Ubiquiti vs. Krebs
courtlistener.com
courtlistener.com
Krebs mentions the person was arrested. Ubiquiti claims first that he doesn't point out the person he sourced it from what arrested, and that he tries to mislead people by not saying repeatedly that the person is basically felon, and that being arrested makes him an invalid source of evidence, etc. They also claim he describes him as a current employee.
This is all nonsense AFAICT
1. Krebs mentions the person was arrested.
2. Krebs says "In March, a ubiqitui employee said X". That was accurate at the time (AFAIK, and ubiquiti cites no real evidence I see that Krebs should have known it was not true).
3. Krebs carefully points out the arrested person claims x and y (which is accurate).
4. The filing says Sharp made false claims, and spends a paragraph explaining them.
5. The filing says Krebs made them too, but ironically, for all of its bluster, doesn't cite where and when (that I can see), and which exact claims, they are claiming Krebs said that were false.
6. The filing cites no evidence that Krebs knew or should have known, in March, that the claims were false. They get into some weird arguments about their 10-q filing but it's hard to understand the point they are trying to make. It apperas they are trying to claim that krebs should have known they notified the public but i think that's kind of a silly argument - krebs is clearly talking about their users, and most users do not read 10-q's. Saying you notified the public because you put it in a 10-q is like saying you notified the public because you put it in a classified ad section. It's dumb wordplay.
7. The December blog post they say he "doubled down on" seems again, carefully written to say what Sharp claims, not what Krebs claims.
I could go on.
The whole thing is, IMHO, not written very well. It's very emotionally written for a pleading, and you will be hard pressed to find a judge who will get themselves worked up over that kind of writing. Instead they mostly roll their eyes and wish that someone gave them a clear and convincing pleading instead.
Put another way - if there is a case here, it isn't visible on this pleading. This feels like "throw a bunch of emotional stuff at a wall and hope it sticks", where you really want "here is an open and shut case of why this person defamed us"
Kreb's original source for the march article was the fake whistleblower extorting ubiquiti. He had just gotten raided by the FBI. Which is why the tweets are being mentioned.
Ubiquiti hangs this entire argument about this on using slightly different wording to refer to a person in two places in an article.
But if you read the article, he reports the facts in a literal linear timeline fashion, attempting to use what appear to be time-correct monikers.
IE He literally says (see the screenshot) In January x happened in March, a ubiquiti employee said something in November, a former developer for ubiquiti was arrested and charged.
He never says the march and november people are different. He is reporting exactly what happened. They claim he knows they are the same person, and should refer to them as such but they literally don't even provide any evidence of this either (ie that it was Krebs source). It wouldn't help them (because what krebs says does not seem wrong or untrue), but they don't prove it either.
IE even if krebs knew they are the same person, the above appears to be a totally accurate rendering of the story. Krebs is only required to be accurate.
Did a Ubiquiti employee say X in march (or did Krebs have good reason to believe a ubiquiti employee said X in march)?
Did a former ubiquiti developer get arrested in late november?
Yes? (AFAIK, yes)
Okay, case over.
The fact that they don't like his reporting doesn't make it untrue, and if they want to show it's untrue, as I said, this filing does a bad job of it.
It’s as if a bank robber was dressed as an innocent old lady and tricked Krebs into carrying the bags of stolen money to the getaway car. Except here, the robber is in the back of a squad car and Krebs is still transporting bags of cash! It doesn’t matter whether the statements were true, they’re an act of extortion! Extortion is defamation per se.
It seems plausible that he could have a decent chance of having such a motion granted -- the bar is generally "in the light most favorable to the plaintiff [Ubiquiti]". Based solely on the commentary I've read, it sounds like the complaint could be deficient.
Edit: Or at least, so Greg says, and I've found him a reliable source for such things: https://twitter.com/greg_doucette/status/1509184336188350465...
Krebs almost certainly has professional liability insurance (if not, that would be pretty dumb at his scale) I would call up my insurance company, tell them i've been sued, send them the documents, and then go back to my day.
I would then proceed to follow their instructions, and not care too much about it, unless i was asked to do things that i wasn't willing to do
Will never use any product of this company.
I've had enough bad experiences that i recently moved my routing/IDS to a dedicated box and am slowly moving away from their switches.
No reasonable replacements i've found for their APs yet though (Meraki is too expensive).
At home I'm happy with Google WiFi mesh all around my house.
Wasn’t sure where to look next… note taken on Aruba
After they bungled reporting the hacks last year, I promised to never purchase anything from Ubiquiti again. Good to know Aruba may be an option.
TP-Link Omada is a very similar system like UniFi in this price range. Their Controller GUI almost looks the same as UniFi‘s.
