Live data from Hacker News

Former Ubiquiti employee charged with stealing data and extorting company

justice.gov

211–220 of 244 posts

Re: Former Ubiquiti employee charged with stealing data and extorting company

#211
post #13

Mr. Sharp is apparently not so sharp. He carried out the attack from his home network. He connected directly for enough time that his bare IP was logged. The rest of the time, he carried out the attack using a commercially purchased VPN solution that was trivial to trace back to him via the purchase record. He lied to the FBI. (I have yet to understand why people talk to law enforcement instead of staying silent so a…

While I agree that the mistake Mr. Sharp made -- it sounds like he had a network disconnection which briefly caused him to perform actions via his home IP address, rather than his VPN address -- we also don't know everything here. It doesn't sound like the guy was all that sophisticated. Using a VPN provider, in the first place, can make you a whole lot easier to be caught depending on the circumstances/provider trustworthiness/jurisdictions. I recall that there were providers which accepted cryptocurrency, but chances are good if he couldn't figure out how to block all traffic when the VPN was down, he'd have made several mistakes trying to keep the Bitcoin/Ethereum from being traced back to him.

For a crime like this -- as serious as this was, with the damages involved, the company and its internal resources/practices -- he probably had no prayer of getting away with it and in a Dunning-Kruger-like manner, he not only didn't know what he didn't know, I don't think there's any way he could have known enough about his adversary's capabilities to get away with it long term.

If a criminal wishes to be successful in getting away with a serious crime without getting caught over their lifetime, that criminal must successfully thwart detection from all current and future technologies. I mention serious because those crimes often do not have a statute of limitations these days. I'm assuming a perfect law enforcement body that similarly makes no mistakes, so a "luck factor" weighs in, but given a (not too) high-profile crime with motivation, budget, competent investigators and expanding technology, I'll law enforcement is gong to rank higher in the luck category.

It's not enough to look at what they're capable of currently. Consider this scenario: A murderer with Type O+ blood (with other common properties) strangles a man with a wire in 1980 leaving behind only that wire as evidence. In the struggle, the wire also cut the murderers hand and deposited a tiny drop of their blood on it. Being that it was a small item stored for an open case and was well preserved, it's still there, today. Luck. Back in 1980, it was of little evidentiary value. Today, that drop has a good chance of producing a DNA profile. Has the murderer been arrested (not convicted) of a felony in the last few decades? They'll probably be caught. Did a family member use certain (do they all do this?) consumer DNA services? Their family might be found, which will narrow the suspect down to a pool of people. Forget drawing suspicions by getting warrants, because it takes so little biological material and you deposit it everywhere you go, the police just wait for garbage day or follow you around town, grab something that came into contact with your mouth and they've get a profile (which will be used to get an easy warrant for a blood sample to confirm it).

Budding criminals, are you storing all of your secret plans on your drive in a bullet-proof encrypted manner and ensuring that it is airgapped? Are you doing all of your secret research on a similarly configured device, but configured to ensure all networking only works via Tor? Are you sure you didn't make a mistake that couldn't rise to the standards required to get a warrant to image your drive/take your equipment (that's hopefully turned off)? That bullet-proof encryption is rotting, and 30 years from now could represent a small hurdle above plain text.

And what happens when the time required to investigate crimes is reduced further? "We'll get around to bike theft when we're done solving all of the murders." But what if solving a small percentage of the bike thefts went from "complaint" to "likely suspect" almost instantly if certain circumstances were right. For instance, imagine law enforcement could automate geo-fence style warrant requests (requests to get "people in a location at a certain time" from Gooble/Apple/mobile phone provider histories[0]) for every bike theft where the bike was stolen from an area infrequently traveled where and the time of the theft is known to within an hour. For any where the there was exactly one person logged, you have a person of interest -- probably the thief. Not enough evidence to prove a crime, but enough to scare some of the petty thieves into giving up more evidence through questioning (or maybe just give up). It's a stretch, on purpose -- but as technology make solving crimes less costly, less serious crimes will be prosecuted more frequently/reliably.

Full disclosure: My only credentials in this area are working in Corporate Security at a multi-national (large) telecom company for a brief stint and in a security/development capacity for most of my career; except for that brief stint, all of my work has been on the defensive/strategic side, not on the investigative side, and never with violent crimes of any kind. I simply enjoy security topics, in general, but if I've shown my ignorance in a few areas, my apologies and feel free to correct.

[0] Assuming this data is kept long enough; I am going to hazard a guess that it is a lot longer than most people think.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#212
post #98
post #57

Earlier quoted context omitted.

Most people don't understand that they can't explain themselves out of a legal investigation. LEOs exploit this.

Imagine the simple scenario of "someone who looks like you was spotted in area X doing crime Y" and in your pocket you have a receipt that puts many miles away at that time (or something else that would immediately stop you from being a suspect). In what way would "fuck you talk to my lawyer" be helpful?

