Ring LLC home security company ransomed by ALPHV ransomware
web.archive.org
web.archive.org
- Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers.
- I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge this.) (I am not a lawyer, this is not legal advice.)
Software engineers & security engineers can make just about anything secure. But we can only do so if we're given time and money to hire the expertise when needed. We need to make it incredibly expensive for companies to lose personal data like this. Management teams should be clamoring to hire the best security engineers. But they'll only do so if they're sufficiently motivated.
The risk of massive liability is the right incentive to convince companies to invest in getting information security right. The current status quo is ridiculous.
Don't tell us, tell your legislators. Ideally with some kind of narrative that ties to a financial incentive for the lawmaker and his or her constituents.
If the security industry got together and lobbied for this as both a jobs program (security companies offering services to tech companies) and as a means of protecting Americans/constituents, then it might get somewhere.
Absofuckinglutely. Never talk to a politician without remembering that if they don't get a cut...
Most voters don't care about digital security. That means most politicians, reasonably, don't care either. Most voters do care about their economies. So linking what you're talking about to talking points the political can use is helpful. Not because they're going to get a cut.
This doesn't protect your PII data though. This is not a good situation at all.
[1] https://support.ring.com/hc/en-us/articles/360054941511-Unde...
Limited notifications,.loss of timeline feature, inaccessible on desktop and other non-mobile platform
and well.. here we are.
If there is a breach, all of your data is accessible because it is decrypted at the endpoint.
This was very informative and changes my views on a few things.
Got any suggestions for OSes that are easy to secure and easy to run 24/7?
No data leaves my LAN unless I want it to.
The most painful part of the whole process was the YAML files for Frigate.
I found leaked details of Royal Mail's negotiations with their attackers fascinating [0].
I'm not sure it's practical to outlaw the payment of ransoms, but it should at least be heavily taxed (say, 100%). Naively, I would expect this to cut by half the amount that can be extorted through ransomware attacks, making countries that implement such a tax less attractive targets.
[0] https://www.theguardian.com/business/2023/feb/15/under-no-ci...
One of these is more universally repulsive than the other. Were it illegal, I'm not sure I could be bothered to blow a whistle on a company paying a cyberransom. That's obviously different for murder.
Reporting the murder will see the community punish the family for not protecting the person better.
> LockBit refused to accept the explanation and accused the company’s negotiator of “bluffing”, speculating that the company’s directors probably held £100m of cryptocurrency personally that could “finish this nightmare”.
I think innovation will happen regardless and I'm kinda tired of fear mongering around "throttling innovation" whenever people talk about making our world better for people.
Personally I think that is a price worth paying. Laws like the parent are suggesting are about having a standard that companies need to meet if they want to operate in a given space, and currently it is clear that companies will not meet these standards unless they are legally obliged to do so.
- Why so expensive?
- Where did all businesses go?
- Let’s create a certified secure data enclave companies!
- Why so expensive still?
- We can’t charge a certified company because it would damage half the economy!
Want cars not to explode when slightly rear-ended? Why are they so expensive now? Where did the car businesses go? Let's create car security companies! Why so expensive still? ...
I can't make a car company. I can make a webcam on doors company.
And you might say it is about raw materials. But I can buy enough materials for one car and one webcam door. I can't put the car on the road (as much as it make sense) only because of the sheer amount of cost required to pass regulations.
So while regulation is something we want as costumers. I think we'd prefer to not have it become a obstacle in the software sector to the point it exist elsewhere.
That is why I think the GDPR is great since it applies to companies with 250+ employs.
Alternatively looked in the metaphor, cars are dangerous things - for the passengers and civilians nearby. We as a society don't want any random vehicle to be on the road due to the risks involved. A webcam door doesn't have this type of risk associated, so it's fine to DIY and whatever. However there are still risks, like PII leaks, so these they need to be mitigated too.
> That is why I think the GDPR is great since it applies to companies with 250+ employs.
No it doesn't? It applies to any company that holds EU citizens' PII.
Well I guess I fell into this myth:
https://www.vistra.com/insights/if-i-have-fewer-250-members-...
Which do give some exemption to <250 people companies but not to an extent that I said.
i would also be glad that not anyone would make a air traffic control or a train signaling system.
while i like foss programs and have low barriers of entry in any field, there needs to be a minimal standard that everyone shoud adhere to where a system failure could affect someones life beyond minor inconvenience.
This is zealous. If consumers don't care, and nobody can show tangible damages, "massive fines" and "criminal charges" are closer to moral outrage than prudent lawmaking.
I don't care if people around me don't have car insurance, but once one of them crashes into my car, i sure want them to have one, while the rest will continue not caring.
So yes, requiring companies to safeguard data, even if that means fines and criminal charges for responsible people is important.
