Live data from Hacker News

A Data Leak Exposed the Personal Information of over 3k Ring Users

buzzfeednews.com

31–40 of 97 posts

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#31
post #5

Even if it was the official article title, "Data Leak" is extremely misleading; the attack is called credential stuffing and is unrelated to any sort of breach on Ring's end. Edit: finished reading the article, and the entire text is just as misleading as the title, credential stuffing happens all the time and really isn't newsworthy.

> credential stuffing happens all the time and really isn't newsworthy.

If a bad thing happens all the time and people are unaware of it, calling attention to it is entirely newsworthy.

To you, as a jaded security person who understands that there are systemic risks to any network-connected service and nobody is good at defending against them, perhaps it's perfectly normal. To a customer who is making the decision between buying a network-connected doorbell for their security and buying a perfectly normal offline doorbell, the fact that credential stuffing happens all the time is a thing they need to hear about!

(Also, there are straightforward ways to resist these attacks, such as "You must use 2FA," "You can only pair a new device with your Ring account while it's in physical proximity to your Ring device," "You must use either 2FA or physical proximity," "The app will generate a password for you and won't let you use an existing one, feel free to write it down on a piece of paper," etc. A home security system should be more paranoid than a politics forum or a meme generator at keeping accounts secure.)

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#32

Earlier quoted context omitted.

I'm not making any guesses what actually happened. Just stating that you misrepresented what the article actually said when you wrote "the attack is called credential stuffing". Your sentence gives impression that the article would have said it, but the article made a point for the opposite.

The Amazon spokesperson directly said it was credential stuffing--the article was trying to argue that it was more than that in an extremely misleading way.

It's in Amazon's interest to argue that it wasn't a failing on their part.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#33
post #19

Earlier quoted context omitted.

After reading the article, it's pretty clear that it was credential stuffing and that the writer didn't take the time to understand how it worked. Not sure what security experts they talked to, but credential stuffing absolutely can get all the information described, and the whole part about wifi connected devices is completely unrelated.

> Not sure what security experts they talked to https://www.eff.org/about/staff/cooper-quintin

And here is his take on it. https://twitter.com/cooperq/status/1207780461834977281

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#34

Earlier quoted context omitted.

You may be totally right and it was credential stuffing and the article may have been wrong, misleading, incompetent and stupid. Nonetheless, you misrepresented what the article actually said -- the article raised both, the possibility credential stuffing (implied by Amazon spokesperson), and doubt about it (unspecified security expert, WiFi attacks).

Calling out an article for being misleading is not the same as misrepresenting it.

Yes they are different, and you did both: called it out for being misleading, and simultaneously misrepresented what it actually said (I've already detailed the reasons above, and others have quoted them verbatim to you).

The best before date of this conversation has clearly expired, so let's just stop here.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#35

Earlier quoted context omitted.

If we read the same article, we’d have been agreeing that it said it was unlikely to be credential stuffing. > Security experts told BuzzFeed News that the format of the leaked data — which includes username, password, camera name, and time zone in a standardized format — suggests it was taken from a company database. They said data obtained via credential stuffing —when previously-compromised emails and passwords ar…

This is a credential stuffing attack. Why did they add it? Why not? I'm betting when they logged in that info came back as part of the API call.

> Why did they add it?

If they were going to sell the information, and the credentials really allowed to remotely access the cameras, then accessing 'camera=BEDROOM' at 11PM Friday local time may provide more entertainment value than 'camera=GARAGE'? :)

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#36

This seems important: "Ring does not alert users of attempted log-in from an unknown IP address, or tell users how many others are logged into an account at one time. Because of this, there is no obvious way to know whether any bad actors have logged into people’s compromised Ring accounts without their consent." I can understand not having 2FA turned on by default, but a bare minimum for this kind of service would b…

Due to the overwhelmingly high amount of attempted fraud in grey/black market VoIP stuff, it's pretty common for wholesale SIP trunking providers to now alert the account owner whenever the web account control panel is logged into from a new, unknown ISP and/or useragent.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#37
post #31
post #5

Even if it was the official article title, "Data Leak" is extremely misleading; the attack is called credential stuffing and is unrelated to any sort of breach on Ring's end. Edit: finished reading the article, and the entire text is just as misleading as the title, credential stuffing happens all the time and really isn't newsworthy.

> credential stuffing happens all the time and really isn't newsworthy. If a bad thing happens all the time and people are unaware of it, calling attention to it is entirely newsworthy. To you, as a jaded security person who understands that there are systemic risks to any network-connected service and nobody is good at defending against them, perhaps it's perfectly normal. To a customer who is making the decision be…

I really hope physical proximity is also some kind of handshake with the device, and not spoofable in-app "GPS"

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#38
post #5

Even if it was the official article title, "Data Leak" is extremely misleading; the attack is called credential stuffing and is unrelated to any sort of breach on Ring's end. Edit: finished reading the article, and the entire text is just as misleading as the title, credential stuffing happens all the time and really isn't newsworthy.

I think your objection is misplaced. It doesn't matter where the credentials came from if there's a list out there that targets Ring accounts.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#39
post #33
post #19

Earlier quoted context omitted.

> Not sure what security experts they talked to https://www.eff.org/about/staff/cooper-quintin

And here is his take on it. https://twitter.com/cooperq/status/1207780461834977281

I really wish this was included in the article, his conclusion makes a lot more sense in that context (though I still disagree with it).

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#40
post #5

Even if it was the official article title, "Data Leak" is extremely misleading; the attack is called credential stuffing and is unrelated to any sort of breach on Ring's end. Edit: finished reading the article, and the entire text is just as misleading as the title, credential stuffing happens all the time and really isn't newsworthy.

I think your objection is misplaced. It doesn't matter where the credentials came from if there's a list out there that targets Ring accounts.

Would you say that a thousand houses "leaked their owner's data" (presence information) if someone went by ten thousand specific homes and rang their doorbells to test if someone is home based on information they got from a third party?

I would say there is a substantial difference between compiling a list of valid Ring credentials by trial and error based on data you already have from another party ("credential stuffing") and Ring disclosing the credentials either on purpose or through a hack ("leaking data" / "data breach").

Note that another comment calls into question whether this really was credential stuffing, but that's not what I mean to comment on.

Post reply on HN