Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

31–40 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#32
The simple interpretation is that lawyers know that the law offers no consumer protections in these scenarios, and tried to use that to protect the corporation. Morals aside, and assuming their assessment about such legal boundaries was correct, they were simply doing their jobs.

The system may be broken, but a patch is necessary, and that is only going to arise via legislation. Sadly, the system of governance is also broken, so I expect this will be closed with status "WONTFIX".

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#33

This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.

Same, my setup is 100% Unifi from back before they started going downhill. At least I was self-hosting the software so I wasn't bitten by this breach.

They forced cloud authentication on self hosted software too.[1]

[1] https://www.reddit.com/r/Ubiquiti/comments/kslyh9/cloud_key_...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#35

This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.

If i were you I’d take heart in the knowledge that the others aren’t any better, it’s just a matter of “when” they’ll get cracked in the same way

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#37

Well, guess I won't be about to drop a few thousand on Ubiquiti gear anymore until we get some more details. Hopefully this account isn't fully truthful, otherwise Ubiquiti has really screwed up.

A few months ago I was considering outfitting my apartment with Ubiquiti gear but ultimately decided to stick to an aging AirPort Extreme and a couple of cheap ethernet switches after seeing reports of bugs with various Ubiquiti pieces. Seems that was a good judgement…

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#38

This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.

I almost did the same thing, but it was clear a year ago that they were moving towards "cloud based" services, something I didn't want to participate in. Looks like it was a good decision, in retrospect.

So what did you go with?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#39

This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.

Same, my setup is 100% Unifi from back before they started going downhill. At least I was self-hosting the software so I wasn't bitten by this breach.

Apparently I was... Now, updated the firmware and it says server certificate changed. Frikkin A. Now I am in 'what the hell' land

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#40
"Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies."

Holy...

Wow. That is catastrophic. Everything is compromised. That's a complete rebuild.

Post reply on HN