6 ms·
Mr. Sharp is apparently not so sharp. He carried out the attack from his home network. He connected directly for enough time that his bare IP was logged. The re
by mjamil 5y ago
Mr. Sharp is apparently not so sharp. He carried out the attack from his home network. He connected directly for enough time that his bare IP was logged. The rest of the time, he carried out the attack using a commercially purchased VPN solution that was trivial to trace back to him via the purchase record. He lied to the FBI. (I have yet to understand why people talk to law enforcement instead of staying silent so as to not implicate themselves.) And, for no apparently good reason (meaning, there's no claim of him shorting the stock), after the raid, he seeded fake news that drove the company's stock down 20%.
- 1cvmask 5y agoGuess he should have bought a VPN with cash or stole someone else’s if Mr. Sharp wanted to be more sharp about it.
- trhway 5y ago>SHARP falsely stated, in part and substance, that someone else must have used his PayPal account to make the purchase. and to me it looks like somebody intentionally left breadcrumb trail leading to the guy. With cloud paying so nice these days nobody is going to risk that way for the paltry $2M (ie. less than 3-4 years earnings in Bay Area for the people like this). It looks like the stock price drop is the real "follow the money" trailhead, and that doesn't lead to the guy. And given that it were about Ubiquiti customer databases - the value of [stealth] access to those customers may possibly dwarf those few billions of valuation drop - so even the stock drop may have been a smoke screen. I mean Ubiquiti as a target reminds me of SolarWinds. Those comments back then is also interestingly predictive https://news.ycombinator.com/item?id=26692987 https://news.ycombinator.com/item?id=26692987 - having a fall back guy kind of absolves the company from architectural and operational sins which allowed the hack and pacifies the customers who otherwise would feel unease of being possibly hacked by somebody serious.
- 1cvmask 5y agoYes your point is valid. It doesn’t seem that they did find any unusual shorting activity though as is or used to be how they went about it in the old days.
- deleted 5y ago[deleted]
- Hamuko 5y agoAre you saying that someone purchased a VPN account using his PayPal account and by sheer coincidence, while that said VPN account was in middle of data exfiltration, his home IP address also connected to said servers with no connection to the exfiltration?
- DangitBobby 5y agoI mean... That is what someone who's setting up a patsy would do if they could. Home networks are not exactly Fort Knox, are they? I had a bunch of rogue connections banging around trying to brute-force database logins within my home LAN earlier this year. I imagine they could have made a connection to a server look like it originated from within my LAN, and if I wasn't watching a live feed of my database connection logs at the time I never would have noticed.
- Thorrez 5y agoWhy, after he realized his own PayPal account had been hacked and used to hack his own company, would he then become a whistleblower and accuse his company of not investigating the hack? He should have been spending his time finding out how his PayPal account and home network got hacked, not talking to journalists accusing the company of not handling the hack correctly.
- 542354234235 5y agoThis seems like a series of unfalsifiable claims. Taking evidence linking him to the crime and saying “That is what someone who's setting up a patsy would do” pretty much means anything and everything becomes “proof” of the conspiracy.
- trhway 5y ago> evidence linking him to the crime keyword is "evidence". Whenever a sympathetic person/cause becomes a target of IP-address based evidence HN is overflowing with posts that IP-address isn't an evidence :)
- dotBen 5y ago(I have yet to understand why people talk to law enforcement instead of staying silent so as to not implicate themselves.) When the FBI knock at the door you totally do the whole "no comment/talk to my lawyer" thing. But what happens next if you're actually part of an investigation is they hand you a grand jury subpoena (which they were going to do anyway, even if you just talked willingly, because they have already gone to the trouble of asking a judge to issue one and have it with them by the time they ring your doorbell) That subpoena is likely to require you to hand over any digital records you have related to the investigation (you can't plead 5th on that) and turn up at a time and place to be interviewed (you have to turn up, even if it's on the other side of the country eg in the Southern District of NY in Manhattan and you live in SF Bay Area). BTW I don't think people widely realize the government has the power to compel you to hand over EVERY piece of material you have on a given subject they are investigating - eg search and share anything from every email you have ever received since you signed up for GMail in 2004, etc. You can plead 5th during the interview but if you have material information (or are actually guilty) and knowing they have all of the documentation subpoenaed and whatever other evidence from other subjects/targets/witnesses, it will likely help you at that point to be cooperative via guidance from your attorney. Remaining silent at that point is just going to leave you at the mercy of whatever other witnesses/subjects/targets convey and their own conclusions from the subpoenas. If you are on a visa or green card you almost certainly can't plead the 5th because they can leverage your right to remain in the US. So, that's why people typically talk to the FBI. It's not at the doorstep when they first engage you, it's once you have been compelled to participate. Related/useful: https://www.natlawreview.com/article/you-received-grand-jury-subpoena-what-now https://www.natlawreview.com/article/you-received-grand-jury... Source: happened to me a number of years ago, although I wasn't guilty of anything. Lawyered up, cooperated, no further action. Wasn't pleasant. IANAL, not legal advice
- gonehome 5y ago> "it will likely help you at that point to be cooperative via guidance from your attorney" guidance from your attorney seems to be the critical bit of that - it's okay to talk, but with your lawyer present.