Watch https://www.youtube.com/watch?v=d-7o9xYp7eE. It gives many such examples, including a very similar scenario than the one you brought up.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#213

Earlier quoted context omitted.

I mean... That is what someone who's setting up a patsy would do if they could. Home networks are not exactly Fort Knox, are they? I had a bunch of rogue connections banging around trying to brute-force database logins within my home LAN earlier this year. I imagine they could have made a connection to a server look like it originated from within my LAN, and if I wasn't watching a live feed of my database connection…

This seems like a series of unfalsifiable claims. Taking evidence linking him to the crime and saying “That is what someone who's setting up a patsy would do” pretty much means anything and everything becomes “proof” of the conspiracy.

> evidence linking him to the crime

keyword is "evidence". Whenever a sympathetic person/cause becomes a target of IP-address based evidence HN is overflowing with posts that IP-address isn't an evidence :)

Re: Former Ubiquiti employee charged with stealing data and extorting company

#214
post #83

A quick search revealed a LinkedIn profile[0] of a previous Ubiquiti employee, he seemed to have left the company in March 2021. I wonder what was first, he quitting his job at Ubiquiti or the FBI Raid. [0] https://www.linkedin.com/in/nickolassharp

Somewhat amusing that he has a new dev job since the incident.

Could be fake. The employer is marked “Confidential.”

Re: Former Ubiquiti employee charged with stealing data and extorting company

#215
post #154

Earlier quoted context omitted.

I’ve finally worked out that people who want something from me, like my company or my software or my expertise, will say whatever they have to say to get a deal - but once the deal is done they just do whatever the hell they want, regardless of what they said. It’s the opposite of what I expect. I can’t deal with it. The people who do this are smart, confident and charismatic. It is clearly a negotiating strategy. Bu…

Thisstory about ebay's attempted takeover of craigslist might interest you. Even before Omidyar stepped down from Craigslist’s board, his appointed agent, Garrett Price, started bullying Craigslist’s owners. In an email to Buckmaster, Price wrote that Craiglist was “driving [eBay’s] execs (especially Meg) to distraction.” He told Buckmaster that eBay’s takeover was “inevitable” and that Craigslist needed to accept th…

That is certainly the nature of things as I’ve experienced them. Thanks for posting this.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#216
post #143

Earlier quoted context omitted.

I’ve finally worked out that people who want something from me, like my company or my software or my expertise, will say whatever they have to say to get a deal - but once the deal is done they just do whatever the hell they want, regardless of what they said. It’s the opposite of what I expect. I can’t deal with it. The people who do this are smart, confident and charismatic. It is clearly a negotiating strategy. Bu…

I sometimes wonder if the snakes learn their craft in some consistent manner (schoolyard politics? non-naive parents?) or if it's mostly instinctual.

Yeah - I wonder that too. I suspect all of the above. Having a privileged education and family contacts probably reinforces it.

From what I’ve seen, openness and honesty are highly regarded in technical work but these traits are considered disadvantages in business.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#217

Earlier quoted context omitted.

Correlation isn't causation, especially with stock prices.

Oh I don't know. news coming out / leaking about a massive data breach, and the stock dropping off it's high _the very same freaking day_ seems like causation, not correlation. But whatever.

Stocks drop for all sorts of reasons, and stuff like breach notifications are routinely swamped by other (often macro) causes. But nerds love to believe that security stories have powerful impacts on stocks, despite the fact that the most successful companies routinely experience them.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#218

Earlier quoted context omitted.

Aruba Instant On. (It's owned by HP) The name is bit misleading though. Especially the first time it can take quite some time for devices to be fully updated and manageable. Regarding support wise: I've had one malfunctioning switch (POE just stopped working) and it was replaced within 24 hours, so that's nice.

Does Aruba instant on allow for multiple VLAN solely for wireless clients by SSID? I love Meraki stuff, so I looked into Meraki Go, and they handicapped Meraki Go by only allowing VLAN for devices with wired connections to the switch. I want the ability to setup a wireless SSID, apply a VLAN to it, and have any wireless devices connected to that SSID be on that VLAN.

https://instanton.club/library/setting-up-aruba-instant-on-1...

Re: Former Ubiquiti employee charged with stealing data and extorting company

#219

Earlier quoted context omitted.

To my knowledge all their switches are fan cooled.

Thank you. Any direct impression on how noisy they are?

I don't really know how to answer that. I ususally put them in (small) server rooms. When they boot they're a lot more noisier than normal operating. The poe versions do make more noise than the non-poe.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#220
post #140
post #124

As a customer, the one thing I really want to know is whether or not the company is dealing with this in a manner that helps me decide if I should continue being a customer. Do they understand that they may need to fire the CEO given that the CEO probably is the weakest link here? Do they have sufficient liquidity and capital to invest in resetting the culture and hiring people who can turn this around?

Are you aware that the CEO owns about 90% of all Ubiquiti shares?

I am now.

Who else offers decent WiFi infrastructure for homes? (And offices)

Post reply on HN