Live data from Hacker News

A Data Leak Exposed the Personal Information of over 3k Ring Users

buzzfeednews.com

41–50 of 97 posts

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#42
post #10
post #6

Amazon's response seems quite defensive. They are typically a bit black box when it comes to security issues.

Maybe it's because literally every password protected service is vulnerable to users reusing passwords on other insecure sites. It would be like a website writing an expose on how ford trucks are killing hundreds of drivers and expecting a response from ford, but when you read the details it's because users are driving their trucks into brick walls, something that literally every car on the market is susceptible to.

MFA?

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#43
post #31
post #5

Even if it was the official article title, "Data Leak" is extremely misleading; the attack is called credential stuffing and is unrelated to any sort of breach on Ring's end. Edit: finished reading the article, and the entire text is just as misleading as the title, credential stuffing happens all the time and really isn't newsworthy.

> credential stuffing happens all the time and really isn't newsworthy. If a bad thing happens all the time and people are unaware of it, calling attention to it is entirely newsworthy. To you, as a jaded security person who understands that there are systemic risks to any network-connected service and nobody is good at defending against them, perhaps it's perfectly normal. To a customer who is making the decision be…

Under that justification, it would require at a bare minimum giving the reader the proper context, e.g., "similar non-breach threats exists for a large number of common online services, such as [list examples the reader is likely to know]".

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#44
post #40

Earlier quoted context omitted.

I think your objection is misplaced. It doesn't matter where the credentials came from if there's a list out there that targets Ring accounts.

Would you say that a thousand houses "leaked their owner's data" (presence information) if someone went by ten thousand specific homes and rang their doorbells to test if someone is home based on information they got from a third party? I would say there is a substantial difference between compiling a list of valid Ring credentials by trial and error based on data you already have from another party ("credential stuf…

Yes, if those thousand houses were connected to a wire that allowed them to be rung simultaneously and remotely.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#45
post #40

Earlier quoted context omitted.

I think your objection is misplaced. It doesn't matter where the credentials came from if there's a list out there that targets Ring accounts.

Would you say that a thousand houses "leaked their owner's data" (presence information) if someone went by ten thousand specific homes and rang their doorbells to test if someone is home based on information they got from a third party? I would say there is a substantial difference between compiling a list of valid Ring credentials by trial and error based on data you already have from another party ("credential stuf…

>Would you say that a thousand houses "leaked their owner's data" (presence information) if someone went by ten thousand specific homes and rang their doorbells to test if someone is home based on information they got from a third party?

That's not what's the headline says, and that's not what TFA says. Someone "leaked" a list of valid credentials to Ring accounts. A better analogy would be if someone collected ten thousand keys they found around the city, tried them on every lock they came across, and then created a map showing which keys worked on which locks. And provided an infinitely-copyable keyring to go along with the map.

Ring says they're not responsible for the data being out there, and that's probably true. But the data is out there, and that's a problem for the people on the list.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#46
post #8

So 3k people who installed neighborhood surveillance devices have suffered a loss of privacy? Can't seem to find much sympathy.

Almost everyone who gets a ring or other smart door bell is getting one to see who is knocking on their door, not to spy on their neighborhood

They may have just wanted a fancy eyehole, but it DOES allow spying on the neighborhood.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#47
Not referenced in this article, but something I've been thinking about while reading about the security kerfuffle, why are people putting cameras in their kids rooms?

I get the exterior, but why are they spying on their kids? I can't think of a security reason for it, it's just super controlling and creepy.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#48

Not referenced in this article, but something I've been thinking about while reading about the security kerfuffle, why are people putting cameras in their kids rooms? I get the exterior, but why are they spying on their kids? I can't think of a security reason for it, it's just super controlling and creepy.

If it's just a baby then I'd want to keep an eye to not fall of the bed. Door would be closed to reduce the noise. That said, I never did it... just thinking.

When they are older then I don't have a good reason.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#49

Not referenced in this article, but something I've been thinking about while reading about the security kerfuffle, why are people putting cameras in their kids rooms? I get the exterior, but why are they spying on their kids? I can't think of a security reason for it, it's just super controlling and creepy.

Baby monitors are a thing and have been for close to 80 years. Now that cameras and displays are cheap video is on there too.

Re: A Data Leak Exposed the Personal Information of over 3k Ring Users

#50

This seems important: "Ring does not alert users of attempted log-in from an unknown IP address, or tell users how many others are logged into an account at one time. Because of this, there is no obvious way to know whether any bad actors have logged into people’s compromised Ring accounts without their consent." I can understand not having 2FA turned on by default, but a bare minimum for this kind of service would b…

I've recently had a similar problem with Spotify. My account was stolen. In part because I did not have 2FA turned on... because the app doesn't offer it for some reason. And, in part, because whoever logged into my account from a different IP and device supposedly didn't trip any of their security measures. So I was never even told that someone took hold of my account until I tried to get on.

It's baffling to me that any popular app wouldn't have 2FA (or any app, for that matter.)

Post reply on HN