- 5y ago
- mdip 5y agoWhile I agree that the mistake Mr. Sharp made -- it sounds like he had a network disconnection which briefly caused him to perform actions via his home IP address, rather than his VPN address -- we also don't know everything here. It doesn't sound like the guy was all that sophisticated. Using a VPN provider, in the first place, can make you a whole lot easier to be caught depending on the circumstances/provider trustworthiness/jurisdictions. I recall that there were providers which accepted cryptocurrency, but chances are good if he couldn't figure out how to block all traffic when the VPN was down, he'd have made several mistakes trying to keep the Bitcoin/Ethereum from being traced back to him. For a crime like this -- as serious as this was, with the damages involved, the company and its internal resources/practices -- he probably had no prayer of getting away with it and in a Dunning-Kruger-like manner, he not only didn't know what he didn't know, I don't think there's any way he could have known enough about his adversary's capabilities to get away with it long term. If a criminal wishes to be successful in getting away with a serious crime without getting caught over their lifetime, that criminal must successfully thwart detection from all current and future technologies. I mention serious because those crimes often do not have a statute of limitations these days. I'm assuming a perfect law enforcement body that similarly makes no mistakes, so a "luck factor" weighs in, but given a (not too) high-profile crime with motivation, budget, competent investigators and expanding technology, I'll law enforcement is gong to rank higher in the luck category. It's not enough to look at what they're capable of currently. Consider this scenario: A murderer with Type O+ blood (with other common properties) strangles a man with a wire in 1980 leaving behind only that wire as evidence. In the struggle, the wire also cut the murderers hand and deposited a tiny drop of their blood on it. Being that it was a small item stored for an open case and was well preserved, it's still there, today. Luck. Back in 1980, it was of little evidentiary value. Today, that drop has a good chance of producing a DNA profile. Has the murderer been arrested (not convicted) of a felony in the last few decades? They'll probably be caught. Did a family member use certain (do they all do this?) consumer DNA services? Their family might be found, which will narrow the suspect down to a pool of people. Forget drawing suspicions by getting warrants, because it takes so little biological material and you deposit it everywhere you go, the police just wait for garbage day or follow you around town, grab something that came into contact with your mouth and they've get a profile (which will be used to get an easy warrant for a blood sample to confirm it). Budding criminals, are you storing all of your secret plans on your drive in a bullet-proof encrypted manner and ensuring that it is airgapped? Are you doing all of your secret research on a similarly configured device, but configured to ensure all networking only works via Tor? Are you sure you didn't make a mistake that couldn't rise to the standards required to get a warrant to image your drive/take your equipment (that's hopefully turned off)? That bullet-proof encryption is rotting, and 30 years from now could represent a small hurdle above plain text. And what happens when the time required to investigate crimes is reduced further? "We'll get around to bike theft when we're done solving all of the murders." But what if solving a small percentage of the bike thefts went from "complaint" to "likely suspect" almost instantly if certain circumstances were right. For instance, imagine law enforcement could automate geo-fence style warrant requests (requests to get "people in a location at a certain time" from Gooble/Apple/mobile phone provider histories[0]) for every bike theft where the bike was stolen from an area infrequently traveled where and the time of the theft is known to within an hour. For any where the there was exactly one person logged, you have a person of interest -- probably the thief. Not enough evidence to prove a crime, but enough to scare some of the petty thieves into giving up more evidence through questioning (or maybe just give up). It's a stretch, on purpose -- but as technology make solving crimes less costly, less serious crimes will be prosecuted more frequently/reliably. Full disclosure: My only credentials in this area are working in Corporate Security at a multi-national (large) telecom company for a brief stint and in a security/development capacity for most of my career; except for that brief stint, all of my work has been on the defensive/strategic side, not on the investigative side, and never with violent crimes of any kind. I simply enjoy security topics, in general, but if I've shown my ignorance in a few areas, my apologies and feel free to correct. [0] Assuming this data is kept long enough; I am going to hazard a guess that it is a lot longer than most people think.