Live data from Hacker News

Ubiquiti developer charged with extortion, causing 2020 “breach”

krebsonsecurity.com

181–190 of 239 posts

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#181

> Investigators say they were able to [subvert the attacker’s VPN] because his Internet connection briefly failed on several occasions while he was downloading the Ubiquiti data. Those outages were enough to expose his real address. Ahem, how convenient! Call me a paranoid Internet-forum dwelling cyber-loon, but that smells an awful lot like parallel construction. When the authorities log the start and end times of e…

I'm generally quite suspicious of lying law enforcement covering up evidence collected via illegal and inadmissible methods, but I doubt that's the case here. Rather than use Tor he decided to just wing it and use his personal consumer VPN that was paid for with his own PayPal account. He used his own credentials for the "hack" and didn't even come up with an excuse for how that could have plausibly happened other than "lol it was AWS that got hacked".

>It feels like a disgruntled and sophisticated Ubiquiti employee is the last person who get caught out by a DNS leak while waiting for their VPN to come back up after a flap.

If it was An-Cheng or Stig I'd agree but given a lot of what Ubiquiti puts out... the bar isn't all that high. Given all of the dumb moves we know he made, it doesn't really surprise me that he would screw up guarding against a VPN dropout. It wouldn't even surprise me if Surfshark screwed up blocking while reconnecting, especially if it was DNS I can see someone making a boneheaded decision to switch name resolution back to the local network while trying to reconnect to lookup the address of the VPN endpoint. It's a consumer VPN, they only really care about hiding from DMCA notices and evading geo-blocks.

Now the Silk Road arrest of Ross Ulbricht on the other hand, that was a travesty of justice. Not that I think he was innocent or shouldn't be in prison, just that in a perfect world many of the prosecutors and federal agents involved would be in a cell beside him.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#182
post #80

Earlier quoted context omitted.

Hoo boy, this is gonna be a fun one. For reference, I spent a year (mid-2018 to mid-2019) running the UniFi Network team and worked with Nick during that time. > * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for when an AWS root IAM account is logged in or used, this account should be under lock and key and when…

This is all pretty damning. What would you use at home instead?

That’s the real question. Aruba has some relevant offerings, but UniFi is still pretty unique in what it offers to prosumers.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#183
post #78

Earlier quoted context omitted.

Wait. So his big "whistleblower" source for this article in April was actually the hacker? https://krebsonsecurity.com/2021/04/ubiquiti-all-but-confirm... Bad on Krebs for not at least mentioning this.

They should have definitely acknowledged they covered this before. But also to be fair, quoting the article the reputation damage was done: “Following the publication of these articles, between Tuesday, March 30, 2021 and Wednesday March 31”. And the Krebs article was on April 4th. It seems BleepingComputer broke the story and Krebs just re-reported the news.

> And the Krebs article was on April 4th. It seems BleepingComputer broke the story and Krebs just re-reported the news.

Kreb's first article was on March 30 https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-b...

Kreb's second article was on April 4th https://krebsonsecurity.com/2021/04/ubiquiti-all-but-confirm...

BleepingComputer's article didn't come out until the email from Ubiquiti on April 1 and quotes Kreb's article on March 30

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#184
post #180

Earlier quoted context omitted.

Have a link to the story/event?

It was notdan, and he’s quite open about both of the things I mentioned both on Twitter and his blog. He is mentioned in this article.

[flagged]

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#185

Earlier quoted context omitted.

He wasn’t just any dev but the cloud lead.

As a "cloud lead" equivalent I make sure I have as a little access as possible and all my (and everyone else's) actions are logged in an (as much as possible) immutable way. And if anyone managed to log into any AWS account with root credentials (MFA token stored in a safe) we get alerts in GuardDuty, Slack, and email within a couple of minutes. AWS provides all the tools to do this and it does not take that much wor…

If you wanted to though, I’m sure you could figure out a way to get around this to exfiltrate data and simulate a “hack”. If Snowden could leak NSA data, what hope do you have of securing your company’s data from a nefarious person in a leadership position?

Is it possible, technically yes, but the level of paranoia and mistrust required to prevent this kind of thing is never going to be supported by leadership or other engineers trying to do their jobs.

Should you lock up your root key effectively like you describe? Absolutely. Should you do other things to restrict access to sensitive data? Absolutely. But whatever you do, you’re not going to be able to avoid a sophisticated internal attacker without making normal work extremely difficult.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#186
post #180

Earlier quoted context omitted.

It was notdan, and he’s quite open about both of the things I mentioned both on Twitter and his blog. He is mentioned in this article.

[flagged]

That’s pretty shitty of him. I’m not saying anyone is a saint, only that krebs doxxes people who disagree with him, which can put their lives in direct harm. I’m not any more of a fan of wee ve than you.

Also, fuck Nazis.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#187
Hmm, where have I seen this before...

Oh, I know.

Sergey Aleynikov says "Hi."

His case was less about extortion, and more just grabbing what he could on the way out the door, but it was sloppy.

Sharp obviously never learned Goldman Corp. Comm. Rule #1:

"Don't talk to the press"

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#188
If anyone is looking for the alternative to Ubiquiti since their fall from grace in recent years, I've found it to be HP Aruba. I always use more open source stuff for personal projects, but Aruba Instant On is what I commonly recommend/integrate for other people, whereas it used to be Ubiquiti. Solid design across hardware and software. It finds that unique balance in quality/usability between cheap/unreliable, and overcomplicated enterprise.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#189
post #156

Earlier quoted context omitted.

Not surprised TBH. Brian Krebs has a history of questionable ethical behavior, like doxxing people who leave negative reviews on his book[0]. [0]: https://itwire.com/security/infosec-researchers-slam-ex-wapo...

Is identifying a real person by their internet pseudonym really doxxing?

Yes, linking the two (public and private) identities is doxxing, because... it links the two.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#190
post #7

Earlier quoted context omitted.

Assuming you're talking about corporate VPN: not using VPN. Things like BeyondCorp. And obviously take away access once that person left the company. https://beyondcorp.com/ https://cloud.google.com/beyondcorp/

This has nothing to do with a company-supplied VPN. This person was an employee using a third party VPN specifically to hide his identity from Ubiquiti.

On his work laptop, lol.
Post reply on HN