Whistleblower: Ubiquiti Breach “Catastrophic”
21–30 of 815 posts
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#22Well, guess I won't be about to drop a few thousand on Ubiquiti gear anymore until we get some more details. Hopefully this account isn't fully truthful, otherwise Ubiquiti has really screwed up.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#23This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#24This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#25> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
What a shockingly large breech. Wow.
“Help yourself to a free year of identify theft insurance” and all that jazz.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#26I have had plans kicking around for a bit over a year to do a full build out using their products, and just within that time it seems like they've gone from a glowing reputation to severely tarnished. Unfortunate, as it seems like they once had great products.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#27Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#28> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed” Perversely, this is exactly the logging that you want to have in place in case of a breach. You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#29I wonder why their legal department would PREVENT them from saving their users. What legal reason would exist for that? I thought legal would instead force them to save their users, since otherwise they would risk getting sued by all of them by all the damages caused or something.
Successfully sweeping it under the carpet means you don't get sued for the mistakes you made. Legal isn't there to make sure the company complies with the laws. Legal is there to advise on and minimize legal risk.
Breaking laws is one sure way to increase legal liability.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#30This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.
Same, my setup is 100% Unifi from back before they started going downhill. At least I was self-hosting the software so I wasn't bitten by this breach.