Earlier quoted context omitted.
What is the proper way to ensure 100% bulletproof VPN connections without leakage?
Assuming you're talking about corporate VPN: not using VPN. Things like BeyondCorp. And obviously take away access once that person left the company. https://beyondcorp.com/ https://cloud.google.com/beyondcorp/
Ubiquiti developer charged with extortion, causing 2020 “breach”
11–20 of 239 posts
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#12I wonder why the developer had access to so many resources on AWS and GitHub? Can’t these excessive permissions be removed? Why it was undetected for such long time?
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#13Hopefully this gets upvoted more but it somewhat repairs my view of Ubiquiti's brand now that more details have come out about what actually happened. I hope the courts will determine the full extent of the truth
Aren't they still serial and uncaring GPL violators?
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#14Not the first time I’ve read about a VPN unable to mask someone’s ip when they were on a wonky connection.
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#15> Investigators say they were able to tie the downloads to Sharp and his work-issued laptop because his Internet connection briefly failed on several occasions while he was downloading the Ubiquiti data. Those outages were enough to prevent Sharp’s Surfshark VPN connection from functioning properly — thus exposing his Internet address as the source of the downloads. Not the first time I’ve read about a VPN unable to…
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#16Ahem, how convenient! Call me a paranoid Internet-forum dwelling cyber-loon, but that smells an awful lot like parallel construction.
When the authorities log the start and end times of every TCP session at both ends they don’t need a VPN leak to correlate traffic corresponding to “GET /secrets” from the client with a response from the server.
It feels like a disgruntled and sophisticated Ubiquiti employee is the last person who get caught out by a DNS leak while waiting for their VPN to come back up after a flap.
On the other hand, I guess if you’re crazy enough to behave this criminally, you can be forgiven at least for not thinking straight in terms of opsec.
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#17> Investigators say they were able to tie the downloads to Sharp and his work-issued laptop because his Internet connection briefly failed on several occasions while he was downloading the Ubiquiti data. Those outages were enough to prevent Sharp’s Surfshark VPN connection from functioning properly — thus exposing his Internet address as the source of the downloads. Not the first time I’ve read about a VPN unable to…
(I see posts elsewhere in the thread now describing how to do this with iptables.)
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#18> Investigators say they were able to tie the downloads to Sharp and his work-issued laptop because his Internet connection briefly failed on several occasions while he was downloading the Ubiquiti data. Those outages were enough to prevent Sharp’s Surfshark VPN connection from functioning properly — thus exposing his Internet address as the source of the downloads. Ouch! Opsec is very easy to screw up.
What is the proper way to ensure 100% bulletproof VPN connections without leakage?
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#19Earlier quoted context omitted.
What is the proper way to ensure 100% bulletproof VPN connections without leakage?
Assuming you're talking about corporate VPN: not using VPN. Things like BeyondCorp. And obviously take away access once that person left the company. https://beyondcorp.com/ https://cloud.google.com/beyondcorp/
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#20> Investigators say they were able to tie the downloads to Sharp and his work-issued laptop because his Internet connection briefly failed on several occasions while he was downloading the Ubiquiti data. Those outages were enough to prevent Sharp’s Surfshark VPN connection from functioning properly — thus exposing his Internet address as the source of the downloads. Not the first time I’ve read about a VPN unable to…
This doesn't sound too good for VPN users