I think there are those who don't care, and those who care but don't know better in the face of misleading marketing.
Pragmatically, it might be the right thing to do, but it feels wrong. Would you consider a due diligence to security threshold? That would certainly make it easier the well resourced to weasel out of fines, but when a small startup comes up against a well resourced nation state level hackers with a catalogue of 0days what are they supposed to do? Just go out of business?
Wouldn't you want your bank get fined if they aren't secure enough and loose your money? Or your local government if they loose your tax records because they think they don't need to lock their door?
The hard part will be determining whether the company could have done something about it (like locking the doors or the windows). If they could, they for sure should get a fine if they didn't.
This isn't an appropriate comparison. I'm not a lawyer but I would imagine this would fall under negligence. Businesses are liable for improperly securing dangerous materials in the physical world.
The type of locks you have affect the price of your home insurance, in the UK at least.
Really? Is it that hard?
The extension ringer is a great idea too. Place it wherever you will hear it...ding-dong...there was someone at your door about 20-30 seconds ago.
Seriously! A doorbell with a camera, the camera won't connect, the bell won't ring
Video is also being archived locally elsewhere on my home network, but no outside hosting is needed for either instant live access or home archiving. Just a minimum of research.
When shopping for a camera, only buy one that has ONVIF compatability. Then you can use it with third party apps.
Yes, $1000 phones work fine, but every other device? the standard must be a mess because every other wifi certified device is unreliable.
Everything on my house that can be wired, is wired.
The Vice story has more context: Ring denies any compromise to their own systems (and if you can't find the ransomware it's not doing its job very well), but there is a third party vendor with no access to customer data who is currently affected.
https://www.vice.com/en/article/qjvd9q/ransomware-group-clai...
It's going to be really bad for customers but it's okay. I'm sure we'll get the "We value privacy" compulsory email any day now.
maybe we are just missing the news.
May not be Ring directly, could be in 3rd party supplier with an undetermined level of data access https://twitter.com/TheRegister/status/1635506291232894976
Either way, bad look for a company that pitches itself as a home security company.
"Hey, we said your home would be secure, not our architecture."
There’s since been an important follow-up tweet:
> Ring denies being a victim of ALPHV. Ring has stated to various media outlets they believe a 3rd party vendor has suffered a data breach.
And a relevant reply:
> I mean, file under MRDA, but Ring told me earlier today that "We currently have no indications that Ring has experienced a ransomware event."
So there goes a janitors job, secretaries etc. Local cafes, bars, transport lose out. The dependents of all the company are now involved. There's a long chain of consequences after this. Why not just target the guilty: maybe any punishment should make them suffer.
Also, I find your "but you have to think about the children^WJobs" argument pretty hollow. Nothing can be changed, because some gay lesbian from a foreign country might loose their already precarious job. Come on, is this really an argument for something?
The same argument is made for why breadwinners shouldn't get jail time when they commit a felony.
I agree. It would be better to make execs personally criminally liable.
Regardless, plenty of places need janitors and the likes. They'll find other jobs.
If anything, there will be more jobs created by the demand to shore up security. They'll be high quality jobs too, as management will be reluctant to outsource potential criminal liability to incompetent contractors in India.
Will be interesting to see what happens.
Seems more like a home insecurity company to me.
And why is it an LLC?
I guess I shouldn't be surprised that a company with such a terrible ethical track record is a part of the fractal of dark patters that is Amazon.
But I would pretty inclined to distrust a "security" company that has "Limited Liability" in their name when they store a lot private data serverside. Doesn't exactly inspire confidence in their commitment to actual security and not merely convenient insecurity which seems to be their actual product.
Hence the question.
And another point. You might not think video outside your home matters, but it could be invaluable to burglars who want to know when you're not home. I could imagine it being used to deanonymize location data as well because it would provide known locations and timestamps to filter data against.
They can also just park on the street and watch you…
So you could make an argument that woth their terrible security track record, numerous leaks etc Ring is more of a help to potential burglars than it is useful as a security device.
Differences between countries are funny. For instance, in France Rings don't fly because you're filming a public place, and by default people have an expectation of privacy and the right not to be filmed. If you want to film a public place (like put a camera that covers the street), there's a specific process to follow that includes getting a permission from the privacy authority, putting up warnings, and having processes (who has access to the videos, when, why, etc.).
https://www.vice.com/en/article/qjvd9q/ransomware-group-clai...
Edit: because twitter doesn't load on this particular device I use for HN. Basically the browser is too old. There is no "hate" ... ffs
Nitter is meant as a privacy-friendly Twitter front-end, but I mainly use it because Twitter takes literal seconds to load a 280 character post and Nitter works almost instantly. As an added bonus, it doesn't rely on Javascript to render.
For example: https://nitter.net/vxunderground/status/1635427567271329792