Live data from Hacker News

Ring LLC home security company ransomed by ALPHV ransomware

web.archive.org

111–120 of 124 posts

Re: Ring LLC home security company ransomed by ALPHV ransomware

#111

Ring sounds like such a neat idea. I'm in bed and I heard a noise at the front door...I open the app...start live view...black screen Really? Is it that hard? The extension ringer is a great idea too. Place it wherever you will hear it...ding-dong...there was someone at your door about 20-30 seconds ago. Seriously! A doorbell with a camera, the camera won't connect, the bell won't ring

Even my beloved Ubiquiti's doorbell cam suffers in much the same ways (and my nest had it too). There must be some difficulty here that is non-obvious for all the competitors to be falling into the same flaws.

I personally blame Unifi's SSO for a lot of the slugishness. My old Reolink (1/3rd the price of Unifi's offerings) was instant when loaded and connected via IP+port.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#112
post #81
post #69

Earlier quoted context omitted.

I think your example just fortified his comment. I can't make a car company. I can make a webcam on doors company. And you might say it is about raw materials. But I can buy enough materials for one car and one webcam door. I can't put the car on the road (as much as it make sense) only because of the sheer amount of cost required to pass regulations. So while regulation is something we want as costumers. I think we'…

>So while regulation is something we want as costumers. I think we'd prefer to not have it become a obstacle in the software sector to the point it exist elsewhere. Alternatively looked in the metaphor, cars are dangerous things - for the passengers and civilians nearby. We as a society don't want any random vehicle to be on the road due to the risks involved. A webcam door doesn't have this type of risk associated,…

> No it doesn't

Well I guess I fell into this myth:

https://www.vistra.com/insights/if-i-have-fewer-250-members-...

Which do give some exemption to <250 people companies but not to an extent that I said.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#113
post #69

Earlier quoted context omitted.

You can translate this to any kind of regulation. Want cars not to explode when slightly rear-ended? Why are they so expensive now? Where did the car businesses go? Let's create car security companies! Why so expensive still? ...

I think your example just fortified his comment. I can't make a car company. I can make a webcam on doors company. And you might say it is about raw materials. But I can buy enough materials for one car and one webcam door. I can't put the car on the road (as much as it make sense) only because of the sheer amount of cost required to pass regulations. So while regulation is something we want as costumers. I think we'…

i am only glad that you arent selling cars without safety tests.

i would also be glad that not anyone would make a air traffic control or a train signaling system.

while i like foss programs and have low barriers of entry in any field, there needs to be a minimal standard that everyone shoud adhere to where a system failure could affect someones life beyond minor inconvenience.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#114

Earlier quoted context omitted.

That's a nice idea, but Blue Iris in particular, while being affordable and while not requiring a subscription, only runs on Windows. Keeping a Windows system running 24/7 is a whole chore in itself. Got any suggestions for OSes that are easy to secure and easy to run 24/7?

Frigate, optionally with Home Assistant. Exceptionally reliable for the two years I've used it.

I rolled my own system, initially with MotionEye, and then rolled over to Frigate. I appreciate the extra object detection feature in MotionEye, whereas MotionEye really only records on, well, motion. Even with two 720P streams, I'm able to do motion detection and object recognition on an ancient Core2Duo Mac Mini, no TPU.

No data leaves my LAN unless I want it to.

The most painful part of the whole process was the YAML files for Frigate.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#115
post #44
post #35

Earlier quoted context omitted.

E2E encryption only protects the data while it is in transmission. If there is a breach, all of your data is accessible because it is decrypted at the endpoint.

Thats not what E2E encryption means. Encryption during transmission is called transport layer encryption (eg via TLS). E2E (end to end) encryption is encryption where the data is encrypted in transit and at rest. Generally E2E systems only have the keys to decrypt the data on the user's (endpoint) device.

Thanks for your comment. I truly had no idea.

This was very informative and changes my views on a few things.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#116

Earlier quoted context omitted.

I'm genuinely surprised we haven't had something like that happen....yet. All these "smart" appliances, fridges, & stoves gotta have the same vulnerability just waiting to make them bots. Considering they're all running some old Android instance.

It has happened. Lots of these devices ARE on botnets. I think it was cloudflare who claimed a significant amount of DDoS traffic comes from hacked IOT devices

midori. it was mostly modems. haven't heard about the security cameras yet.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#117
post #18
post #15

Earlier quoted context omitted.

This. It would have been (relatively) easy for Ring to encrypt the video data so that they themselves can't access it. Obviously I don't wish it upon the individuals that use these cameras but I would probably smirk if data gets leaked and Amazon gets sued into the ground.

E2E encryption is supported with Ring. You have to enable it yourself. Only discovered this a few weeks ago and immediately enabled it [1] This doesn't protect your PII data though. This is not a good situation at all. [1] https://support.ring.com/hc/en-us/articles/360054941511-Unde...

They should be required by law to provide offline access to your stream, RTSP or something similar.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#118

This should be interesting. Also, thanks for not making me visit twitter. Edit: because twitter doesn't load on this particular device I use for HN. Basically the browser is too old. There is no "hate" ... ffs

If Twitter doesn't work (well), I recommend nitter.net (or other instances of Nitter, it's open source software). Addons are available for various browsers to automatically redirect. Nitter is meant as a privacy-friendly Twitter front-end, but I mainly use it because Twitter takes literal seconds to load a 280 character post and Nitter works almost instantly. As an added bonus, it doesn't rely on Javascript to render…

Thank you men. I knew about it. But it didn't always work..

Re: Ring LLC home security company ransomed by ALPHV ransomware

#119

Ring sounds like such a neat idea. I'm in bed and I heard a noise at the front door...I open the app...start live view...black screen Really? Is it that hard? The extension ringer is a great idea too. Place it wherever you will hear it...ding-dong...there was someone at your door about 20-30 seconds ago. Seriously! A doorbell with a camera, the camera won't connect, the bell won't ring

I've worked professionally with wifi equipment and my take on the whole deal is this: if it's on wifi, it will fail not as frequent enough to be replaced by something better, but often enough to be make you miserable.

Yes, $1000 phones work fine, but every other device? the standard must be a mess because every other wifi certified device is unreliable.

Everything on my house that can be wired, is wired.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#120
post #12

I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…

Apart from leaks harming the privacy of customers, paying ransoms does social harm by providing an income and incentive to criminals. I found leaked details of Royal Mail's negotiations with their attackers fascinating [0]. I'm not sure it's practical to outlaw the payment of ransoms, but it should at least be heavily taxed (say, 100%). Naively, I would expect this to cut by half the amount that can be extorted throu…

If an organization pays a ransom, I consider that organization to be effectively in league with the criminals, and avoid doing any business with them in the future.
Post reply on HN