Personally I hate the way they're going towards cloud accounts and dedicated management boxes. We used to be able to just install a docker to manage everything but the latest hardware ranges (eg their video offering) require dedicated management hardware. They're also pretty slow with uptake on new standards like WiFi 6 and now 6E.
The ideal selling point of ubiquiti was self-managed near-enterprise quality hardware with free self-hosted management and decent hardware prices.
I can't fully blame them because I know venture capital idealises subscription pricing and data mining right now but it won't work for me and it's annoying having to look for another option again when I'm invested in their ecosystem.
But anyway it would be interesting to read more about what's going on behind the scenes.
If I'm faced with paying premium rates, I'm going with Cisco and premium vendors. Ubiquiti's value was good equipment at reasonable prices to the point that you could buy spares for reliability and save 90% of the cost of service contracts from premium vendors. That differential was the absolute wrong space for them to try to tap for more profit, because nothing else was special about the brand. Cheap, decent, "good enough" network gear is now a market available for exploitation, ubiquiti has lost it.
Exactly, well put.
For what it's worth, as I have been bitten by this practice of "gotchanomics" too many times that I've become a bit sensitive to any signs pointing to it.
I'm not 100% sure Unifi is doing this with their existing products, but new ranges like the video stuff require a modern management box which in turn requires a cloud account as far as I've heard. I've decided not to buy those for this reason. But it undermines my confidence in buying new gear for the ecosystem because it really feels like this will be the next step.
Pera owns ~91% of the company, it all comes from the top.
UI they have been slowly screwing up more and more for years (How many years are they into the "new UI" migration for the controller?).
But the actual switching is pretty basic stuff (and a separate hardware chip they are driving that is not hard to drive), and simply shouldn't be going wrong in this way.
I've also got a UDM-SE and UDM-Pro that seem to have hardware issues on the SFP+ uplink when connected in certain ways (and won't break 500mbps upstream) no matter what SFP+ module is connected (fiber, dac, etc) if the LAN SFP+ port is connected at 10gbps. All the same modules work in every other router (mikrotik, etc) connected the exact same way. (yes, before HN tries to debug this, IDS/etc is all turned off. There are no nft rules, no nothing, i have debugged this to death through the actual shell). Others have had the same issue.
They also have an $1800 ptz camera that can't follow objects even when it detects them (This is 100% basic functionality of a PTZ camera, especially at this pricepoint), despite promising it for years.
I have lots of these kinds of "why is basic functionality broken or missing" stories. Ubiquiti gets it out the door, says they'll fix it all in post, and moves on to the next thing.
They aren't a hardware manufacturer, they are a bad AAA game developer :)
My current favorite was the update to the AP Pro APs that broke everything if you were using a wireless uplink (I was using one to bridge a semi-decent signal to my garage). Clients connected to that AP had zero connectivity to anything else, despite the Controller saying "all good!"
I was thinking of a newer gateway as the USG is too slow to do decent IDS. And the video for my home.. But I didn't buy either for this reason. I looked at it about 2 years ago.
It feels like they want to do the same with the older network gear but they just won't because there will be too much backlash from the move.
However, UniFi Protect is hardware only. You have to have either a UDM, a CloudKey Gen2 Plus, or a UNVR. I bought into Protect a couple years ago and now I'm sort of stuck with it. I _think_ that I could de-provision the cameras from my UNVR and use them standalone with BlueIris or Frigate but I've heard stories that they gimp the RTSP resolution on the G4 Pro camera (of which I have three).
Want your surveillance video to be cloud-hosted or on your own pre-existing RAID? Pound sand!
I think it's still an okay value but you need to watch your flanks.
I manage them with an app on a tablet connected to the same LAN, I've disabled all cloud management. That said, they are almost configure and forget, after the initial install I've only had to upgrade the firmware when I visit the site.
(I reworked our home network to Omada gear last fall. OC200, ER605, a few managed switches, couple of EAP245 APs. Overall quite happy with it; as the person above said it's pretty much fire and forget once you get the initial setup done. Used to use -- and enjoyed -- Mikrotik but alas their wifi support/performance at least on the home front has stagnated over the past several years.)
I bought their largest AP, the 660, attached it to a second floor ceiling, and found it covered my whole home and much of the yard. It supports 100s of clients.
The only thing I regret of theirs is the router (TL-R605). It’s not bad, but the VPN performance is mediocre, and I always wonder if I would’ve been happier with pfsense. Every other piece of hardware has been great.
