Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

41–50 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#41
>Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee.

So the laptop probably had some malware/keylogger on it that was able to pick up some data in the lastpass browser extension or something?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#42
post #35

This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.

If i were you I’d take heart in the knowledge that the others aren’t any better, it’s just a matter of “when” they’ll get cracked in the same way

Not every network hardware provider ties everything to a "Cloud" for reasons. They may have breaches but they won't be this widespread.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#43
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based.

WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is that too much to ask?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#44

Was days away from refitting my home out with £2,000 of gear. Any other recommendations for routers, wifi and security cameras?

Mikrotik is the most common recommendation probably but wifi speed is a problem apparently.

There were some other suggestions in yesterday's Ubiquiti discussion.[1]

[1] https://news.ycombinator.com/item?id=26628198

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#45

> Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies. A root user user breach, seemingly on the organiza…

What is the right way store credentials to something like this?

Hardware keys?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#46
post #21

Shit, I had plans to refresh the network infrastructure in my parent's place with a full ubiquiti setup to replace the years of added on junk.

Parent’s place? Go Eero Pro. Your future time management self will thank you.

I'll take a look at it, but also note that I need in total:

Router, Wifi AP (probably two to get full coverage), Powerline extender, Point-to-point extender with a switch on the other end.

Stupid outbuildings. Anyway, thanks for the tip!

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#47

Was days away from refitting my home out with £2,000 of gear. Any other recommendations for routers, wifi and security cameras?

I use Mikrotik (or OpenWRT) for routers, but Mikrotik is not that good on WiFi. Peeople recommend Ruckus, but it's pretty expensive (and not that easy to get second hand in Europe, or Spain at least).

Is there any (good) brand with pricing between Mikrotik and a Ruckus that doesn't need a cloud connection?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#49
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Peplink seems pretty good; they do have a Cloud:tm: management offering called InControl2 but as far as I'm aware it's entirely optional. I've had good luck configuring everything via the local UI. My setup is a Balance Two + a few One AX APs.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#50
post #41

>Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee. So the laptop probably had some malware/keylogger on it that was able to pick up some data in the lastpass browser extension or something?

previously stored. They probably made a csv backup of the lastpass database. Those aren’t encrypted.
Post reply on HN