Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

1–10 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#5
I wonder why their legal department would PREVENT them from saving their users.

What legal reason would exist for that? I thought legal would instead force them to save their users, since otherwise they would risk getting sued by all of them by all the damages caused or something.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#7
> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.”

> “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,”

Maybe putting your network control plane in 'the cloud' isn't such a good idea after all...

Edit: Just re-read the article, this part stood out:

> the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies.

> Adam says Ubiquiti’s security team picked up signals in late December 2020 that someone with administrative access had set up several Linux virtual machines that weren’t accounted for.

If this is true, and whoever breached them had full access to their AWS account, can we really trust them to clean up all their tokens and fully eradicate all forms of persistence the hackers may have gotten?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#8

Well, guess I won't be about to drop a few thousand on Ubiquiti gear anymore until we get some more details. Hopefully this account isn't fully truthful, otherwise Ubiquiti has really screwed up.

meh, not really a good substitute. They've got the prosumer market locked down.

Probably why they got into this mess. Lots of successful product people deferring 'non product' stuff.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#9
post #5

I wonder why their legal department would PREVENT them from saving their users. What legal reason would exist for that? I thought legal would instead force them to save their users, since otherwise they would risk getting sued by all of them by all the damages caused or something.

Successfully sweeping it under the carpet means you don't get sued for the mistakes you made.

Legal isn't there to make sure the company complies with the laws. Legal is there to advise on and minimize legal risk.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#10

Well, guess I won't be about to drop a few thousand on Ubiquiti gear anymore until we get some more details. Hopefully this account isn't fully truthful, otherwise Ubiquiti has really screwed up.

> Hopefully this account isn't fully truthful

Brian Krebs is a reputable source who has a lot to lose if he makes unsubstantiated claims.

Post reply on HN