Live data from Hacker News

Ubiquiti developer charged with extortion, causing 2020 “breach”

krebsonsecurity.com

151–160 of 239 posts

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#151

Earlier quoted context omitted.

> With wireguard since there is no "connection" to be maintained

What does that even mean? Let's say you have a Wireguard configuration, wg0 which runs off ens0. If your wg0 connection dies, for whatever reason (let's say the remote server goes down), your computer falls back to ens0. What does "not having a connection to be maintained" change about this?

Wireguard will keep contacting the remote server. You'd have to delete the wg0 interface or delete the default route for packets to go out via ens0. Wireguard only has "connection" in a sense that it caches some runtime information about the peer's endpoint, but endpoint configuration is static.

I guess, too much magic automation on top of this is not the best thing for opsec, including having some daemon that can disable your wireguard interface or reconfigure the network if it doesn't like something. You want your network configuration to be static and predictable, regardless of some temporary failures. Basic wireguard kernel primitives will give you that.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#152

Earlier quoted context omitted.

He wasn’t just any dev but the cloud lead.

As a "cloud lead" equivalent I make sure I have as a little access as possible and all my (and everyone else's) actions are logged in an (as much as possible) immutable way. And if anyone managed to log into any AWS account with root credentials (MFA token stored in a safe) we get alerts in GuardDuty, Slack, and email within a couple of minutes. AWS provides all the tools to do this and it does not take that much wor…

As a conman scumbag cloud wouldn't you make sure at have a much access as possible and have none of the actions (and maybe nobody else for extra confusion) logged in (if forced too in a super ephemeral). Root credentials would be stored only in yellow sticky notes.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#153

If he wanted 20 btc all he had to do was put up one of those shitty livestream YouTube scam videos that you always see (Elon Musk was a 2020 favorite). And he would not have been arrested either.

What livestream YouTube scam videos? I've never seen one.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#154

If he wanted 20 btc all he had to do was put up one of those shitty livestream YouTube scam videos that you always see (Elon Musk was a 2020 favorite). And he would not have been arrested either.

What livestream YouTube scam videos? I've never seen one.

Teleshopping except with fake crypto giveaways telling people to send in cryptocurrency to get more back, usually done from hacked accounts. Surprisingly successfull.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#155
post #80

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

Hoo boy, this is gonna be a fun one. For reference, I spent a year (mid-2018 to mid-2019) running the UniFi Network team and worked with Nick during that time. > * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for when an AWS root IAM account is logged in or used, this account should be under lock and key and when…

Wow.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#156

Earlier quoted context omitted.

Wait. So his big "whistleblower" source for this article in April was actually the hacker? https://krebsonsecurity.com/2021/04/ubiquiti-all-but-confirm... Bad on Krebs for not at least mentioning this.

Not surprised TBH. Brian Krebs has a history of questionable ethical behavior, like doxxing people who leave negative reviews on his book[0]. [0]: https://itwire.com/security/infosec-researchers-slam-ex-wapo...

Is identifying a real person by their internet pseudonym really doxxing?

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#157
post #156

Earlier quoted context omitted.

Not surprised TBH. Brian Krebs has a history of questionable ethical behavior, like doxxing people who leave negative reviews on his book[0]. [0]: https://itwire.com/security/infosec-researchers-slam-ex-wapo...

Is identifying a real person by their internet pseudonym really doxxing?

Practically by definition, yes.
Post reply on HN