Live data from Hacker News

Ring LLC home security company ransomed by ALPHV ransomware

web.archive.org

11–20 of 124 posts

Re: Ring LLC home security company ransomed by ALPHV ransomware

#12
I've said it before and I'll say it again:

- Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers.

- I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge this.) (I am not a lawyer, this is not legal advice.)

Software engineers & security engineers can make just about anything secure. But we can only do so if we're given time and money to hire the expertise when needed. We need to make it incredibly expensive for companies to lose personal data like this. Management teams should be clamoring to hire the best security engineers. But they'll only do so if they're sufficiently motivated.

The risk of massive liability is the right incentive to convince companies to invest in getting information security right. The current status quo is ridiculous.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#13
post #12

I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…

> I've said it before and I'll say it again

Don't tell us, tell your legislators. Ideally with some kind of narrative that ties to a financial incentive for the lawmaker and his or her constituents.

If the security industry got together and lobbied for this as both a jobs program (security companies offering services to tech companies) and as a means of protecting Americans/constituents, then it might get somewhere.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#14

This should be interesting. Also, thanks for not making me visit twitter. Edit: because twitter doesn't load on this particular device I use for HN. Basically the browser is too old. There is no "hate" ... ffs

[flagged]

[flagged]

Re: Ring LLC home security company ransomed by ALPHV ransomware

#15
post #12

I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…

This. It would have been (relatively) easy for Ring to encrypt the video data so that they themselves can't access it. Obviously I don't wish it upon the individuals that use these cameras but I would probably smirk if data gets leaked and Amazon gets sued into the ground.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#16

Earlier quoted context omitted.

[flagged]

Because often when you click on a link that goes to Twitter and start reading a thread they will pester you to make an account and won’t let you read the whole thread if you don’t. Also, Elon Musk.

For what it's worth, this behavior has always bothered me hugely (can't read a thread without registering), but disappeared shortly after the last point you cite. Now there is just a nag notification similar to a cookie acceptance bar, you can dismiss it and read the whole thread without interruption:

https://twitter.com/vxunderground/status/1635427567271329792

Let me know if it works for you now. (I have no affiliation to Twitter, just curious.)

Re: Ring LLC home security company ransomed by ALPHV ransomware

#18
post #15
post #12

I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…

This. It would have been (relatively) easy for Ring to encrypt the video data so that they themselves can't access it. Obviously I don't wish it upon the individuals that use these cameras but I would probably smirk if data gets leaked and Amazon gets sued into the ground.

E2E encryption is supported with Ring. You have to enable it yourself. Only discovered this a few weeks ago and immediately enabled it [1]

This doesn't protect your PII data though. This is not a good situation at all.

[1] https://support.ring.com/hc/en-us/articles/360054941511-Unde...

Re: Ring LLC home security company ransomed by ALPHV ransomware

#19

Earlier quoted context omitted.

[flagged]

Because often when you click on a link that goes to Twitter and start reading a thread they will pester you to make an account and won’t let you read the whole thread if you don’t. Also, Elon Musk.

there's also a billion times where i've clicked on a twitter link which is a useless summary and a link to the actual article

Re: Ring LLC home security company ransomed by ALPHV ransomware

#20

Earlier quoted context omitted.

Because often when you click on a link that goes to Twitter and start reading a thread they will pester you to make an account and won’t let you read the whole thread if you don’t. Also, Elon Musk.

For what it's worth, this behavior has always bothered me hugely (can't read a thread without registering), but disappeared shortly after the last point you cite. Now there is just a nag notification similar to a cookie acceptance bar, you can dismiss it and read the whole thread without interruption: https://twitter.com/vxunderground/status/1635427567271329792 Let me know if it works for you now. (I have no affiliat…

Thanks, that’s a nice change then :)
Post reply on HN