Earlier quoted context omitted.
Sounds like their cloud provider environment was breached. If that's the case then access to databases with salted and hashed passwords is to be expected, is it not? Would be good to know which provider this is and whether it was the fault of the provider itself.
As some of the IPv4 addresses for ui.com seem to be assigned to AWS I'm not sure what to make of it.
Ubiquiti Networks Breach
61–70 of 486 posts
Re: Ubiquiti Networks Breach
#62Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…
Re: Ubiquiti Networks Breach
#63edit: I have since received the email
Re: Ubiquiti Networks Breach
#64Earlier quoted context omitted.
It's impossible to secure yourself against a devoted persistent threat group over the long term. The asymmetry of effort is not tractable to overcome. So they can take your security seriously, but they will be hacked, or they have already.
I don't think my post argues, or even attempts to argue, against your point. It was a light-hearted jest at the fact that this exact line is in every single breach notification I have read for the past few years. The more serious point I was alluding at was not "just don't get breached", it was that the "we care" line rings hollow after the 250th time reading it.
Re: Ubiquiti Networks Breach
#65Ubiquiti is slowly becoming Sonos. The difference is, their potential for bad behavior, risks and attack surface is far, far greater.
Re: Ubiquiti Networks Breach
#66Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…
Re: Ubiquiti Networks Breach
#67Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…
Re: Ubiquiti Networks Breach
#68No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"
They opted to TELL people about it which is a good indicator. I’m sure there’s many companies who choose not to (which may be against the law). It’s also HR spin on the topic, but iirc ubiquity offer bug bounties on a range of devices they sell so there’s at least some truth to the spin. ‘We know they breached but don’t know what they did’ is an interesting statement. One POV is that they didn’t have sufficient loggi…
Re: Ubiquiti Networks Breach
#69https://help.ui.com/hc/en-us/articles/115012240067-UniFi-How...
Re: Ubiquiti Networks Breach
#70Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…
Did you happen to write up the results of your router tests? I'd be really interested in reading up on them! I recently picked up an old Apple Airport Extreme so I could easily set up Time Machine backups on my network, but obviously Airports have their own host of issues so I'd be really interested in upgrading soon.