One thing i have that often limits my choices is that the ubiquiti's are recessed into my ceiling (6 AP's). I can do the drywall work, if they make the mounts :)
If I have to, I guess i can make some from scratch in solidworks, but i'd rather not.
I do like their WAPs. I've got a couple of RS510 WAPs that do a great job, but initially they had some noticeable performance problems for almost a year until fixed by a firmware update.
But i am very happy with the router. I have 5gbps symmetrical internet, and it's one of the few that can handle it for real without BS.
Ruckus is my go-to for access points/ client Wi-Fi. (I manage 1000s of ruck) Excellent hardware. Every AP they offer can have it’s firmware flashed to either fully standalone, OR centralized manage (vSZ / ZoneDirector), OR unleashed (which is AP self-managed for up to 25 local aps). Another much overlook feature of ruckus is that every function can be controlled/modified via SSH. while not as powerful as a true API, it’s still very powerful and often very overlooked.
Anything I should keep in mind before I get more of this brand?
Via Twitter, T. Greg Doucette, a criminal defense attorney and former computer scientist, opined that Ubiquiti's lawsuit would be considered an attempt to suppress lawful speech – a strategic lawsuit against public participation, or SLAPP – in states that have anti-SLAPP laws.
"It's a SLAPP: the coverage by Brian Krebs was substantially true and/or First-Amendment-protected opinion, and the lawsuit basically admits it in the text itself," Doucette wrote. "But Ubiquiti intentionally filed in Virginia, because there's no anti-SLAPP statute there." ®
https://www.theregister.com/2022/03/30/ubiquiti_brian_krebs/
They actually appear to have sued a lot of media companies at a glance.
But it's hard to tell. I think it would be more accurate to say "if you want to sue someone for defamation, they'll do it as long as it's not a conflict" :)
(IE they don't seem to be particularly pro or against anything).
It seems like a reasonable firm to hire for defamation if your goal is something like "get people to retract claim/apologize or go at them legally until they do".
But to your point, it's definitely not the "bury them/grind them to dust with a million lawyers" they would get at a large law firm.
https://www.rcfp.org/anti-slapp-guide/virginia/
It's true it's not the "motion gets ruled on within 15 days, before discovery" type of anti-slapp you see elsewhere, but it's not "no anti-SLAPP"
What really will matter is how favorable the state views the defamation-against-corporation claim, whether it has an anti-SLAPP law or not. If the state views it as strong, anti-SLAPP wouldn't matter because it would survive. If the state views it as weak, anti-SLAPP may kill it a little earlier but it will still go badly for them quickly.
The only practical advantage to the anti-SLAPP for defendants like this is that A. you often can get a faster hearing B. you often have guarantees around damages for bad-faith claims.
anti-SLAPP is much more useful when it's david vs goliath, and the small guy either needs a hearing in a week or two or ends up bankrupt from lawyer fees.
The smaller firms are more likely to be willing to say "eh, it's your funeral".
I'm not sure what they are thinking on this, but this is also the company that wired 46 million dollars to fraudsters, so its obvious they haven't made wise decisions in the past.
If i say "all people wearing blue are pedophiles", i can't be sued by anyone wearing blue because i defamed them :). This is because defamation is, at the core, about injury to reputation of individual people. It's really hard to meaningfully injure the reputation of individual people with general statements (it's not impossible mind you, but for the average joe it's pretty hard).
So first you have to be able to identify what is defamed, exactly. Second, corporations have no reputations in any easily definable personal sense (and remember, defamation is about injury to reputation).
Why do I go into all of this? Because it's at the core of what standard you would have to meet to be liable for defaming a corporation.
Generally three ways to prove defamation of a overall: Prove the person knew that the statement was false and defamatory, or Prove the person acted with reckless disregard of the truth or falsity of the statement in making the statement, or Prove the person acted negligently in failing to ascertain whether the statement was true or false before making it.
The first almost never happens. The second almost never happens. The third is what gets most people.
The third is also, it turns out, not available if the defamation was of a public figures. In fact, for public figures, you have to prove one of the first two by clear and convincing evidence (which is higher than the usual burden of proof in a civil case, which is preponderance of the evidence).
So if ubiquiti, the corporate plaintiff, is held to be a public figure (or some other variant, like a limit purpose public figure, etc), as long as krebs was only negligent (an idiot) rather than malicious (deliberately ignoring the truth of falsity), it still wouldn't be defamation.
Ubiquiti is almost certain to be held to be some sort of public figure - they even sort of out themselves on this by pointing out they file 10-q's with the SEC and expect all their interactions to be with the public.
https://twitter.com/QuinnyPig/status/1509374736903507974 is just an example of how well this is going over.
