> Investigators say they were able to [subvert the attacker’s VPN] because his Internet connection briefly failed on several occasions while he was downloading the Ubiquiti data. Those outages were enough to expose his real address. Ahem, how convenient! Call me a paranoid Internet-forum dwelling cyber-loon, but that smells an awful lot like parallel construction. When the authorities log the start and end times of e…
>It feels like a disgruntled and sophisticated Ubiquiti employee is the last person who get caught out by a DNS leak while waiting for their VPN to come back up after a flap.
If it was An-Cheng or Stig I'd agree but given a lot of what Ubiquiti puts out... the bar isn't all that high. Given all of the dumb moves we know he made, it doesn't really surprise me that he would screw up guarding against a VPN dropout. It wouldn't even surprise me if Surfshark screwed up blocking while reconnecting, especially if it was DNS I can see someone making a boneheaded decision to switch name resolution back to the local network while trying to reconnect to lookup the address of the VPN endpoint. It's a consumer VPN, they only really care about hiding from DMCA notices and evading geo-blocks.
Now the Silk Road arrest of Ross Ulbricht on the other hand, that was a travesty of justice. Not that I think he was innocent or shouldn't be in prison, just that in a perfect world many of the prosecutors and federal agents involved would be in a cell beside him.