Live data from Hacker News

Ubiquiti developer charged with extortion, causing 2020 “breach”

krebsonsecurity.com

171–180 of 239 posts

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#171
post #163
post #156

Earlier quoted context omitted.

Is identifying a real person by their internet pseudonym really doxxing?

Krebbs doxxed one of my friends who happens to be a gay hacker in a country where both being gay and being a hacker are illegal. Krebbs doesn’t take kindly to any sort of bad reviews or even the hint that he’s not perfect FYI.

Krebs revealed that your friend is gay?

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#172
post #144

The indictment: https://www.justice.gov/usao-sdny/press-release/file/1452706... Side note: Free suggestion for a new startup. Make indictments pretty! What is it with all these fonts? Looks they really type this on a typewriter. Are all court clerks just frustrated novelists?

I'm waiting for them to follow the footsteps of recipe writers. "It was a frosty December morning, much like the ones I spent with my grandfather up north in my childhood" Just show me the deposition!

Just as long as they don't make you click through fifty digressing interstitials to get to the actual deposition.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#173
post #121

Earlier quoted context omitted.

>Also, for some perspective, at that time Ubiquiti kept all the hardware signing keys in a private GitHub repo that every employee had read access to. And they were in plain-text. So... yeah. This is frankly worse than any of this other news. So there's essentially zero trust associated with the code signatures since any employee, past or present, can sign a payload. Wonderful.

I've since heard that the repo has been taken down and all the keys rotated, but just kinda makes you wonder how many APs and switches and cloud keys, etc are still out there using compromised keys. Also, even though they may have had read access, not many knew it existed. But it wasn't super hard to find (I stumbled across it basically). Oh and then there the whole metrics collection debacle, where the controller ba…

[deleted]

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#174
post #77
post #68

Earlier quoted context omitted.

Source for this?

Latest I can find is this thread: https://news.ycombinator.com/item?id=21450944 I’m not sure if it’s still ongoing, that’s why I asked if it was.

My comment from back then stands.

https://news.ycombinator.com/item?id=21451666

There's also some random community post here: https://community.amplifi.com/topic/3296/gpl-source-code-ava...

They're still in flagrant violation of the license for all the software they're stealing.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#175

Earlier quoted context omitted.

Are killswitches actually fast enough? Serious question, I don’t know much/anything about networking internals. I never trust killswitches and when I want to ensure I don’t leak anything, I bind to the VPN interface instead, but I don’t know if that actually gives better security?

Just setup your routes/firewall so that the only possible way traffic can leave your machine is via the VPN device. VPN dies? no traffic going anywhere. Pretty much networking 101 stuff.

That should be the same when bound to an interface, shouldn’t it?

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#176
post #144

The indictment: https://www.justice.gov/usao-sdny/press-release/file/1452706... Side note: Free suggestion for a new startup. Make indictments pretty! What is it with all these fonts? Looks they really type this on a typewriter. Are all court clerks just frustrated novelists?

As someone who worked (still do) with the legal community and hundreds of lawyers, they are the hardest to change in order to modernize. It's slowly changing, but the older generation would use a bottle of ink and a feather to write if you gave them that.

I'm not from the US, but have met folks from the US. Essentially, the law firms change and digitize, the older institutions such as the courts, will be the last as they are full of people that are much older (judges) than the general workforce, and to them, there is no incentive to change what works, and what is comfortable to them.

Also, they are trained to argue. So you can't just go in there and easily change their mind.

EDIT: They still love to print paper.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#178
post #161

So... do the ubiquity things work again without being tied to their 'cloud'? Fake vulnerability or not, this is the worst part about their devices these days. Speaking of which, are there any semi-pro APs that still work without going through the vendor's servers?

> So... do the ubiquity things work again without being tied to their 'cloud'? Ubiquity works without their "cloud" if you install their management software on your computer (I use a VM on my server). In my experience, you don't even have to run their management software once you have the network configured. If you are paranoid, install their s/w on a VM, set up your network, and then shut down the VM. You should bri…

It does? I have a UniFi and the old admin software just started up and let me admin the boxes.

The new one wants me to register somewhere...

Mind, I haven't checked in 6+ months. I just use the old software I still have on an older machine.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#179
post #163
post #156

Earlier quoted context omitted.

Is identifying a real person by their internet pseudonym really doxxing?

Krebbs doxxed one of my friends who happens to be a gay hacker in a country where both being gay and being a hacker are illegal. Krebbs doesn’t take kindly to any sort of bad reviews or even the hint that he’s not perfect FYI.

Have a link to the story/event?

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#180
post #163

Earlier quoted context omitted.

Krebbs doxxed one of my friends who happens to be a gay hacker in a country where both being gay and being a hacker are illegal. Krebbs doesn’t take kindly to any sort of bad reviews or even the hint that he’s not perfect FYI.

Have a link to the story/event?

It was notdan, and he’s quite open about both of the things I mentioned both on Twitter and his blog.

He is mentioned in this article.

Post reply on HN