engineered the alibi.” 3. There's no reason you have to immediately begin demonstrating your innocence. It can wait…

You mistook my assertiveness for aggression :) And let's assume it's not just the only receipt you happen to have in your house. Anyway, real life example - police calls me up saying this number came up in an investigation, who are you and a few more other questions. They were obviously expecting me to cooperate cause they hadn't bothered to do the paperwork to obtain my identity which was tied to the number. First t…

> Anyway my point is - don't you think me lawyering up for this would have been absurd?

Isn’t this just hindsight bias? What if the situation wasn’t your mother’s absentmindedness but your number being found in the phone of a murder victim? The “back and forth” with the officer leads you to confirm that you know and have visited the small town where this person was killed. So they ask you if you have ever visited the window tinting shop where they work, and you say no. What you don’t know if an eye witness incorrectly believes they saw you there, which makes you a liar in the LEO’s eyes.

This issue isn’t “what if it turns out to be nothing”. The issue is that if it does turn out to be something, the consequences of not keeping your mouth shut are far worse than the minor “over reaction” when things end up being ok. Its like wearing a seat belt. You don’t do it for all the times you don’t get in an accident. You wear it because the consequences are dire in the case that you do get in an accident.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#195
post #180

Earlier quoted context omitted.

> Is that (creds) considered safe/secure these days? No, definitely not. It's just super convenient and happens all the time at every organization. The most recent Twitter breach involved a credential shared in a Slack channel. Security teams have a hard time monitoring Slack and the default settings are pretty bad (infinite session length, infinite message retention).

Should there be a chat bot for this? "Hey, I see you just shared a credential, I'll remind you in 5 minutes to delete it, if the message is not deleted I'll alert a member of the security team" kinda thing?

Ideally shouldn't the credential be rolled even if you delete the message?

Unless slack hard deletes messages, but my guess would be soft deletion. Even then it's not really designed for sending sensitive credentials

Re: Former Ubiquiti employee charged with stealing data and extorting company

#196
post #72

Earlier quoted context omitted.

Are you saying that someone purchased a VPN account using his PayPal account and by sheer coincidence, while that said VPN account was in middle of data exfiltration, his home IP address also connected to said servers with no connection to the exfiltration?

I mean... That is what someone who's setting up a patsy would do if they could. Home networks are not exactly Fort Knox, are they? I had a bunch of rogue connections banging around trying to brute-force database logins within my home LAN earlier this year. I imagine they could have made a connection to a server look like it originated from within my LAN, and if I wasn't watching a live feed of my database connection…

This seems like a series of unfalsifiable claims. Taking evidence linking him to the crime and saying “That is what someone who's setting up a patsy would do” pretty much means anything and everything becomes “proof” of the conspiracy.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#197

I do that that the media that breathlessly amplified this persons attack should learn from it. In particular, As much as I like and appreciate his reporting, Brian Krebs was the key person amplifying this message - which makes him a unwitting accomplice to many billions of dollars of damage to ubiquiti shareholders. Responsible disclosure exists for a reason.

What's really unproven here is the idea that Ubiquiti lost billion of dollars in stock value over these messages. Seems pretty unlikely.

The stock definitely was at a peak, and fell dramatically on the release of that news and stayed low. That part is absolutely correct. Now you can argue that it wasn't a permanent loss, but the damage was done by the hacker and the journalist.

It has also stayed relatively in that range afterwards - but you can definitely argue that this is due to the supply chain problems that the entire world is dealing with - but it's a pretty straight line to say that billions in shareholder value were wiped out.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#198
post #61

Earlier quoted context omitted.

Brian Krebs isn't a good reporter or a good person. He has a history of doxxing people without basis (or for the basis of leaving bad reviews on his books). It disappoints me that he has the audience he does.

He's a reporter. "Doxxing" isn't a thing in journalism, even though it upsets people on message boards to hear it.

doxxing is doxxing. Don't care if the media think they are special.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#199
post #180

Earlier quoted context omitted.

Should there be a chat bot for this? "Hey, I see you just shared a credential, I'll remind you in 5 minutes to delete it, if the message is not deleted I'll alert a member of the security team" kinda thing?

Ideally shouldn't the credential be rolled even if you delete the message? Unless slack hard deletes messages, but my guess would be soft deletion. Even then it's not really designed for sending sensitive credentials

Slack has no concept of a hard delete. There's always a record, as far as I know.

So yes, you'll want to: 1. Delete the message 2. Revoke the token 3. Notify the user/ security operations team

Re: Former Ubiquiti employee charged with stealing data and extorting company

#200

Earlier quoted context omitted.

What's really unproven here is the idea that Ubiquiti lost billion of dollars in stock value over these messages. Seems pretty unlikely.

The stock definitely was at a peak, and fell dramatically on the release of that news and stayed low. That part is absolutely correct. Now you can argue that it wasn't a permanent loss, but the damage was done by the hacker and the journalist. It has also stayed relatively in that range afterwards - but you can definitely argue that this is due to the supply chain problems that the entire world is dealing with - but…

Correlation isn't causation, especially with stock prices.
Post reply on HN