If Krebs had just been a rube who was used by the hacker, I'd agree with you. But by not updating the record, he's continuing to further lies that he knows aren't true and are/will hurt Ubiquiti's reputation. Given that, I don't think it's as simple as "this gets dismissed as a SLAPP".
Krebs got taken. Pure and simple. I can see why he might not want to acknowledge that, or do any soul searching on it, but when you were part of the problem, you have a responsibility to fix your part in it, even if it was a unwitting accomplice.
It means that a correction should have been issued.
It doesn't seem like it. Either way, Ubiquiti had a major security issue on its hands. Krebs didn't make that true by reporting it, it was true already and he wasn't wrong to say that they did, regardless of some niggling over whether he knew two people were actually the same person lying to him about who they were.
And the bigger issue is, once the truth came out, he should've done a retraction and discussed what he knows about "Adam" and how he was likely the hacker who did the extortion.
> he should've done a retraction and discussed what he knows about "Adam" and how he was likely the hacker who did the extortion.
That's not a retraction. That's an update based on new information. Those aren't the same thing. This is just begging the question of his knowledge. It doesn't really seem like Krebs, even if he is a shitty journalist overall (I know very little about him, so I'm not going to assume one way or another), said anything actually false at the time he said it.
Is a journalist, once they report on a story once, required to continue reporting on that story forever?
Proving that in court seems like it's going to be very hard. Never mind proving that he did it intentionally and with malice. It's not like he gains anything really by not expanding on the story as we know it, and as I've mentioned, it's not even clear what ubiquiti gains from expecting him to talk about new facts that make them look bad.
See exhibit E.
https://storage.courtlistener.com/recap/gov.uscourts.vaed.52...
The cited article suggests that some Federal circuits treat anti-SLAPP statutes as procedural rather than substantive law, and so federal judges might decline to apply them in the cases brought to them.
Flipside, there's a term named "Krebbed" for a reason. https://www.urbandictionary.com/define.php?term=krebbed
Krebs has a history of poor journalism to say the least. Frankly, it's best to ignore Krebs. I stopped reading him years ago.
https://itwire.com/business-it-news/security/new-york-times-...
https://itwire.com/business-it-news/security/infosec-researc...
https://itwire.com/business-it-news/security/ex-wp-man-krebs...
3 separate instances where Krebs got it wrong. Seems to happen a little too often.
Seems clear to me, Ubiquiti got Krebbed.
I remember having a stupid little blog about torrents and filesharing, it was basically a drama blog. People would go on and on about how I had to ensure things were correct and I wasn't a proper journalist because I didn't fact check and stuff. I kept replying, I wasn't a journalist, I was a dude with a blog who people kept telling stuff. So if I was getting that, I sure as hell expect a proper journalist to deal with the fall out if they got it wrong and it cost a company money. Like I would expect a newspaper or tv show to pay out if they cost me money and what not.
I feel like torrents and filesharing isn't going to need much fact checking. Unless you're perhaps talking about lawsuits or something where you might end up getting sued for your words.
>So if I was getting that, I sure as hell expect a proper journalist to deal with the fall out if they got it wrong and it cost a company money. Like I would expect a newspaper or tv show to pay out if they cost me money and what not.
I personally see Krebs as liable. Many other professions have to keep 'errors and omissions' insurance. Sometimes you just get it wrong. Nobody is perfect, you're going to make mistakes.
torrentfreak.com is a current example of a long running blog about filesharing/torrent related news that constantly gets things wrong with no fact checking. Their articles are fine when they're about legal cases, new copyright laws, or actions of governments. But when they report on the goings on of non-mainstream streaming sites or private trackers they're almost completely fabricating their articles - believing the words of any "source" that sends them info without doing any sort of validation on it.
The thing is, in such a community the only real source is going to be sources. The people often aren't going to admit to things especially if it makes them look bad. The one time I did actually go to check something out which was someone told me the nickserv nick wasn't reserved on a tracker's irc and the services were down so people could use it. They then accused me of stealing passwords instead of checking out if what I was told was true. So they want me to fact check but when I do they complain too.
But overall having to believe sources when it comes to criminal stuff is major thing. You can't do much else. For example, look at most gangland reporting. They'll often be wrong because they're dealing with word of mouth.
A former employer of mine was the subject of multiple Krebs pieces. Many of the facts he has reported were incorrect. I have no personal stake in getting involved to "set the record straight" and much to lose by doing so.
There's only so much accuracy you can expect from someone who deals in hearsay. The most credible witnesses won't talk to reporters.
> I guess that's the job of a journalist to ensure what you are publishing is true.
Informants are afforded credibility. The job of the informant is to ensure what they're informing on is true. In any supply chain attack, everybody involved post-compromise is just doing their job.
