Live data from Hacker News

Ubiquiti developer charged with extortion, causing 2020 “breach”

krebsonsecurity.com

231–239 of 239 posts

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#231
post #78

Earlier quoted context omitted.

They should have definitely acknowledged they covered this before. But also to be fair, quoting the article the reputation damage was done: “Following the publication of these articles, between Tuesday, March 30, 2021 and Wednesday March 31”. And the Krebs article was on April 4th. It seems BleepingComputer broke the story and Krebs just re-reported the news.

> And the Krebs article was on April 4th. It seems BleepingComputer broke the story and Krebs just re-reported the news. Kreb's first article was on March 30 https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-b... Kreb's second article was on April 4th https://krebsonsecurity.com/2021/04/ubiquiti-all-but-confirm... BleepingComputer's article didn't come out until the email from Ubiquiti on April 1 and quotes…

Whoops I stand corrected. Wish I could edit my old comment. Looks like Kreb's definitely talked to the guy now indicted in their March 30th article. That makes the complete lack of acknowledgement quite a bit more damning.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#232
post #87

Earlier quoted context omitted.

To be clear, at least ExpressVPN has a "prevent traffic going through outside the VPN" mode which would handle this case, and it's on by default. I am not sure how it's implemented, but it's pretty easy to imagine someone deciding to not use it cuz "it's slow/annoying" or whatever.

That option isn't enough, it works only when the VPN connection is up. If your internet connection is flaky and lose connectivity to the VPN itself, your OS will revert to using its default gateway, and your home IP, which is how the guy got caught. You need your firewall to block any internet access when the VPN is down. I have something like that set up in a Docker container for my torrenting VPN system, so I never…

That's incorrect. If you lose access to the ExpressVPN VPN connection then (while the VPN software is active) you _completely lose access to the internet_, until you disable a switch in the software. You get network errors and the like. at least with the ExpressVPN tool.

This is a proprietary application, not just using the OS-integrated VPN software. Given your comment, I imagine it sets up firewalls.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#233
post #232

Earlier quoted context omitted.

That option isn't enough, it works only when the VPN connection is up. If your internet connection is flaky and lose connectivity to the VPN itself, your OS will revert to using its default gateway, and your home IP, which is how the guy got caught. You need your firewall to block any internet access when the VPN is down. I have something like that set up in a Docker container for my torrenting VPN system, so I never…

That's incorrect. If you lose access to the ExpressVPN VPN connection then (while the VPN software is active) you _completely lose access to the internet_, until you disable a switch in the software. You get network errors and the like. at least with the ExpressVPN tool. This is a proprietary application, not just using the OS-integrated VPN software. Given your comment, I imagine it sets up firewalls.

I don't use ExpressVPN and apparently the guy with Surfshark thought his VPN functioned like this but it didn't. When in doubt, write the firewall rules yourself, especially if you're going criminal.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#234
post #204

Earlier quoted context omitted.

> You assume anyone except the hacker knew anything about AWS. There were a lot of smart and experienced people at Ubiquiti when I worked there. Nick Sharp manipulated his way into total control over everything and wouldn't let anyone outside of his isolated team touch it. Nick was hired out of his job at Amazon because he was supposed to be the AWS expert. He used that to lock out anyone but himself and a trusted te…

> Nick was hired out of his job at Amazon because he was supposed to be the AWS expert. This always cracked me up. From what I can tell, he was a mid level dev on the Alexa web api team. He knew AWS sure, but he did not have the cred at all to justify the position and responsibility he was given at Ubiquiti.

This means the fall in Ubiquiti’s share price was entirely deserved.

Management abdicated its responsibility.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#235

Earlier quoted context omitted.

I'm waiting for them to follow the footsteps of recipe writers. "It was a frosty December morning, much like the ones I spent with my grandfather up north in my childhood" Just show me the deposition!

Just as long as they don't make you click through fifty digressing interstitials to get to the actual deposition.

10 reasons the defendant is not guilty. You won't believe number 6!

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#236

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

> Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? Oh my sweet summer child. You haven't worked in large organizations with thousands of employees before, have you? Surely not if you think this is "Security 101".

Up to and including companies of 100,000 staff, to my current employer of At around ~1,000 staff though you quickly lose "insight" into platform security as it's delegated out to sub-orgs within a larger organisation.

Though I've not worked at any FAANG companies where I'd hope security is... erm, of a certain 'maturity'. E.g. Google and BeyondCorp.

But I've no desire to rehash leet code exams or get back in that space so likely will never go there :).

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#237

Earlier quoted context omitted.

> * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for when an AWS root IAM account is logged in or used, this account should be under lock and key and when used, confirmed and audited by relevant persons or teams. I had never heard of GuardDuty so I got curious. It doesn't seem like there's a free tier available fo…

You're absolutely right. I had not noticed. I'd say this was to do with GuardDuty isn't free but has consistently been such a small line item on my AWS bills that I thought it was free. Thank you for the correction. All the same the point I was trying to drive is when the service is incredibly effective, both in practice and cost, it should in nearly all instances be implemented. Edit: I wanted to amend my statement…

Thanks. This seems like a service that _should_ be free and enabled by default at least with a subset of options for the root account.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#238
post #214
post #138

Earlier quoted context omitted.

> And picture: he could have been the guy who did a great job "fixing" employer's lack of security This is not really a thing. It's very hard to get recognition or even a shared understanding of the risk mitigation. As everything else in the world, it's way easier to reward someone for things that happen (new functionality) than rewarding someone for preventing things happening (hack).

I completely disagree. You may not get recognition with the people at the front desk, but you absolutely can get recognition from your peers inside a company and (as valuable?) people outside the company. Some of this has to be the result of your own work and marketing - conferences, getting clearance to talk about the work you've done (which is good marketing for the company if sold correctly), speaking engagements,…

Classic example of the Do Stuff / Tell People You Did Stuff balance. This stuff is arcane and invisible by default. The coordination and communication tasks that surround the direct work are important.

One was to strike a good balance here is a security roadmap. Write down the adverse outcomes that would be a problem for your business. Write down the possible mitigations, how much they cost to implement and how strong they are. Propose a plan that continuously improves security in a cost effective way. Highlight significant things you can’t defend against yet, and explain how you could address them sooner with more funding. Show the plan to leadership, get it approved, and get to work. Every month / quarter / sprint, write down what you did, show where you are the roadmap, and adjust the roadmap to reflect any changes in business priorities.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#239

Earlier quoted context omitted.

How would one have prevented their IP from leaking?

Used a public wifi access point from a computer bought second hand with cash.

Remember that if law enforcement has to identify you, they have a whole different set of resources most of us don't have – like the ability to go to the coffee shop and also nearby stores and ask for their camera feeds.

And license plate readers (like others have mentioned).

Physical opsec is probably also very hard (I don't know anything about it, I just love those kinds of Hollywood movies).

Post reply on HN