Earlier quoted context omitted.
Apart from leaks harming the privacy of customers, paying ransoms does social harm by providing an income and incentive to criminals. I found leaked details of Royal Mail's negotiations with their attackers fascinating [0]. I'm not sure it's practical to outlaw the payment of ransoms, but it should at least be heavily taxed (say, 100%). Naively, I would expect this to cut by half the amount that can be extorted throu…
It’s been tried. Laws against paying just make people not report to the police at all.
Ring LLC home security company ransomed by ALPHV ransomware
61–70 of 124 posts
Re: Ring LLC home security company ransomed by ALPHV ransomware
#62Is there any proof of these claims, has Ring confirmed this?
https://www.vice.com/en/article/qjvd9q/ransomware-group-clai...
Re: Ring LLC home security company ransomed by ALPHV ransomware
#63My personal trust of devices like this is low - and since it is capturing public side recordings (outside my front door) I'm less worried about the vidoes. I just prefer to treat them as untrusted devices and put them on my guest network isolated from the rest of my network.
And another point. You might not think video outside your home matters, but it could be invaluable to burglars who want to know when you're not home. I could imagine it being used to deanonymize location data as well because it would provide known locations and timestamps to filter data against.
Re: Ring LLC home security company ransomed by ALPHV ransomware
#64Earlier quoted context omitted.
This. It would have been (relatively) easy for Ring to encrypt the video data so that they themselves can't access it. Obviously I don't wish it upon the individuals that use these cameras but I would probably smirk if data gets leaked and Amazon gets sued into the ground.
E2E encryption is supported with Ring. You have to enable it yourself. Only discovered this a few weeks ago and immediately enabled it [1] This doesn't protect your PII data though. This is not a good situation at all. [1] https://support.ring.com/hc/en-us/articles/360054941511-Unde...
Re: Ring LLC home security company ransomed by ALPHV ransomware
#65Re: Ring LLC home security company ransomed by ALPHV ransomware
#66Leaking user data isn't really penalized enough. First two incidents, high monetary penalty, third incident, company is closed permanently in the interest of public security.
>company is closed permanently in the interest of public security. So there goes a janitors job, secretaries etc. Local cafes, bars, transport lose out. The dependents of all the company are now involved. There's a long chain of consequences after this. Why not just target the guilty: maybe any punishment should make them suffer.
Regardless, plenty of places need janitors and the likes. They'll find other jobs.
Re: Ring LLC home security company ransomed by ALPHV ransomware
#67I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…
Apart from leaks harming the privacy of customers, paying ransoms does social harm by providing an income and incentive to criminals. I found leaked details of Royal Mail's negotiations with their attackers fascinating [0]. I'm not sure it's practical to outlaw the payment of ransoms, but it should at least be heavily taxed (say, 100%). Naively, I would expect this to cut by half the amount that can be extorted throu…
> LockBit refused to accept the explanation and accused the company’s negotiator of “bluffing”, speculating that the company’s directors probably held £100m of cryptocurrency personally that could “finish this nightmare”.
Re: Ring LLC home security company ransomed by ALPHV ransomware
#68I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…
Pragmatically, it might be the right thing to do, but it feels wrong. Would you consider a due diligence to security threshold? That would certainly make it easier the well resourced to weasel out of fines, but when a small startup comes up against a well resourced nation state level hackers with a catalogue of 0days what are they supposed to do? Just go out of business?
Re: Ring LLC home security company ransomed by ALPHV ransomware
#69Earlier quoted context omitted.
In the next episodes: - Why so expensive? - Where did all businesses go? - Let’s create a certified secure data enclave companies! - Why so expensive still? - We can’t charge a certified company because it would damage half the economy!
You can translate this to any kind of regulation. Want cars not to explode when slightly rear-ended? Why are they so expensive now? Where did the car businesses go? Let's create car security companies! Why so expensive still? ...
I can't make a car company. I can make a webcam on doors company.
And you might say it is about raw materials. But I can buy enough materials for one car and one webcam door. I can't put the car on the road (as much as it make sense) only because of the sheer amount of cost required to pass regulations.
So while regulation is something we want as costumers. I think we'd prefer to not have it become a obstacle in the software sector to the point it exist elsewhere.
That is why I think the GDPR is great since it applies to companies with 250+ employs.
Re: Ring LLC home security company ransomed by ALPHV ransomware
#70Is this the same Ring that was giving away video to the police with no warrant? Seems more like a home insecurity company to me. And why is it an LLC?