Journalists are not private investigators and it's unfair to expect them to be. We don't condemn doctors when the patients they trust falsely report/induce symptoms with intent to commit disability fraud.
http://www.aaronsw.com/weblog/hatethenews
There seems to be a correlation that the more you know about a subject, the more likely you think the journalist is simply wrong.
I have proposed the idea that if I put together a big enough group of experts. We might have a group of people who can refute journalism in whole. What if 100% or damned near 100% of what journalists claim is untrue.
I don't think that's the case, I have many good journalists who are across a spectrum of viewpoints who are good at reporting.
In reality, we should hold journalists accountable via Errors and Omissions. Require all journalists to hold E&O insurance. He screwed up, his insurance covers it.
But we do (and should!) expect journalists to issue retractions if they find out something they reported was incorrect.
Waste of everyone's time and money.
Ever since they fired their domestic development staff and shipped those jobs overseas it has been getting worse and worse. And it isn't because foreign developers cannot develop, it is because the company then and since has prioritized cost (and flash half-baked features) over quality.
Meraki competes against Ubiquiti and Aruba InstantOn with Meraki Go, not mainline Meraki.
Thanks to Ubiquiti's efforts, now the story is known to a larger audience.
He seems like the sort of person to take it personally and then go out of his way to find security issues, of which I am sure there are plenty, considering the breadth of software and firmware across all their devices.
This is not a symmetric fight.
This whole thing pisses me off. A insider threatened a company with reputational damage and used a press guy to pull it up. HN picked it up and amplified it. Press guy never corrected the story, and the here we are - with people still railing on HN for a untrue story that the press guy enable that the extortionist planted.
Ubiquiti did not have good security policy as stated in the hacker news post from 3 months ago (cred open to many people etc).
While it’s impossible to completely prevent this, best practices were not followed.
Krebs does tend to just throw stuff on the wall. Conversely, people should not be so influenced by one security blogger.
If you're Brian Krebs and are writing, editing and publishing this stuff yourself, I don't know that you'd have the bandwidth to be able to monitor and correct every new development in something you've written. The New Yorker has a staff of hundreds of fact checkers, lawyers and proof readers just to keep them out of court, and they too seem to have a difficult time with publishing corrections.
I'm not excusing either party, there are issues here that need to be resolved. But the expectation that any part of the press, be it publishing a physical newspaper or running a security blog, will spend much time paying attention to old stories for corrections doesn't match up with reality.
It arguably started when they:
- Shipped tons of jobs overseas, and firmware quality took a noise-dive.
- Stopped letting people run the NVR on their own hardware (with short-notice).
- Required cloud login and an app for setup (something that, for years, NOT having was a claimed Unifi advantage).
- Constantly introducing and retiring half-baked ideas/products/lines.
The whole company has lost focus and certainly lost quality. The recent security kerfuffle certainly didn't help, but mostly it reminded people that their previously "local only" stuff was now Cloud Connected™ by force, and that UB lost the keys that users didn't want to exist to begin with.
- Got acquired by Cisco.
Heaven help us.
The price here is almost the same as the Lite series of Unifi. They also have a Meraki go line but that seems to be yet another one (from an acquisition). But this is also in the same price range.
But the nail in the coffin was their reaction to the whole thing with lawsuits and denials.
- Ads in the management interface
I get it. Telemetry helps with diagnosing issues. But UI’s reaction to being unmasked made me realize they could never, ever be trusted for network infrastructure.
Forcing everything to cloud-connected is what turned me off.
I don't need the devices I use to connect to the cloud to be dependent on the cloud.
Mostly from how the company has shifted their focus as described in other posts.
Then around a year later an update bricked 4 of my 5 cameras, and support was completely useless.
You know, and then they had this huge security issue.
Sure, Krebs reported the security issue, but "ubiquiti sucks" sentiment has largely been Ubiquiti's doing IMHO.
This entire fiasco has hurt Ubiquiti’s brand and reputation, and in no small part Krebs is responsible for that.
2. The "Ubiquiti sucks" mood started with Ubiquiti releasing shit products with even shittier software that, quite incredibly, sometimes even degraded with updates.
If you read his reporting on this now, it is still not clear that "Adam", his source, and the person committing the alleged offences are the same person. It may be he doesn't know but he certainly makes zero effort in either article to address the question.
Ubiquiti's forced cloud BS is more than enough reason for people to move away from them -- they basically dropped out of consideration for my purposes after they did that.
It can also be true that there was a drop in stock price when this incident was reported, and further drops after Krebs' coverage.[3] In fact he even discusses their share price at the tail end of his original article, even updating it on March 31 and acknowledging a roughly $50 drop following his reporting.
