Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

51–60 of 486 posts

Re: Ubiquiti Networks Breach

#51

Ubiquiti is in a weird market, where they are better than Linksys/Netgear etc, but they are crap compared to something like Meraki. Their support isn't very good (they point you to a forum), their hardware replacement is spotty (sorry, out of stock, you'll have to wait!), and their hardware/software is buggy. We had 48 port switches that would randomly reboot, for example. They can be a decent solution for SMB wifi,…

Are there any 48 port switches you would recommend? I've concluded that they're overpriced compared to multiple 24 port switches for example but I'm hoping I'm wrong. Never heard of Meraki for example.

Re: Ubiquiti Networks Breach

#52

Ubiquiti has typically been the "cloudless" provider which is why I've used their stuff. They've been sorta moving in a disturbing direction for cloud control. I don't want that risk.

Cloudless if and only if you run their gigantic bloated Java network management tool. I really like ubiquiti hardware but I got fed up with their software BS. Now I use either Mikrotik or TP-Link’s industrial offerings. Both are way easier to work with than ubiquiti and the hardware is usually in the same tier.

Mikrotik? Easier?

Do not get me wrong, I love Mikrotik, but easier would not the word I would be using. This image (https://www.reddit.com/r/mikrotik/comments/jyjgnc/mikrotik_v...) sums it up neatly.

Also, Mikrotik is not directly comparable, you cannot replace Unifi Controller with Capsman.

Re: Ubiquiti Networks Breach

#53
post #24
post #20

At least we know third party have access to our salted passwords et. al?

Sounds like their cloud provider environment was breached. If that's the case then access to databases with salted and hashed passwords is to be expected, is it not? Would be good to know which provider this is and whether it was the fault of the provider itself.

You are right. Would be interesting to know who it is. Couldn't find anything for AWS atm. That could be big, but let's hope it's nothing to worry about. I appreciate they communicate this notice asap. Even if we don't have the details yet.

Re: Ubiquiti Networks Breach

#54
post #45

Earlier quoted context omitted.

It's impossible to secure yourself against a devoted persistent threat group over the long term. The asymmetry of effort is not tractable to overcome. So they can take your security seriously, but they will be hacked, or they have already.

I think it is possible to secure yourself against a devoted, persistent threat group. I think it's expensive, but possible. Do you have data to back up your claim that no one, ever has ever successfully remained secure?

My name is Ozymandias, King of Kings; Look on my Works, ye Mighty, and despair!

Re: Ubiquiti Networks Breach

#55
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

> That phenomenon is called counter-signaling, which I first ran into listening to Dan Jurafsky making the point that if a menu uses the word "fresh", its a low-brow restaurant. A high-brow restaurant would never use the word "fresh" -- the freshness is implicit in the other signals. https://kelley.iu.edu/riharbau/cs-randfinal.pdf

source: https://news.ycombinator.com/item?id=25713050

Re: Ubiquiti Networks Breach

#56
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

It's impossible to secure yourself against a devoted persistent threat group over the long term. The asymmetry of effort is not tractable to overcome. So they can take your security seriously, but they will be hacked, or they have already.

I don't think my post argues, or even attempts to argue, against your point.

It was a light-hearted jest at the fact that this exact line is in every single breach notification I have read for the past few years.

The more serious point I was alluding at was not "just don't get breached", it was that the "we care" line rings hollow after the 250th time reading it.

Re: Ubiquiti Networks Breach

#57
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

They opted to TELL people about it which is a good indicator. I’m sure there’s many companies who choose not to (which may be against the law). It’s also HR spin on the topic, but iirc ubiquity offer bug bounties on a range of devices they sell so there’s at least some truth to the spin.

‘We know they breached but don’t know what they did’ is an interesting statement. One POV is that they didn’t have sufficient logging and segregation to determine how widespread the breach was, the other is that they’re not arrogant enough to think their SIEM adequately captures everything.

Re: Ubiquiti Networks Breach

#58
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

I mean, should they say that they don’t care about your security?

they should tell me, what they are going to improve. :)

Re: Ubiquiti Networks Breach

#59
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

I mean, should they say that they don’t care about your security?

Weird polar opposite stance.

No, that is not what I'm saying. I'm saying don't put platitudes in a breach notification.

Re: Ubiquiti Networks Breach

#60
As someone who was planning on buying Ubiquiti hardware for their house, this breach and a lot of the comments here are disconcerting. Are there any other alternatives that are more locally managed that people would recommend?
Post reply on HN