A Data Leak Exposed the Personal Information of over 3k Ring Users
buzzfeednews.com
buzzfeednews.com
"Ring does not alert users of attempted log-in from an unknown IP address, or tell users how many others are logged into an account at one time. Because of this, there is no obvious way to know whether any bad actors have logged into people’s compromised Ring accounts without their consent."
I can understand not having 2FA turned on by default, but a bare minimum for this kind of service would be to alert users when someone successfully logs in from a new device.
Otherwise, what you're doing is perfectly fine and well enough: connect to your SIP trunk via credentials using a local client and you've more or less got a working, accessible phone number. Unless you truly have a need for Asterisk features, don't bother.
I happen to know first hand of a "voice company" that has a pretty sizeable footprint in the travel/hospitality industry making several million dollars a year and one of their products amounts to nothing more than configuring IVRs and charging through the nose to host them using what is (in my opinion alone) a thoroughly overly-complicated Asterisk infrastructure and similarly overly-complicated dial plans.
It's baffling to me that any popular app wouldn't have 2FA (or any app, for that matter.)
No more that the password already does. 2FA isn't supposed to protect you from the company you already have the data too. And it's not really for the "privacy" of that personal data but for securing it.
All keylogged/phished/etc.
Edit: finished reading the article, and the entire text is just as misleading as the title, credential stuffing happens all the time and really isn't newsworthy.
Just stating that you misrepresented what the article actually said when you wrote "the attack is called credential stuffing". Your sentence gives impression that the article would have said it, but the article made a point for the opposite.
Nonetheless, you misrepresented what the article actually said -- the article raised both, the possibility credential stuffing (implied by Amazon spokesperson), and doubt about it (unspecified security expert, WiFi attacks).
The best before date of this conversation has clearly expired, so let's just stop here.
> Security experts told BuzzFeed News that the format of the leaked data — which includes username, password, camera name, and time zone in a standardized format — suggests it was taken from a company database. They said data obtained via credential stuffing —when previously-compromised emails and passwords are used to get access to other accounts — would likely not display RIng-specific data like camera names or time zone.
> “One could argue that the person maybe got these through credential stuffing,” Cooper Quintin, a security researcher and senior staff technologist at the Electronic Frontier Foundation, told BuzzFeed News. “But if that was the case, why did that person go through and add the information about names of camera and time zones?”
Why did they add it? Why not? I'm betting when they logged in that info came back as part of the API call.
If they were going to sell the information, and the credentials really allowed to remotely access the cameras, then accessing 'camera=BEDROOM' at 11PM Friday local time may provide more entertainment value than 'camera=GARAGE'? :)
If a bad thing happens all the time and people are unaware of it, calling attention to it is entirely newsworthy.
To you, as a jaded security person who understands that there are systemic risks to any network-connected service and nobody is good at defending against them, perhaps it's perfectly normal. To a customer who is making the decision between buying a network-connected doorbell for their security and buying a perfectly normal offline doorbell, the fact that credential stuffing happens all the time is a thing they need to hear about!
(Also, there are straightforward ways to resist these attacks, such as "You must use 2FA," "You can only pair a new device with your Ring account while it's in physical proximity to your Ring device," "You must use either 2FA or physical proximity," "The app will generate a password for you and won't let you use an existing one, feel free to write it down on a piece of paper," etc. A home security system should be more paranoid than a politics forum or a meme generator at keeping accounts secure.)
Then customers can decide whether they want an internet-connected home security system from a company that doesn't invest heavily in account security.
I would say there is a substantial difference between compiling a list of valid Ring credentials by trial and error based on data you already have from another party ("credential stuffing") and Ring disclosing the credentials either on purpose or through a hack ("leaking data" / "data breach").
Note that another comment calls into question whether this really was credential stuffing, but that's not what I mean to comment on.
That's not what's the headline says, and that's not what TFA says. Someone "leaked" a list of valid credentials to Ring accounts. A better analogy would be if someone collected ten thousand keys they found around the city, tried them on every lock they came across, and then created a map showing which keys worked on which locks. And provided an infinitely-copyable keyring to go along with the map.
Ring says they're not responsible for the data being out there, and that's probably true. But the data is out there, and that's a problem for the people on the list.
"of those we spoke to none had been contacted by Ring — contrary to the company’s claim."
It is also fascinating how media companies are likely to pounce on the slightest of flaws(some malignant, and some innocuous) with either Nest or Ring, since it feeds on people's sense of security/safety again, and thus are likely to lead to more clicks.
I wouldn't characterize these flaws as slight. But I'm biased... I used to work in the security space, and I know culturally the typical engineer are less concerned, and non-technical people in the technology sector being fully deferential to product orgs in that respect.
It's fascinating how Ring's business model benefits from local crime prevalence, which in turn might lead people to invest in home security.
That's an interesting point. The whole Ring ecosystem is kinda boosted by Amazon's other business too: leaving boxes on peoples front porches to be stolen. Amazon really knows how to grow a circular ecosystem huh?tbh I prefer your version though.
I get the exterior, but why are they spying on their kids? I can't think of a security reason for it, it's just super controlling and creepy.
When they are older then I don't have a good reason.
https://www.nbcnews.com/news/us-news/man-hacks-ring-camera-8...
"I just ran these in a script I wrote to process them through HaveIBeenPwned in bulk. Every single email except ~20 was already compromised. These Ring dumps going around (+Buzzfeed prob) are highly likely password reuse; not evidence to suggest internal DB"
source https://twitter.com/josephfcox/status/1207864924459978752
They didn't properly defend against credential stuffing attacks. The victims here reused passwords.
It would be like a website writing an expose on how ford trucks are killing hundreds of drivers and expecting a response from ford, but when you read the details it's because users are driving their trucks into brick walls, something that literally every car on the market is susceptible to.
"Ring does not alert users of attempted log-in from an unknown IP address, or tell users how many others are logged into an account at one time. Because of this, there is no obvious way to know whether any bad actors have logged into people’s compromised Ring accounts without their consent."
If its stored in the Cloud, then it ain't private.
...by showing how not to do it