Former Ubiquiti employee charged with stealing data and extorting company
justice.gov
justice.gov
Nick had his hands in everything from GitHub to Slack and we could never understand why or how. He rose to power in the company by claiming to find a vulnerability that let him access the CEO's personal system, but nobody I spoke to ever knew what the vulnerability was. I discussed this with another ex-Ubiquiti person in an old thread [1] Now I'm positive he faked the security issue as a power move, just as he faked this attack for extortion purposes.
He would also harass people and use his control over Slack and GitHub against the people he didn't like. Many people left around this time partially because Nick made everything so difficult at the company. What a terribly depressing series of events.
Now... submit a ticket. Frustrating/pointless UI changes. Breaking system upgrades. Backed up your configuration? Doesn't matter, you're going to need to reset this update... disappointing. I still have hope they'll turn it around because they have the best UI of any network gear I've used for getting small/mid size networks up and done.
(My issue is that I understand that most users are clueless, heck I started in support for Win3.1 for an ISP, but the stuff in the debug clearly was a statement that I understood what I was say, and even as a Jr. engineer 30 years ago, I would have read it and said "hum, this dude knows his stuff, maybe I should ask at the next level").
The rest of Ubiquiti's gear does use IEEE 802.x.
Ubiquiti sells some devices that are 24V passive PoE. These devices include their UISP products (such as devices like the AirMax). Passive injectors are dangerous because they always supply 24V to the port; this could damage a non-24V PoE device.
There's also the 802.3a* standards family, such as the 802.3at (what Ubiquiti calls PoE+). Each of the standards (e.g. 802.3at, 802.3af, etc.) support different amounts of current, but they're all 48V active adapters. Active PoE is safer because the device "requests" the power it wants; the switch does not always supply 48V power over the port, so devices that don't require PoE won't be receiving power.
Ubiquiti sells a few switches that support both 24V passive PoE and 48V active PoE. You can change this in the switch's web interface, through the port settings. You may also want to consider just using a 24V passive injector, especially if your switch cannot be configured to supply 24V power.
Edit: also their stock. Believed in them so much I bought their stock
Regarding support wise: I've had one malfunctioning switch (POE just stopped working) and it was replaced within 24 hours, so that's nice.
I love Meraki stuff, so I looked into Meraki Go, and they handicapped Meraki Go by only allowing VLAN for devices with wired connections to the switch. I want the ability to setup a wireless SSID, apply a VLAN to it, and have any wireless devices connected to that SSID be on that VLAN.
Wish they would reevaluate that decision, as I've heard good things about their access points.
Personally, I would argue that Ubiquiti handled the pandemic much better than other companies. Take the Cloud Key firmware: Back when it was first released, the thing was so unstable it had to be reset every few weeks. Every firmware update required a factory reset. Nowadays, it's solid. Even flashing beta builds is a smooth, issue-free process. Features like person and vehicle detection in their Protect lineup are a much welcome addition, as is the revamp of the Protect app. All of this happened during the pandemic.
I know people whine about how Ubiquiti unified everything under a global login, but come on.. if it works, it works. It's hardly a reason to bash Ubiquiti because you're upset you temporarily have to sign into ui.com.
Now, maybe they are putting more effort into Protect than they are into the network side of things. I don't know, because I primarily use them for Protect. With that being said, I'm fairly satisfied.
Do you mean he got promotions cause he found a non existent vuln? Surely whoever handed out those promotions is to blame here?
Actually not unusual.
Lots of the Highest Ranked Sys Admins in larger companies are quite "invulnerable" due to the implication, that they might know everyones mail & the companies dirt.
But IMO the truly depressing event here is management refusing to do anything until it was too late. What are they even paid for?
Also, extortion. I'm always amazed at what people will say over Slack DMs, seemingly not realizing that it all is accessible by the company.
Is that (creds) considered safe/secure these days? Is it common place? I kinda figured slack might get to be a 1password on top of everything else, so it's interesting to hear it's happening.
No, definitely not. It's just super convenient and happens all the time at every organization.
The most recent Twitter breach involved a credential shared in a Slack channel. Security teams have a hard time monitoring Slack and the default settings are pretty bad (infinite session length, infinite message retention).
