This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.
Whistleblower: Ubiquiti Breach “Catastrophic”
51–60 of 815 posts
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#52Earlier quoted context omitted.
What a shockingly large breech. Wow.
The breaches are common, the reporting/discovery of them is not. Security just isn’t a priority for a lot of Orgs, as the consequences are minimal (see: Equifax) due to a lack of regulatory or financial penalty pain when a breach occurs. “Help yourself to a free year of identify theft insurance” and all that jazz.
If you discover, you have to report. If you don’t, odds are nobody will notice/will blame someone else.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#53> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed” Perversely, this is exactly the logging that you want to have in place in case of a breach. You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#54> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#55Earlier quoted context omitted.
Successfully sweeping it under the carpet means you don't get sued for the mistakes you made. Legal isn't there to make sure the company complies with the laws. Legal is there to advise on and minimize legal risk.
> Legal isn't there to make sure the company complies with the laws. Legal is there to advise on and minimize legal risk. Breaking laws is one sure way to increase legal liability.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#56Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#57> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…
It's the right hardware, and great firmware and wonderful flexibility - but it needs an easy to use GUI controller to make the simple stuff easy to take over from Ubiquiti.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#58Earlier quoted context omitted.
Successfully sweeping it under the carpet means you don't get sued for the mistakes you made. Legal isn't there to make sure the company complies with the laws. Legal is there to advise on and minimize legal risk.
> Legal isn't there to make sure the company complies with the laws. Legal is there to advise on and minimize legal risk. Breaking laws is one sure way to increase legal liability.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#59> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
Is it rally cost and complexity?
Or just missing awareness?
Or the lack of consequences when you get hacked in a way which could easily have been prevented (through then they might have attacked in a different way, tbh.).
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#60> Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies. A root user user breach, seemingly on the organiza…
What is the right way store credentials to something like this? Hardware keys?