Live data from Hacker News

Ubiquiti developer charged with extortion, causing 2020 “breach”

krebsonsecurity.com

61–70 of 239 posts

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#61
post #28

Earlier quoted context omitted.

What is the proper way to ensure 100% bulletproof VPN connections without leakage?

use tor. it's specifically designed to avoid traffic leaks (as long as you don't open an external application). I trust that far more than whatever "killswitch" VPN providers have, or properly implementing a home rolled solution with iptables/network namespaces/raspberry pis. the "bouncing your traffic across 3 servers to obfuscate tracking" is a nice bonus as well.

So few people are actually using Tor that correlation-based traffic analysis has very good odds of revealing identities: get the list of employees, pick out those whose connections have accessed Tor at the time of attacks, and you'll have a very short list of suspects.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#62

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

While I agree this is demonstrative of overall less than adequate security practices, I’m unsurprised that a company that started with making hardware and only later added cloud functionality beyond a website/store was not initially setup as you described. What you described is the sort of setup I’ve been involved in the transition from what Ubiquiti has and what you just described, and it can be quite a lot of work to make that transition, if the industry involved didn’t have regulatory risk management drives, it’s entirely possible that it would have been considered more expensive than it was worth.

Ubiquiti now has public evidence their security posture is inadequate and there will be pressure for them to demonstrate they have changed this situation.

It’s very difficult to completely prevent malicious actors engaging in deliberate efforts to infiltrate and plan actions like this once they have any measure of access and trust. What matters now is how they respond to it.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#63
post #22

Earlier quoted context omitted.

Most come with a killswitch, so if it wonks out you can't access the net.

Are killswitches actually fast enough? Serious question, I don’t know much/anything about networking internals. I never trust killswitches and when I want to ensure I don’t leak anything, I bind to the VPN interface instead, but I don’t know if that actually gives better security?

Speed should not be a problem and hardware solution should not have to be a better solution, ideally. Shame that has to be brought up still.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#64

Earlier quoted context omitted.

Presumably this is an OS-level thing, that it helpfully tries to fall back? If so, I suppose it could be mitigated either by a software control that prevents using the bare connection, or by running the VPN elsewhere, for example on your router. (I see posts elsewhere in the thread now describing how to do this with iptables.)

what I heard some naugthy people say is that one way to deal with these kind of issues is to have two virtual machines, one that connects to the vpn and a second one (without host networking) that can only access internet through the first one. the firewall on the gateway vpc has to be on drop by default and only forward traffic from the 2nd vpc to the vpn interface. the gateway vpc should NEVER provide DHCP or DNS t…

Even if you did that, if I have oversight of the network in a country, like a 5+ eyes level of oversight and you were in a 5+ eyes country, I'd still be able to see where you are and what you would be doing.

Road & Rail networks have a lot in common with digital networks, when you think about it.

Personally I'd have a machine in a foreign country and used that either via an app or friend in front of the machine to do the download(s) with a time delay to avoid obvious links and then sneak it back across the border in bits.

Insecure home networks can be useful, and there is no limit to the number of times and algo's that can be used to encrypt files Russian Doll style.

Foreign country's which do not data share or extradite have their uses, but media like news orgs, Youtube and others can be helpful for establishing what hackers have been extradited. Assume all country's have hackers attacking the US or some other country and then look for missing news stories, YT videos and that sort of thing.

Then look into what relations are like between the two country's and go from there.

If you do your research or homework there shouldnt be any risks.

I dont think the hackers behind this have ever been caught. https://www.bbc.co.uk/iplayer/episode/m0010s10/the-trick

https://web.archive.org/web/20120719071718/http://www.norfol...

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#65
post #61
post #28

Earlier quoted context omitted.

use tor. it's specifically designed to avoid traffic leaks (as long as you don't open an external application). I trust that far more than whatever "killswitch" VPN providers have, or properly implementing a home rolled solution with iptables/network namespaces/raspberry pis. the "bouncing your traffic across 3 servers to obfuscate tracking" is a nice bonus as well.

So few people are actually using Tor that correlation-based traffic analysis has very good odds of revealing identities: get the list of employees, pick out those whose connections have accessed Tor at the time of attacks, and you'll have a very short list of suspects.

where do you get tor usage data? The only time I heard of it being used was when someone used tor on some university's wifi network to send a bomb threat. In that case it would be fairly easy to get the data, but if it's just a random guy using his home internet connection, can you get their ISP to cooperate? do they even keep such data around?

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#66

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

I agree it reflects poorly on the organization, but the previous story on HN [1] mentioned that the malicious insider had scared the CEO into giving access by manufacturing some sort of security incident. Had this not happened, he would not have been able to pull it off IIRC.

That would also point to the CEO being too powerful when it comes to security, which is also a knock against the organization, but in a different way.

[1] https://news.ycombinator.com/item?id=29411775

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#67
post #58

Earlier quoted context omitted.

VPNs are not intended to mask illegal behavior. The assumption is no one will care enough to try to get the real IP. So blatantly breaking the law throws that out the window.

Yeah and I don’t trust that a vpn would really care for my $5 a month or whatever when faced with state actions that if it came to that.

At least one VPN provider did just that

https://torrentfreak.com/private-internet-access-no-logging-...

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#68
post #3

Hopefully this gets upvoted more but it somewhat repairs my view of Ubiquiti's brand now that more details have come out about what actually happened. I hope the courts will determine the full extent of the truth

Aren't they still serial and uncaring GPL violators?

Source for this?

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#69
post #46
post #14

> Investigators say they were able to tie the downloads to Sharp and his work-issued laptop because his Internet connection briefly failed on several occasions while he was downloading the Ubiquiti data. Those outages were enough to prevent Sharp’s Surfshark VPN connection from functioning properly — thus exposing his Internet address as the source of the downloads. Not the first time I’ve read about a VPN unable to…

Proper opsec is you blackhole all traffic when the vpn isn’t active.

Is there a good reason for that to not be the default when using a VPN? At the very least it should be easy to configure. I remember when I tried using a VPN on Ubuntu a bunch of years ago, I had to set up iptables rules even though the VPN connection could be configured through the network manager GUI.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#70

The funny thing is that krebsonsecurity.com are the ones that published the false information in the first place. Good summary of the whole saga by Crosstalk youtube channel which covers mostly Ubiquiti: https://www.youtube.com/watch?v=paLm0tP5GbI

Damn that’s a really bad hire.
Post reply on HN