Earlier quoted context omitted.
After reading the article, it's pretty clear that it was credential stuffing and that the writer didn't take the time to understand how it worked. Not sure what security experts they talked to, but credential stuffing absolutely can get all the information described, and the whole part about wifi connected devices is completely unrelated.
> Not sure what security experts they talked to https://www.eff.org/about/staff/cooper-quintin
A Data Leak Exposed the Personal Information of over 3k Ring Users
21–30 of 97 posts
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#22Earlier quoted context omitted.
I'm not making any guesses what actually happened. Just stating that you misrepresented what the article actually said when you wrote "the attack is called credential stuffing". Your sentence gives impression that the article would have said it, but the article made a point for the opposite.
The Amazon spokesperson directly said it was credential stuffing--the article was trying to argue that it was more than that in an extremely misleading way.
Nonetheless, you misrepresented what the article actually said -- the article raised both, the possibility credential stuffing (implied by Amazon spokesperson), and doubt about it (unspecified security expert, WiFi attacks).
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#23Amazon's response seems quite defensive. They are typically a bit black box when it comes to security issues.
Maybe it's because literally every password protected service is vulnerable to users reusing passwords on other insecure sites. It would be like a website writing an expose on how ford trucks are killing hundreds of drivers and expecting a response from ford, but when you read the details it's because users are driving their trucks into brick walls, something that literally every car on the market is susceptible to.
"Ring does not alert users of attempted log-in from an unknown IP address, or tell users how many others are logged into an account at one time. Because of this, there is no obvious way to know whether any bad actors have logged into people’s compromised Ring accounts without their consent."
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#24"Ring does not alert users of attempted log-in from an unknown IP address, or tell users how many others are logged into an account at one time. Because of this, there is no obvious way to know whether any bad actors have logged into people’s compromised Ring accounts without their consent."
I can understand not having 2FA turned on by default, but a bare minimum for this kind of service would be to alert users when someone successfully logs in from a new device.
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#25It's fascinating how Ring's business model benefits from local crime prevalence, which in turn might lead people to invest in home security. It is also fascinating how media companies are likely to pounce on the slightest of flaws(some malignant, and some innocuous) with either Nest or Ring, since it feeds on people's sense of security/safety again, and thus are likely to lead to more clicks.
I wouldn't characterize these flaws as slight. But I'm biased... I used to work in the security space, and I know culturally the typical engineer are less concerned, and non-technical people in the technology sector being fully deferential to product orgs in that respect.
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#26Earlier quoted context omitted.
The Amazon spokesperson directly said it was credential stuffing--the article was trying to argue that it was more than that in an extremely misleading way.
You may be totally right and it was credential stuffing and the article may have been wrong, misleading, incompetent and stupid. Nonetheless, you misrepresented what the article actually said -- the article raised both, the possibility credential stuffing (implied by Amazon spokesperson), and doubt about it (unspecified security expert, WiFi attacks).
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#27This seems important: "Ring does not alert users of attempted log-in from an unknown IP address, or tell users how many others are logged into an account at one time. Because of this, there is no obvious way to know whether any bad actors have logged into people’s compromised Ring accounts without their consent." I can understand not having 2FA turned on by default, but a bare minimum for this kind of service would b…
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#28Even if it was the official article title, "Data Leak" is extremely misleading; the attack is called credential stuffing and is unrelated to any sort of breach on Ring's end. Edit: finished reading the article, and the entire text is just as misleading as the title, credential stuffing happens all the time and really isn't newsworthy.
If we read the same article, we’d have been agreeing that it said it was unlikely to be credential stuffing. > Security experts told BuzzFeed News that the format of the leaked data — which includes username, password, camera name, and time zone in a standardized format — suggests it was taken from a company database. They said data obtained via credential stuffing —when previously-compromised emails and passwords ar…
Why did they add it? Why not? I'm betting when they logged in that info came back as part of the API call.
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#29I'm curious if Ring operates a different security engineering team than the rest of Amazon. Because Amazon.com or AWS would not get hacked; not like this.
They didn't properly defend against credential stuffing attacks. The victims here reused passwords.
Re: A Data Leak Exposed the Personal Information of over 3k Ring Users
#30"of those we spoke to none had been contacted by Ring — contrary to the company’s claim."