Unless slack hard deletes messages, but my guess would be soft deletion. Even then it's not really designed for sending sensitive credentials
So yes, you'll want to: 1. Delete the message 2. Revoke the token 3. Notify the user/ security operations team
Even if slack would delete the message, clients like bitlbee and wee-slack exist, and save the messages as soon as they came in, and slack will not be able to delete them. Bots get those messages as well.
Just because the chat service deletes messages from their backend does not mean the message is deleted at the clients.
To me, this seems like a classic example. To quote the press release: "During the execution of that search, SHARP made numerous false statements to FBI agents, including, among other things, in substance, that he was not the perpetrator of the Incident and that he had not used Surfshark VPN prior to the discovery of the Incident. When confronted with records demonstrating that SHARP purchased the Surfshark VPN service in July 2020, approximately six months prior to the Incident, SHARP falsely stated, in part and substance, that someone else must have used his PayPal account to make the purchase."
This man was a senior developer yet this quote sounds like it comes from a nine year-old. Not to mention "hire a lawyer, don't talk to the police" has always been pretty solid advice.
He now faces significant prison time, and the strong potential for a dismal life.
When faced correcting a false reality you have created, it can be quite hard to decide to phase change into telling the truth. The lies that come out come from not being prepared and not being a very good liar. For people who lie like this, a good way to think about it is as though it were a disease.
Actually intelligent people just don't do things like this, even if they have nefarious intent. There are quite smarter ways to accomplish substantially the same thing that this crime does not reflect.
I'm not convinced that this person was particularly intelligent in the first place.
Are you really claiming that intelligent people don’t commit crime or don’t lie? That seems incredibly naive.
Intelligent criminals and liars are better at it, better at obfuscating, better at making it unclear whether or not a crime was actually committed, better at never having their crime discovered and not getting caught if it is.
Or just don’t talk to the police and lawyer up. I agree the best thing is to not do the crime, but if you are a criminal then the intelligent and simple thing is to use a lawyer.
The full phrase - "don't talk to cops except upon the advice of your lawyer" - isn't complicated either.
Tech has a contempt culture problem, and this can be one manifestation of it: feeling that being moderately bright about getting computers to do things makes you a tremendous intellect, and everyone else around you an easily hoodwinked moron.
Perhaps the most extreme example was Hans Reiser. Anyone who followed the twists and turns of the case against him for murdering his wife will remember how many trivially disproved lies he told, apparently under the illusion that he was a mastermind who could put one over on the courts based on his faulty understanding of ideas like reasonable doubt.
https://www.theregister.com/2008/07/10/reiser_rejected_volun...
I've been seriously bitten by this, and find it more scary than fascinating. Growing up, I thought people who followed cult leaders and charismatic narcissists were so stupid (still do), it appeared so transparent to me. Later, in my professional and adult life I found myself to be equally gullible when intelligent people were abusive or outright dumb in other areas. This has been a challenge to unlearn, like learning an old dog to sit. Basically, our proxies for predicting people's character range from bad to terrible.
oh I am 100% with you on this. I tried to elaborate but I just sound bitter and twisted, and that's probably true. But I've spent the last few years unlearning things I thought I knew. It has been a painful and expensive set of lessons.
long story short: I think we judge people's reaction to a situation by projecting how we would act... but that's not how people actually act.
The people who do this are smart, confident and charismatic. It is clearly a negotiating strategy. But in reality, the only thing that matters is who controls the flow of money. If they control the money then it doesn’t matter what they said, they can do what they damn well please. They know this up front, and they count on it.
Despite these setbacks I’ve done alright for myself, but honestly, I’m really bummed out about how useless I am when it comes to judging people and creating businesses where I’m free to actually do my best work.
Anyway, I don’t know if that helps you, but you asked and honestly it has helped me a bit to vent even if it’s all in the abstract.
From what I’ve seen, openness and honesty are highly regarded in technical work but these traits are considered disadvantages in business.