I doubt Ubiquiti will win this court case but I do think Krebs damaged his own credibility here.
[1]: https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-b...
[2]: https://krebsonsecurity.com/2021/12/ubiquiti-developer-charg...
[3]: https://markets.businessinsider.com/stocks/ui-stock?op=1
It also doesn't mention anywhere in the indictment who Sharp spoke with, so until it goes to trial... unless Krebs confirms that it was Sharp that contacted him, these are just assumptions/allegations and not something that have been proven one way or the other.
You can't sue journalists for this.
Now, it sounds like they have a bunch of other (factually correct) nonsense going on, they had a leak, suing to try to stop is just an incredibly bad look. I don't even know who Ubiquiti is, but fuck them, they sound like aholes to me.
A random "Tell HN: UI sucks because their firmware went down hill"-post is not likely to go anywhere. But as a comment within an article about UI, sure, that works.
There are many things wrong with UI. An inflated insider security story does not change that.
things like this contribute more to the mood you reference than the reporting from Krebs a year ago, IMO.
Their product direction changed and they're no longer my go-to. It appeared to kill a lot of goodwill from others too.
On the other hand, I hadn't even heard Krebs was going after them until today.
I took that as an un-recommend.
Nobody’s posted a “Ubiquiti sucks” thread from before the Krebs kerfuffle, so here’s one from Nov 2019. In that thread, people complain about a new “phone home” feature and Ubiquiti ignoring the terms of the GPL.
It turns out, there can be such a thing as bad publicity. And like all forms of publicity, there are ways of putting it into a positive feedback loop. (Positive in the sense that you get more of it, perhaps from your perspective it is a positive development, perhaps not).
>Krebs intentionally disregarded these facts
It's easy to miss something when you're not directly involved in a case, even more so when you're also not a lawyer (me) but from what I understand:
Success for Ubiquiti here requires an ability to prove not only that statements he was making (as reported to him by a disgruntled Ubiquiti employee) were false, but that Krebs knew the claims were false. Ubiquiti seems to be arguing that, "because we said these claims were false, that proves he knew they were." That's a non sequitur IMHO.
They would have to prove that he was malicious in writing the article and since it's his job to write articles about security, they're going to have a real hard time doing that.
But that's not remotely defamation.
You can decide to judge him harshly in the court of opinion for not fully disclosing that, but that isn't defamation.
"In March, a Ubiquiti employee warned that the company had drastically understated the scope ... claim was a fabrication. On Wednesday, a former Ubiquiti employee was arrested..."
I'm pretty sure this is junior school level writing, but full stop means end of sentence, and then you start another. There is nothing in the screenshot's text which suggest the former is referring to the same person as the latter; in fact, I read it as expressly making a potential distinction.
"6. Krebs altered his description of Sharp, first he described Sharp as a current employee. He then described Sharp as a..."
Who wrote this beautiful pair of sentences in the complaint, immediately after? Two sentences which clearly should have been one.
If this is the basis of their complaint, I worry for Ubiquiti as a company.
Yes, precisely. You proved the complaint’s point. You think they might be distinct, and the complaint is pointing out that since they were the same person, this writing is intentionally misleading.
> If this is the basis of their complaint, I worry for Ubiquiti as a company.
Slow your roll. You just demonstrated the complaints point.
Regardless of the merits of the case as a whole, #6 is a fair point.
As for the grammar. It’s not Pulitzer level. But there are complete thoughts in each sentence, so it’s not wrong either.
I disagree (with the complaint, not with you). For one, if Sharp _was_ an employee in March and not at the time of writing, it is accurate to write it as-is, is it not?
The ad makes a couple of statements of fact, which parse true by my reckoning regardless of whether or not that person is one and the same.
I'm interested to see what comes of this, it feels to me like desperate swinging looking for something to make contact with.
Having filled my home, and recommended to many colleagues Ubiquiti gear, I have been nothing but disappointed with their output of late, so much so that I recently began switching away from their gear, there is _something_ going on within Ubiquiti and it smells off.
This is something you have to be very careful about in patent claims.
1 - https://en.wikipedia.org/wiki/Robert_Pera 2- https://www.fool.com/investing/2021/09/28/3-stocks-with-78-p...
Any legal eagles here who can clarify this aspect? Is "I was just repeating what your executive told me" a get-out-of-jail-free card?
. knew that the statement was false and defamatory, or
. acted with reckless disregard of the truth or falsity of the statement in making the statement, or
. acted negligently in failing to ascertain whether the statement was true or false before making it.
