Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

11–20 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#13
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

What a shockingly large breech. Wow.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#15

> Adam wrote in his letter. “Legal overrode the repeated requests to force rotation of all customer credentials, and to revert any device access permission changes within the relevant period.” tsk.

By trying to sweep it under the rug they just opened themselves up.

Crazy.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#17

This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.

Yeah well, more money in marketing than anything else.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#18
> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed”

Perversely, this is exactly the logging that you want to have in place in case of a breach.

You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#20
> Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies.

A root user user breach, seemingly on the organization main account. Ouch.

I wonder if MFA was set up, with the TOTP creds also kept in LastPass.

Post reply on HN