Live data from Hacker News

Ring LLC home security company ransomed by ALPHV ransomware

web.archive.org

91–100 of 124 posts

Re: Ring LLC home security company ransomed by ALPHV ransomware

#91
post #89
post #56

Earlier quoted context omitted.

The analogy is closer to being: the state will prosecute the murder victim's family for failing to properly protect them AND won't be able to locate or punish the true murderer. So in this situation, what's the family going to do? Mourn in private and not report the crime, maybe try for vigilante justice if they think they've identified the murderer.

And not let the community know there is a threat out there.

In this scenario. the community is a danger to the family.

Reporting the murder will see the community punish the family for not protecting the person better.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#92

My personal trust of devices like this is low - and since it is capturing public side recordings (outside my front door) I'm less worried about the vidoes. I just prefer to treat them as untrusted devices and put them on my guest network isolated from the rest of my network.

Apparently quite a few people have Ring cameras inside their homes as well. And another point. You might not think video outside your home matters, but it could be invaluable to burglars who want to know when you're not home. I could imagine it being used to deanonymize location data as well because it would provide known locations and timestamps to filter data against.

I guess?

They can also just park on the street and watch you…

Re: Ring LLC home security company ransomed by ALPHV ransomware

#93

Earlier quoted context omitted.

[flagged]

Because often when you click on a link that goes to Twitter and start reading a thread they will pester you to make an account and won’t let you read the whole thread if you don’t. Also, Elon Musk.

I manage to avoid that by using uMatrix to block scripts, and it's not even supported anymore.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#94
Original Tweet rather than an archived version: https://twitter.com/vxunderground/status/1635427567271329792

There’s since been an important follow-up tweet:

> Ring denies being a victim of ALPHV. Ring has stated to various media outlets they believe a 3rd party vendor has suffered a data breach.

And a relevant reply:

> I mean, file under MRDA, but Ring told me earlier today that "We currently have no indications that Ring has experienced a ransomware event."

Re: Ring LLC home security company ransomed by ALPHV ransomware

#96
We should change the URL to point to the Vice article instead. This is a tweet of a screenshot of the hacker's home page, and while we have no specific reason to disbelieve them, we also have no reason to believe they're telling the whole truth.

The Vice story has more context: Ring denies any compromise to their own systems (and if you can't find the ransomware it's not doing its job very well), but there is a third party vendor with no access to customer data who is currently affected.

https://www.vice.com/en/article/qjvd9q/ransomware-group-clai...

Re: Ring LLC home security company ransomed by ALPHV ransomware

#97
post #92

Earlier quoted context omitted.

Apparently quite a few people have Ring cameras inside their homes as well. And another point. You might not think video outside your home matters, but it could be invaluable to burglars who want to know when you're not home. I could imagine it being used to deanonymize location data as well because it would provide known locations and timestamps to filter data against.

I guess? They can also just park on the street and watch you…

Yes, but doing that is much more risky and time consuming. The burglar could find the basic pattern in a matter of hours rather than days of sitting on the house at the risk of being reported as suspicious. They would also be able to tell which entrances are surveilled and use that information for the burglary itself.

So you could make an argument that woth their terrible security track record, numerous leaks etc Ring is more of a help to potential burglars than it is useful as a security device.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#98
post #68
post #12

I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…

I kinda agree with you but it’s a tough one because what you’re describing is fining the victims of a crime. We don’t fine homeowners who fit cheap locks and get burgled do we. Pragmatically, it might be the right thing to do, but it feels wrong. Would you consider a due diligence to security threshold? That would certainly make it easier the well resourced to weasel out of fines, but when a small startup comes up ag…

> We don’t fine homeowners who fit cheap locks and get burgled do we.

The type of locks you have affect the price of your home insurance, in the UK at least.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#99
post #3

This was always going to happen.. you can't have that much access to sensitive data and expect to be prepared for stuff like this. It's going to be really bad for customers but it's okay. I'm sure we'll get the "We value privacy" compulsory email any day now.

I'm just shocked it happened before all rings become zombies on some botnet. maybe we are just missing the news.

I'm genuinely surprised we haven't had something like that happen....yet. All these "smart" appliances, fridges, & stoves gotta have the same vulnerability just waiting to make them bots. Considering they're all running some old Android instance.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#100
post #64
post #18

Earlier quoted context omitted.

E2E encryption is supported with Ring. You have to enable it yourself. Only discovered this a few weeks ago and immediately enabled it [1] This doesn't protect your PII data though. This is not a good situation at all. [1] https://support.ring.com/hc/en-us/articles/360054941511-Unde...

Run your own camera system with Blue Iris.

That's a nice idea, but Blue Iris in particular, while being affordable and while not requiring a subscription, only runs on Windows. Keeping a Windows system running 24/7 is a whole chore in itself.

Got any suggestions for OSes that are easy to secure and easy to run 24/7?

Post reply on HN