Not vetting your sources can be seen as acting in reckless disregard of the truth or acting negligently in failing to ascertain whether the statements were true.
Honestly, all I would like to see here is a correction from Krebs, that enlightens people more about the risk of insider attacks, the role that the media can play in that.
Issuing a retraction can potentially lessen the damages if the original statement leads to liability, but that's only relevant if the plaintiff first wins on the original statement being defamatory.
The right outcome here would be some form of retraction, and more visibility into how this came about in the first place.
As with all insider attacks, it's almost impossible to stop someone from doing the first bad thing, but you should have controls in place to easily identify who the bad actor was. Ubiquiti eventually did - with the assistance of the FBI, but not after the damage was done.
On the other hand, Krebs not vetting his source, and allowing this through resulted in a 20% drop to Ubiquiti's stock - which affected the company, their employees (who have a financial interest in the stock) and played into the attackers hands.
I'd like to see both of them come together and do a real strong analysis.
That said, the negative "tone" that came from these articles persists - take a look at this thread for evidence.
How many people know that Ubiquiti dropped the cloud login requirement? That their recent firmware and releases have been impressively solid (judging from my and community experience)?
I don't want Krebs or Ubiquiti to "win" here, I want people to behave ethically.
The public speech -> printed statement -> online publishing transition problematizes the meanings of "retraction" and "previous statement". Probably not legally, of course, but I'm thinking about the ordinary usage of these terms here.
Lots of traditional journalism outlets also publish online, but the way the reporting ends up being used is very different. Anything they put on their websites tends to live forever, and it's often difficult even for careful readers to remember to check the publishing dates.
If an article was published a year ago, but the page itself doesn't carry a retraction notice, I often assume the published information continues to be accurate. The lack of a retraction on an easily editable webpage indicates to me that the publishing individual or organization continues to endorse the material, as if it had been published the day I read it.
That's why organizations with journalistic integrity are so careful to add retraction notices to incorrect articles, even for small changes. I doubt it amounts to defamation to not add such a notice, but it certainly makes the violation of journalistic integrity much worse.
Anyone else here who would have remained ignorant of this all absent this lawsuit?
Streisand Effect 1 - Ubiquity 0
Is there a more detailed write-up somewhere about what happened exactly?
Basically, insider used his credentials as a highly trusted resource to access internal repositories. He then anonymously blackmailed the company, threatening to go public as a "external actor" if the company didn't pay him. The company instead got the FBI involved - which Sharp was aware of because of his role at Ubiquiti. He then lied to Krebs at least once (probably twice) claiming first that a external actor had breached ubiquiti and the company was deliberately covering it up.
No. My internal network infrastructure should NEVER depend on someone else's computer, ever.
They are suing for defamation because Krebs failed to retract anything after more information was revealed.
Ubiquiti must have solid ground to be dragging themselves into this mess? I mean, from one side - it looks like a lot of people are on Krebs side, awesome. But, from another - no one at Ubiquity expected some kind of a pushback?
Not as much as you might expect.
There are so many times when I have seen cases made purely to save face or to be offensive as the best form of defence. I can't say whom but a Solicitor I know has told me of a number of cases she didn't expect she could possibly win in Court but the client had the money to pursue it to make some kind of point and didn't care whether they would actually win or not.
Not saying Ubiquiti don't have a good reason, just that they don't necessarily have one.
Telemetry, declining quality, outdated software (log4j was so old it was hard to patch), NVR discontinued, and now this. It's over for me. I will never sell ubnt again.
I liked there positioning in the market, it was my goto solution for small to mid deployment, up to 20AP.
A few days ago, a customer got their nvr hacked and it started (well, it tried) to mine crypto. I had told him it would happen eventually so I limited the nvr user permissions and resources to the strict minimum, which mitigated the attack.
I ended up coding an in house solution, with a mix of ffmpeg rtsp->hsl bridges and motion for motion detection. Nothing fancy, a few scripts and a few html pages.
[1] I have no idea which side is correct, I am just amusing Ubiquiti's claims are correct.
Many countries have laws specifically outlawing this behavior.
If you're curious specifically about the intersection of those laws and the rights afforded by the First Amendment in the United States, read https://en.wikipedia.org/wiki/Defamation_and_the_First_Amend...
Defamation can occur, and can be pursed legally against you, if you publish a blog where you knowingly proclaim something false that damages someone's reputation.
https://en.wikipedia.org/wiki/Defamation#United_States
"Defamation law in the United States is much less plaintiff-friendly than its counterparts in European and the Commonwealth countries. A comprehensive discussion of what is and is not libel or slander under United States law is difficult, as the definition differs between different states and is further affected by federal law."