Even before Omidyar stepped down from Craigslist’s board, his appointed agent, Garrett Price, started bullying Craigslist’s owners. In an email to Buckmaster, Price wrote that Craiglist was “driving [eBay’s] execs (especially Meg) to distraction.” He told Buckmaster that eBay’s takeover was “inevitable” and that Craigslist needed to accept their fate, telling “Buckmaster that he and Newmark were mortal, but eBay was not, and eBay would acquire 100 percent of craigslist whether it took decades and, if necessary, over Newmark’s and Buckmaster’s dead bodies.”
Buckmaster replied by reminding Price that when they negotiated the sale of their stake, eBay had agreed to abide by a three-year “courtship period” during which time, if Craigslist felt their two cultures were incompatible, eBay had agreed it would sell back its shares.
Price’s response to Buckmaster:
“that was then, this is now.”
https://web.archive.org/web/20150623005252/https://pando.com...It's been one thing for me to be on the receiving end of bad behaviour and to form an opinion and suspicions about what happened.
But it's quite another to see it played out deliberately, in the large, using trust and friendship as a weapon to defeat a group of people who aren't even playing the same game.
The remarkable thing for me is that people really are capable of this kind of shitty behaviour; that it can be entirely intentional, and planned well ahead of time. And that it doesn't matter how rich some people are, they are happy to cheat and steal just to get a little bit more. It's disgusting.
Thanks again for linking to it.
Hell I grew up in Normandy and was 16 when some Americans became so mad we refused to follow their war in Iraq they called us ungrateful. Talk about the fall of an idol :D So all that freedom we were supposed to be grateful for was only ever supposed to be used when deciding between buying a coca cola or a pepsi cola, but never for real big boy decision ? Thanks I guess ?
Rules have no intrinsic meaning, authorities are there by luck and circumstances and not their mystical ability to always lead towards the right direction, people try their best and often fail and nobody truly is intelligent in all circumstances.
It actually takes explicit training and practice, as it goes against every social habit and "instinct" we have developed throughout our entire adult lives.
I actually rehearse now, because police in the USA are so corrupt and unreliable.
Something along the lines of "I know you are just doing your job, but, respectfully, I must consult with my attorney before answering any questions."
Then (to their dismay and annoyance) I repeat the exact same thing over and over again when they inevitably ask me other, follow up questions, trying to work around my initial refusal. (It's so disrespectful, as well as illegal, for them to keep going at that point.)
I have also semi-successfully appealed their FOIA denials covering the incident.
It has resulted in the sexual assault of some of my traveling companions by US CBP (full and thorough body search, simply as punishment for remaining silent). CBP is lousy with criminal pigs.
You can't refuse to answer questions when entering most countries you aren't a citizen of, if you wish to be permitted entry.
A big part of the lawyers job is to question people. Their stories fell apart pretty quickly.
Once I got quizzed when boarding ElAl flights. They have well trained interrogators. It turns out a complicated life story and ADHD method of story telling doesn’t make them happy. A lot of “I said X because the full story is way too complicated, so here’s the full version” ;)
People think they can stand up to it but it’s hard when it’s someone whose full time job is exposing fake stories.
Dude, let's not be generous. Could he write code? Yes. But this is a guy who wrote everything in Node, but absolutely _refused_ to use any existing libraries except for ones he personally wrote. He didn't "trust" them.
He wasn't even hired on as a dev, he was hired to be the "Cloud guy", essentially a sysadmin for AWS, and basically spooked the CEO into giving him the keys to the castle.
Sounds like the single sensible thing he did. Have you seen the npm ecosystem?
Of the top 10 posts on HN about NPM in the past 30 days[1], 9 are about security problems, and last 1 is about package spam.
[1] https://hn.algolia.com/?dateRange=pastMonth&page=0&prefix=fa...
To illustrate: A new Ruby on Rails app has 1/10th the number of maintainers in its dependency list than a new create-react-app codebase.
Picking a language (and possibly runtime) is a pretty huge investment if you intend to become proficient. A lot of people like to think that they are polyglot programmers and that language doesn't really matter. But it does. It takes a few years to become a decent programmer in a given language. And if people claim it takes just weeks or a couple of months, it really only tells you that they have very low standards.
