Earlier quoted context omitted.
What is the proper way to ensure 100% bulletproof VPN connections without leakage?
use tor. it's specifically designed to avoid traffic leaks (as long as you don't open an external application). I trust that far more than whatever "killswitch" VPN providers have, or properly implementing a home rolled solution with iptables/network namespaces/raspberry pis. the "bouncing your traffic across 3 servers to obfuscate tracking" is a nice bonus as well.
Ubiquiti developer charged with extortion, causing 2020 “breach”
61–70 of 239 posts
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#62For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…
Ubiquiti now has public evidence their security posture is inadequate and there will be pressure for them to demonstrate they have changed this situation.
It’s very difficult to completely prevent malicious actors engaging in deliberate efforts to infiltrate and plan actions like this once they have any measure of access and trust. What matters now is how they respond to it.
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#63Earlier quoted context omitted.
Most come with a killswitch, so if it wonks out you can't access the net.
Are killswitches actually fast enough? Serious question, I don’t know much/anything about networking internals. I never trust killswitches and when I want to ensure I don’t leak anything, I bind to the VPN interface instead, but I don’t know if that actually gives better security?
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#64Earlier quoted context omitted.
Presumably this is an OS-level thing, that it helpfully tries to fall back? If so, I suppose it could be mitigated either by a software control that prevents using the bare connection, or by running the VPN elsewhere, for example on your router. (I see posts elsewhere in the thread now describing how to do this with iptables.)
what I heard some naugthy people say is that one way to deal with these kind of issues is to have two virtual machines, one that connects to the vpn and a second one (without host networking) that can only access internet through the first one. the firewall on the gateway vpc has to be on drop by default and only forward traffic from the 2nd vpc to the vpn interface. the gateway vpc should NEVER provide DHCP or DNS t…
Road & Rail networks have a lot in common with digital networks, when you think about it.
Personally I'd have a machine in a foreign country and used that either via an app or friend in front of the machine to do the download(s) with a time delay to avoid obvious links and then sneak it back across the border in bits.
Insecure home networks can be useful, and there is no limit to the number of times and algo's that can be used to encrypt files Russian Doll style.
Foreign country's which do not data share or extradite have their uses, but media like news orgs, Youtube and others can be helpful for establishing what hackers have been extradited. Assume all country's have hackers attacking the US or some other country and then look for missing news stories, YT videos and that sort of thing.
Then look into what relations are like between the two country's and go from there.
If you do your research or homework there shouldnt be any risks.
I dont think the hackers behind this have ever been caught. https://www.bbc.co.uk/iplayer/episode/m0010s10/the-trick
https://web.archive.org/web/20120719071718/http://www.norfol...
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#65Earlier quoted context omitted.
use tor. it's specifically designed to avoid traffic leaks (as long as you don't open an external application). I trust that far more than whatever "killswitch" VPN providers have, or properly implementing a home rolled solution with iptables/network namespaces/raspberry pis. the "bouncing your traffic across 3 servers to obfuscate tracking" is a nice bonus as well.
So few people are actually using Tor that correlation-based traffic analysis has very good odds of revealing identities: get the list of employees, pick out those whose connections have accessed Tor at the time of attacks, and you'll have a very short list of suspects.
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#66For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…
That would also point to the CEO being too powerful when it comes to security, which is also a knock against the organization, but in a different way.
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#67Earlier quoted context omitted.
VPNs are not intended to mask illegal behavior. The assumption is no one will care enough to try to get the real IP. So blatantly breaking the law throws that out the window.
Yeah and I don’t trust that a vpn would really care for my $5 a month or whatever when faced with state actions that if it came to that.
https://torrentfreak.com/private-internet-access-no-logging-...
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#68Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#69> Investigators say they were able to tie the downloads to Sharp and his work-issued laptop because his Internet connection briefly failed on several occasions while he was downloading the Ubiquiti data. Those outages were enough to prevent Sharp’s Surfshark VPN connection from functioning properly — thus exposing his Internet address as the source of the downloads. Not the first time I’ve read about a VPN unable to…
Proper opsec is you blackhole all traffic when the vpn isn’t active.
Re: Ubiquiti developer charged with extortion, causing 2020 “breach”
#70The funny thing is that krebsonsecurity.com are the ones that published the false information in the first place. Good summary of the whole saga by Crosstalk youtube channel which covers mostly Ubiquiti: https://www.youtube.com/watch?v=paLm0tP5GbI