...but, there is such a thing as defamation/libel/slander in US law.
On the one hand we need openness with regards to reporting breaches.
On the other hand we need truth in reporting. Krebs seems to be teetering at the edges. I’d rather have solid reporting without the drama.
I was also not amused when he started defending anonymous shell companies by saying "Not everyone who uses shell companies is trying to launder $$. Some people just really value their privacy."
https://twitter.com/briankrebs/status/1336487678301364226
I'm guessing that in addition to third-party WHOIS privacy, Krebs also has a shell company. Privacy for me, but not for thee.
More information: https://en.wikipedia.org/wiki/Security_through_obscurity
They're basically suing because he didn't retract or update and clarify his (really false) initial story. Krebs was taken for a ride by his "source" who it appears was a disgruntled employee, causing the damage.
Should they have handled the situation better? Sure.
Will they win their lawsuit? Unclear; they've got a big hill to climb to it seems unlikely.
Is this in any way "silencing" discussion about it? No, it is doing the opposite, and it's not as though Ubiquiti is unfamiliar with this, given their history.
Anyone remembers when Krebs doxxed the admin of cock.li because they disagreed with Krebs on spamhaus' black listing policy? [1] (Spamhaus just blacklists all TCP SYNs, which can be easily spoofed since it's not the complete handshake)
I don't know. I believe that Krebs has usually good intentions, but sometimes he is just presenting his findings in a very malicious way.
I don't shed a tear for that person though, as someone who has gotten about three dozens of murder threats that were sent through their service.
cock.li is an awful service that serves no legitimate purpose other than enabling people to cause harm. The admin should have been arrested at 36c3 by the police instead of simply been booted out for his neo-Nazi domain names, but unfortunately our police is incredibly incompetent.
You see, people are using Tor to buy drugs and to share child porn. Does that make tor a tool "that serves no legitimate purpose other than enabling people to cause harm"?
I am a happy user of cock.li, because it's one of the only few email providers, which don't require my phone number (unlike gmail, outlook etc). I don't mind that they also offer domains joke domains such as "hitler.rocks", since I know what a joke is.
https://en.wikipedia.org/wiki/Poe%27s_law
Not judging one way or the other, just saying that it's incredibly risky to make jokes like this, especially in the current climate, where the narrative and emotional response matters more than facts and rationality.
Not complying with court orders for information disclosure is also either a crime or a serious infraction (Ordnungswidrigkeit), too.
As said, the guy got lucky he didn't get arrested like he should have been.
I feel like the law would be especially difficult to apply in this context given that the domain names offered by cock.li are obviously picked for the sole purpose of causing offense, not to promote an unconstitutional organization.
Let me translate the key section of his letter: "Section 86a of the Criminal Code is located in the third title of the first section of the Special Part of the Criminal Code. The offenses of this title criminalize acts that constitute a 'threat to the democratic constitutional state.'" The protected interests of the provision are political peace, the free democratic basic order democratic basic order, the idea of international understanding, and Germany's reputation abroad. The ban serves [...] to prevent the revival of the banned organizations or the aspirations they pursue [...]."
"Hitler.rocks" is not falling under this, since it is not a "threat to the democratic constitutional state". That's also why satire magazines like "Titanic" are allowed to publicly show Swastikas on their front page. [2]
A domain about hitler minerals [3] which does not aspire the revival of banned organizations such as the NSDAP, (there isn't any nazi glorifying content on the website), does not reflect a threat to Germany's democratic state. At least I hope so :)
[1] https://www.bundestag.de/resource/blob/869290/c8bd5f14ef172e...
To Krebs, false means he did not accurately report the information as presented to him. In that way he is correct.
To Ubiquiti, false means the information was willfully inaccurate, should not have been deceptively presented to a notable authority in the tech field, and this should not have been published.
Ubiquiti has to sue Krebs to show that the damage to their reputation was related his reporting which they can tie back to Sharp. Krebs has to defend his standpoint to show he was not complicit in Sharp's planned sabotage. I expect they'll settle once the sides are fully aired.
The bar to show defamation in a case like this is very high. Ubiquiti isn't going to meet it.
To clarify the phrasing, the disgruntled employee caused the damage to Ubiquiti. He was the one who "hacked" Ubiquiti (actually he misused his credentials), was the "whistleblower" that fed Krebs information of his own "hack", and tried to blackmail Ubiquiti. All while he was a Ubiquiti employee... assigned to investigate the "hack."
Ref:
https://thenextweb.com/news/ubiquiti-ex-employee-hacker-whis...
https://www.securityweek.com/former-employee-accused-being-b...