If you are familiar with a given language, ecosystem and runtime, and you care about productivity and quality, the path of least resistance is to stick to what you know. Taking on a major project in a language you don't know is a risky proposition. In terms of quality, time, and even in terms of being able to deliver something acceptable.
I tend to have a main workhorse language. It typically takes 2-3 years to reach an acceptable level of comfortable familiarity with a new language. If history is any guide I tend to stick to the same language for 5-10 years. 5 years ago I switched from Java to Go. I mostly worked mostly as a manager at the time, which is why it took longer to reach what I think is an acceptable level. I'd say it is only in the last 18 months or so I've started feeling sufficiently competent in Go to call myself a Go programmer.
That being said: I think the JS space is both a poor technical choice and a poor career choice. The whole ecosystem is janky as fuck, you have to spend a lot of time dealing with silly complexity that tries to fix the jankiness, and the type of work you get isn't very attractive.
I knew a senior developer doing advanced R&D at a big tech company, who also kept getting suckered into MLM scams.
and to me it looks like somebody intentionally left breadcrumb trail leading to the guy. With cloud paying so nice these days nobody is going to risk that way for the paltry $2M (ie. less than 3-4 years earnings in Bay Area for the people like this). It looks like the stock price drop is the real "follow the money" trailhead, and that doesn't lead to the guy.
And given that it were about Ubiquiti customer databases - the value of [stealth] access to those customers may possibly dwarf those few billions of valuation drop - so even the stock drop may have been a smoke screen. I mean Ubiquiti as a target reminds me of SolarWinds.
Those comments back then is also interestingly predictive https://news.ycombinator.com/item?id=26692987 - having a fall back guy kind of absolves the company from architectural and operational sins which allowed the hack and pacifies the customers who otherwise would feel unease of being possibly hacked by somebody serious.
He should have been spending his time finding out how his PayPal account and home network got hacked, not talking to journalists accusing the company of not handling the hack correctly.
keyword is "evidence". Whenever a sympathetic person/cause becomes a target of IP-address based evidence HN is overflowing with posts that IP-address isn't an evidence :)
So, we have electric grid evidence that matches up with IP evidence, that matches up with Paypal account evidence. I’m not saying he is guilty or innocent, but lets not misrepresent what is being discussed. I’m saying that responding to chains of evidence by claiming that is what someone setting up a patsy would do, is a unfalsifiable conspiracy theory.
When the FBI knock at the door you totally do the whole "no comment/talk to my lawyer" thing. But what happens next if you're actually part of an investigation is they hand you a grand jury subpoena (which they were going to do anyway, even if you just talked willingly, because they have already gone to the trouble of asking a judge to issue one and have it with them by the time they ring your doorbell)
That subpoena is likely to require you to hand over any digital records you have related to the investigation (you can't plead 5th on that) and turn up at a time and place to be interviewed (you have to turn up, even if it's on the other side of the country eg in the Southern District of NY in Manhattan and you live in SF Bay Area). BTW I don't think people widely realize the government has the power to compel you to hand over EVERY piece of material you have on a given subject they are investigating - eg search and share anything from every email you have ever received since you signed up for GMail in 2004, etc.
You can plead 5th during the interview but if you have material information (or are actually guilty) and knowing they have all of the documentation subpoenaed and whatever other evidence from other subjects/targets/witnesses, it will likely help you at that point to be cooperative via guidance from your attorney. Remaining silent at that point is just going to leave you at the mercy of whatever other witnesses/subjects/targets convey and their own conclusions from the subpoenas.
If you are on a visa or green card you almost certainly can't plead the 5th because they can leverage your right to remain in the US.
So, that's why people typically talk to the FBI. It's not at the doorstep when they first engage you, it's once you have been compelled to participate.
Related/useful: https://www.natlawreview.com/article/you-received-grand-jury...
Source: happened to me a number of years ago, although I wasn't guilty of anything. Lawyered up, cooperated, no further action. Wasn't pleasant.
IANAL, not legal advice
guidance from your attorney seems to be the critical bit of that - it's okay to talk, but with your lawyer present.
LEOs exploit this.
In what way would "fuck you talk to my lawyer" be helpful?
