Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

81–90 of 486 posts

Re: Ubiquiti Networks Breach

#81
I did a double take after clicking through- when did Unifi change their URL to UI.com? I thought this was a clever scaled phishing attempt for a second.

Come to think of it, how many times have they changed their URL/how many are there? feels like im being trained to do something stupid.

Re: Ubiquiti Networks Breach

#82
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

The real genius in the announcement is, "data hosted by a third party provider". Absolutely irrelevant, but subtly implying that the error was the fault of a third party.

That will be the new norm in these kinds of annoucements, I'm sure.

Just like SolarWinds dropping "Team City", saying "no evidence" of a breach of it. So why mention it at all?

Re: Ubiquiti Networks Breach

#83

Ubiquiti has typically been the "cloudless" provider which is why I've used their stuff. They've been sorta moving in a disturbing direction for cloud control. I don't want that risk.

Cloudless if and only if you run their gigantic bloated Java network management tool. I really like ubiquiti hardware but I got fed up with their software BS. Now I use either Mikrotik or TP-Link’s industrial offerings. Both are way easier to work with than ubiquiti and the hardware is usually in the same tier.

You can also just run a docker container for it [0]. This has the added benefit of separating your data from the runtime so you can move it around as if you had a physical cloud key.

[0] https://hub.docker.com/r/linuxserver/unifi-controller

Re: Ubiquiti Networks Breach

#84
post #40

I must admit - Ubiquiti has lost some of it's shine in the last few years, whilst AP and routing hardware seems to still be very good in terms of pricepoint, it does feel like the software side of things has been going in a very strange direction for quite some time. I'm still quite annoyed by the fact that I was forced to migrate from Unifi Video to Unifi Protect - due to vendor lock in and the fact that the remote…

Agree on Ubiquiti losing their shine. They seem to have fallen for the classic trap of vendors selling hardware without fully factoring in the cost of maintaining software and “cloud” infrastructure. So now their “growth hackers” have to keep coming up with things that should just be add-ons or bug fixes but instead they sell them as a premium feature or new product to make up for a lack of recurring revenue.

Basically they are alienating their existing customer base (who have already paid a premium price for the prosumer product upfront and expect things to Just Work for the price) in favour of convincing the next idiot to fund their OPEX with shiny new features and toys that are a quick sell. Not realising (or unwilling to realise) that this strategy is completely in contradiction with their reputation and brand image as trustworthy prosumer hardware vendor, and just adds to the underlying issue.

I predict that it won’t be long before they run out of cash or investor confidence and have to sell out to a large consumer hardware vendor with deep pockets that will try to capture the Ubiquiti premium margins by selling their lower-value existing consumer gear under the Ubiquiti brand. I applaud them for having come this far while maintaining most of their integrity and reputation, but I’m afraid their strategy is doomed to fail and it’s starting to show.

Re: Ubiquiti Networks Breach

#85
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

> That phenomenon is called counter-signaling, which I first ran into listening to Dan Jurafsky making the point that if a menu uses the word "fresh", its a low-brow restaurant. A high-brow restaurant would never use the word "fresh" -- the freshness is implicit in the other signals. https://kelley.iu.edu/riharbau/cs-randfinal.pdf source: https://news.ycombinator.com/item?id=25713050

Italian franchise[0] restaurant in Sacramento has this huge neon sign in their window: "health inspected". Neon. It's just that one instance of the store. Not that I've seen them all, but never seen that signage in their other stores.

[0] Maybe not technically a franchise. Not sure. There are a bunch in California.

Re: Ubiquiti Networks Breach

#87
post #18

Ubiquiti is slowly becoming Sonos. The difference is, their potential for bad behavior, risks and attack surface is far, far greater.

What’s wrong with Sonos? I’m about to drop a bunch on a full home setup, should I consider an alternative?

Would recommend reading through the previous threads on HN.

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

Re: Ubiquiti Networks Breach

#88
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

It's impossible to secure yourself against a devoted persistent threat group over the long term. The asymmetry of effort is not tractable to overcome. So they can take your security seriously, but they will be hacked, or they have already.

They put all of their users eggs in one basket in the cloud. That makes for a very interesting target.

They could have not done that. The users were probably unaware that their data was even placed on the cloud servers of some third party.

Ubiquiti used to be cool. They've taken a nose dive in recent years in several ways: Firmware upgrade suddenly including telemetry by default, forcing people to use their NVR appliance instead of installing their software on their private servers, etc.

Had Ubiquiti not moved people to "cloud solutions" an attacker would have to attack millions of peoples equipment. Now he only had to attack one providers network.

Re: Ubiquiti Networks Breach

#89

As someone who was planning on buying Ubiquiti hardware for their house, this breach and a lot of the comments here are disconcerting. Are there any other alternatives that are more locally managed that people would recommend?

If you include a cloud key in the network there’s no need to connect to the ubiquity cloud. The cloud key runs an entirely local ubiquity management stack.
Post reply on HN