2. “The suspect conveniently had a receipt in their pocket placing them elsewhere at the exact time of the Y crime. It was the only receipt in his pocket! Seems suspicious to me. He plainly engineered the alibi.”
3. There's no reason you have to immediately begin demonstrating your innocence. It can wait until you have proper representation.
It's rarely the case where a receipt in your pocket is the difference between handcuffs and freedom. I'm sure they exist, but more often the decision to arrest you or not is not hinging on your answers to the cop's questions. It's already been made.
Anyway, real life example - police calls me up saying this number came up in an investigation, who are you and a few more other questions. They were obviously expecting me to cooperate cause they hadn't bothered to do the paperwork to obtain my identity which was tied to the number. First thing I did was say I'll call you back cause I'm driving, what's your name? So I could verify it was an actual cop.
When I called them back I said I'm not telling you anything until you tell me what it's about. Cop hesitantly starts giving a few bits of information and we go back and forth until my mother's town comes up (too small a place to be a coincidence) and the whole thing unravels.
Turns out my mom had been getting some weird calls at home and when she was out & about by a person who seemed to be following her. Because of her age and absentmindedness she gave the wrong number out of her recent calls list to the police. Hilarity ensues. Cop suggests I check on my mom, we genuinely thought she had some kind of attack of dementia (she was fine, just very embarrassed).
Cop also called my mom to saying your kid's a real hard-ass (but polite and correct)!
Anyway my point is - don't you think me lawyering up for this would have been absurd?
In this case you had a cop who is actually willing to go back-and-forth with you until you discovered what was going on. Absent that, you absolutely would be right to say something like, “without knowing what’s going on here I can’t answer any questions.”
Your initial example of “you look like a criminal we’re searching for” is way more fraught with pitfalls that can be avoided by not cooperating.
Also, I should be more “assertive” at work…
No!
An actual lawyer wrote an actual book about this (after he made that famous video we are all talking about). Refusing to answer questions can be used against you!
His advice is to collapse it to:
"I want a lawyer."
It becomes unconstitutional for them to continue questioning you after that statement. Do not decline to answer questions directly - ask for an attorney!
Isn’t this just hindsight bias? What if the situation wasn’t your mother’s absentmindedness but your number being found in the phone of a murder victim? The “back and forth” with the officer leads you to confirm that you know and have visited the small town where this person was killed. So they ask you if you have ever visited the window tinting shop where they work, and you say no. What you don’t know if an eye witness incorrectly believes they saw you there, which makes you a liar in the LEO’s eyes.
This issue isn’t “what if it turns out to be nothing”. The issue is that if it does turn out to be something, the consequences of not keeping your mouth shut are far worse than the minor “over reaction” when things end up being ok. Its like wearing a seat belt. You don’t do it for all the times you don’t get in an accident. You wear it because the consequences are dire in the case that you do get in an accident.
Then by talking to them you accidentally give them ammunition. "Yeah, I hated the guy, but I couldn't have killed him" turns into "the defendant told us that he hated the guy". Or you lie accidentally, which gives them another crime to threaten you with; "you had better plead out, because we have a whole list of crimes we can get you for".
If someone thinks you have wronged them or committed a crime do not engage them. You will not change their mind. You are not that convincing, and they will see your efforts as manipulative and slimey.
(My own first-hand experience with this was civil, not criminal. Someone I had never met accused me of something absolutely nonsensical and filed a lawsuit against me. I thought I could reason with them, but this just made things worse. I would have been much better to approach the situation as though they were dangerously irrational. Just don't engage.)
It's totally true that you can give cops ammo against yourself without realizing and you must be very careful wrt lying and saying the wrong things.
But there also has to be some kind of middle ground.
Don't talk to the police under any circumstances. You cannot ever talk your way out of getting arrested.
There is no middle ground. Watch the "don't talk to police" video linked in the thread. He explains that it is like a ratchet: statements can only hurt, it is illegal under the rules of evidence for your statements to the police to be used to exonerate you!
If you have watched this video, you might want to review this highly anticipated follow up several years later: https://www.youtube.com/watch?v=-FENubmZGj8
See Miranda v. Arizona 1966 and the Fifth Amendment.
For a crime like this -- as serious as this was, with the damages involved, the company and its internal resources/practices -- he probably had no prayer of getting away with it and in a Dunning-Kruger-like manner, he not only didn't know what he didn't know, I don't think there's any way he could have known enough about his adversary's capabilities to get away with it long term.
If a criminal wishes to be successful in getting away with a serious crime without getting caught over their lifetime, that criminal must successfully thwart detection from all current and future technologies. I mention serious because those crimes often do not have a statute of limitations these days. I'm assuming a perfect law enforcement body that similarly makes no mistakes, so a "luck factor" weighs in, but given a (not too) high-profile crime with motivation, budget, competent investigators and expanding technology, I'll law enforcement is gong to rank higher in the luck category.
It's not enough to look at what they're capable of currently. Consider this scenario: A murderer with Type O+ blood (with other common properties) strangles a man with a wire in 1980 leaving behind only that wire as evidence. In the struggle, the wire also cut the murderers hand and deposited a tiny drop of their blood on it. Being that it was a small item stored for an open case and was well preserved, it's still there, today. Luck. Back in 1980, it was of little evidentiary value. Today, that drop has a good chance of producing a DNA profile. Has the murderer been arrested (not convicted) of a felony in the last few decades? They'll probably be caught. Did a family member use certain (do they all do this?) consumer DNA services? Their family might be found, which will narrow the suspect down to a pool of people. Forget drawing suspicions by getting warrants, because it takes so little biological material and you deposit it everywhere you go, the police just wait for garbage day or follow you around town, grab something that came into contact with your mouth and they've get a profile (which will be used to get an easy warrant for a blood sample to confirm it).
Budding criminals, are you storing all of your secret plans on your drive in a bullet-proof encrypted manner and ensuring that it is airgapped? Are you doing all of your secret research on a similarly configured device, but configured to ensure all networking only works via Tor? Are you sure you didn't make a mistake that couldn't rise to the standards required to get a warrant to image your drive/take your equipment (that's hopefully turned off)? That bullet-proof encryption is rotting, and 30 years from now could represent a small hurdle above plain text.
And what happens when the time required to investigate crimes is reduced further? "We'll get around to bike theft when we're done solving all of the murders." But what if solving a small percentage of the bike thefts went from "complaint" to "likely suspect" almost instantly if certain circumstances were right. For instance, imagine law enforcement could automate geo-fence style warrant requests (requests to get "people in a location at a certain time" from Gooble/Apple/mobile phone provider histories[0]) for every bike theft where the bike was stolen from an area infrequently traveled where and the time of the theft is known to within an hour. For any where the there was exactly one person logged, you have a person of interest -- probably the thief. Not enough evidence to prove a crime, but enough to scare some of the petty thieves into giving up more evidence through questioning (or maybe just give up). It's a stretch, on purpose -- but as technology make solving crimes less costly, less serious crimes will be prosecuted more frequently/reliably.
Full disclosure: My only credentials in this area are working in Corporate Security at a multi-national (large) telecom company for a brief stint and in a security/development capacity for most of my career; except for that brief stint, all of my work has been on the defensive/strategic side, not on the investigative side, and never with violent crimes of any kind. I simply enjoy security topics, in general, but if I've shown my ignorance in a few areas, my apologies and feel free to correct.
[0] Assuming this data is kept long enough; I am going to hazard a guess that it is a lot longer than most people think.
Had he put in a little more thought and preparation then I still don't know if he would've gotten away with it, but at least he'd be in a better position. He wouldn't have to lie to the FBI agents and they probably would've had to catch him by going after the source of the place where the data was leaked instead.
Opsec is hard, but this is just embarrassing for someone in the know trying to steal 50 bitcoin. I'm also not sure why he did it. Suddenly owning a few million in crypto would be noticed, unless he didn't spend any of it, ever. What was his plan, just quit his job and move away right after the hack?
I would like the bad people to be caught and you are just giving away free advice to any future thief like him and also kind of encouraging other people which is kind of worrisome.
Privacy is a double edge sword and this is case that I happy that he was caught because of his lack of knowledge.
He was probably just overconfident in his knowledge; you kind of have to be somewhat nuts to try to pull this off so it's not too surprising.
If you're a criminal reading my comments and learning anything new from them, let me tell you this: if you needed this info, you're not smart enough to evade the FBI. Go find a real job or something.
I'm glad the ass got caught and I hope he'll get what he deserves. However, I believe that the common modus operandi for criminals shouldn't be a secret because it will get out anyway. The "solutions" I propose are obvious and basically handed to criminals by the FBI analysis.
Good opsec for crime is incredibly hard, which is great in cases like these. I don't think I've heard of some super smart hacker that's managed to stay away from the authorities unless they live outside the relevant jurisdiction. Even then the FBI will find ways to get you into a country where they can arrest you, legally or otherwise.
A lot of "crime" in some countries, like China or Russia, is just doing the right thing in my opinion. You might very well need this kind of opsec if your goal is to help teenagers learn about homosexuality in many of the more bigoted countries, for example, or get the truth out about COVID without suddenly finding yourself falling out of a window.
I don't think the "true crime" style comments help criminals in any way. Documentaries about how murdered got caught aren't very good manuals and the advice of random people who've been in contact with the police aren't either. If they're dumb enough to follow the advice of some random guy here on orange reddit, their criminal career won't last very long.
Now they're looking at you from two angels.
Instead of all this jumping through hoops with anonymous VPN and payment methods, why not just do it from Starbucks?
But also starbucks / any shop / cafe / restraunt / apple store - or going for a drive and finding an open WiFi. Kinda wondering now how these places all handle their wifi being abused for crimes ...
Responsible disclosure exists for a reason.
It disappoints me that he has the audience he does.
At best, it's shoddy journalism. He was taken for a ride and should bear some public shame for that.
I doubt he'll get sued for it but a lot of people lost money because of him, so I wouldn't be surprised if someone tried.
It has also stayed relatively in that range afterwards - but you can definitely argue that this is due to the supply chain problems that the entire world is dealing with - but it's a pretty straight line to say that billions in shareholder value were wiped out.
But whatever.
Why? If a company prints a single stock then sells it for $100, I would expect the company's market cap to go up by $100 since it now has $100 more dollars in its bank account.
The company valuation is not stock price * stock count, which is your confusion, it's more tangible asset + speculative future assets, so the more stock you emit the less they each is worth. Companies become popular by doing stock buyback (increasing each remaining stock individual value).
Market cap, which is the stuff they do for amateur and children, to multiply stock count by stock price, is entirely meaningless because it ignores value when stocks were actually transacted and liquidity. If you emit a million stock at 0.1c and then create a marketing fad while locking the supply in the hands of a few and refuse to sell, you create a huge gap between low supply and high demand, increasing the individual price manyfold, arriving at a huge market cap... but you paid nothing for most stocks and a few people paid a LOT for a little. In investment banking we use volume weighted average price to try to get a view of what's the short term intraday value of a stock instead.
Imagine, I dont know, a crypto asset with a market cap of a trillion and a single individual owning 1/21 of the entire asset pool, if this single individual signal just one token sale, the entire market starts selling to people who dont want to buy anymore: what is then the value of considering the market cap ? It can go to 0 tomorrow just if demand disappear. Basically you need to include liquidity, a metric of the stability of the supply and demand, that's why I prefer to look at earnings per share to evaluate a company, it is way more significative of what you just bought. For a crypto asset it's 0 for instance.
Good point. But I was responding to someone who said "theoretically", which I took to mean ignoring psychology things like this and just looking at numbers. Of course "theoretically" can have many different meanings, and I might have been misunderstanding how that commenter was using it.
> it's more tangible asset + speculative future assets
When you sell a stock for $100 the tangible assets went up by $100. So the second equation is actually ($V+$100)/(N+1).
> Imagine, I dont know, a crypto asset
Bitcoin is a bit different because people believe Satoshi's coins are literally gone, lost. I don't think that happens with stocks.
Couple things that stood out to me was that the incident occurs in December and the raid ensues March 24th, so roughly 3 months. Building the case I presume.
Then after the raid, the accused doubles down and seeds fake news stories.
If nothing else, wouldn't they want to keep some information about customers that in the past have abused the service? You need some way to ban assholes, right? How would you do that if you have no idea who anyone is?
In addition to the the usual passion killings and random murders, there is the occasional criminal that thinks they are way smarter than everyone else and doubles or triples down even as the noose is tightening, because they 100% believe they are geniuses and will get away with it.
Example: https://www.youtube.com/watch?v=mVVL_U4BTGs
In this episode a member of Mensa, who enjoyed staging murder mystery dinner parties for his Mensa friends, poisoned his neighbor over loud music and barking dogs, and thought he was such a criminal mastermind that he could talk his way out of it. These people have mental disorders.
Great show
But I guess in retrospect using an exotic method of killing someone is bound to draw heavy attention.
That's almost $5 billion wiped off the company's market capitalisation because of this employee.
I mean Nick Sharp certainly took a chunk out of them but there is more to the story for why the market lost that much faith.
Try re-reading it, but replacing every instance of "Adam", with "Nick" and see how it comes across.
I'd love to see Krebs follow up on this.
Krebs got played here.
which were followed by a significant drop in the company’s share price associated with the loss of billions of dollars in its market capitalization."
Do they understand that they may need to fire the CEO given that the CEO probably is the weakest link here? Do they have sufficient liquidity and capital to invest in resetting the culture and hiring people who can turn this around?
Who else offers decent WiFi infrastructure for homes? (And offices)
I thought it was meant to be hard out there in tech valley ?
Is OpenWRT or OPNSense the way to go? Or is there some more generic web dashboard you can run on any GNU/Linux or BSD system?
I am a satisfied user of their software (and hardware) for the past 10years.
If you don't mind the rather rustic interface, it should be as closest to a professional grade cisco as you can get.
I'd personally be interested in a hardware vendor supporting a free-software stack (but with an accessible price range), or an established software vendor (ideally a workers coop) maintaining an administration dashboard to setup on commodity hardware.
Haven't run into any issues with Fortigates, yet. Time will tell.
Thats for Firewall/nat/router style devices, for wireless we've got a large number of unify flying saucers. I've use mikrotik wireless in the past, but it's not on the same level at all.
Are these running a free-software stack? Couldn't find info about it since fortinet website blocks Tor traffic.
OTOH I know a lot of people who are pretty happy with them, but that might relate to the fact that I recently started at a company selling them (among other brands). What impressed me most was the well executed "single pane of glass" integration of the first deployment I saw; all switches could be easily managed from the FortiGate web interface. Compared to that the Unifi Manager feels like a chaotic hack job from the 90s.
(To be fair, at home I still use Unifi APs and the switches are based on bang-for-buck: The 8P GBe 2P SFP+ Mikrotik in the study and the 24P GBe PoE 4P SFP+ Aruba as a "core" in the basement [that is, once it arrives, for now an ancient Netgear switch has core switching duty], Firewall is a loaned FortiGate, which I will probably replace with an OPNSense when I have to return it -- I'd go all FortiNet if the basement switch alone wouldn't cost about as much as my PC, though).
It may surprise some, but there is not prosumer/enterprise vendor that provides that Ubiquti does in terms of a solid experience, with bugs (as all software does), across routers, switches and network, with a single pane of glass.
Don't use ubiquiti is you want OPNsense capabilities. For almost everything else, it's a great bet.
The new UDR that is about to come out is a very worthy successor to the Apple Airport... but has more power then any other consumer hardware. That's a hard combo to get to.
https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-b...
This seems to explain how this comes down after less than a year since the incident. Surfshark now supports an outage related kill switch, not sure if that's a new feature.
Edit: oh, and using his own keys that were tied to him as an employee while he was being the attacker.
It’s interesting that that was what brought him down. I was going to guess a rogue log from the VPN provider until I got to that point.
Grant Margolin being one of the co-conspirators behind Fyre fest, along with Billy McFarland. I had the dubious privilege of interacting with the two in DC alongside Ja Rule as part of a Magnises event.
How did they know it was SurfShark?
Use CYBERWEEK19 for 85% your first years subscription.