Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

61–70 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#61
post #21

Shit, I had plans to refresh the network infrastructure in my parent's place with a full ubiquiti setup to replace the years of added on junk.

Parent’s place? Go Eero Pro. Your future time management self will thank you.

Eero is cloud managed too. And reports MAC addresses and network usage to Amazon.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#62

Was days away from refitting my home out with £2,000 of gear. Any other recommendations for routers, wifi and security cameras?

I use Mikrotik (or OpenWRT) for routers, but Mikrotik is not that good on WiFi. Peeople recommend Ruckus, but it's pretty expensive (and not that easy to get second hand in Europe, or Spain at least). Is there any (good) brand with pricing between Mikrotik and a Ruckus that doesn't need a cloud connection?

Can you elaborate on your experience with Mikrotik wifi? What don't you like about it?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#63
post #42
post #35

Earlier quoted context omitted.

If i were you I’d take heart in the knowledge that the others aren’t any better, it’s just a matter of “when” they’ll get cracked in the same way

Not every network hardware provider ties everything to a "Cloud" for reasons. They may have breaches but they won't be this widespread.

It’s increasingly hard to find providers that don’t though. The advantages to global management software is pretty high & the easiest way to implement that is the cloud.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#64

Earlier quoted context omitted.

Same, my setup is 100% Unifi from back before they started going downhill. At least I was self-hosting the software so I wasn't bitten by this breach.

They forced cloud authentication on self hosted software too.[1] [1] https://www.reddit.com/r/Ubiquiti/comments/kslyh9/cloud_key_...

Wow, that's awful.

I have a few Ubiquiti devices I haven't updated in months, that don't use any cloud accounts, and I used to run their controller software in a container that I only started when I needed to administer something. But now I guess I'm never updating and will be looking to get rid of all their equipment.

What an incredibly consumer hostile and incompetent company. Shame, because the hardware pretty much works reliably.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#65
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Ruckus Unleashed is what you're looking for.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#66

> Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies. A root user user breach, seemingly on the organiza…

What is the right way store credentials to something like this? Hardware keys?

For AWS root account?

Generate a long random password, print it out and then lock it in a safe without allowing anyone to see it.

Turn on 2FA and then lock the second factor in a different safe.

There’s virtually never a need for the root account and it’s impossible to attenuate (by design).

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#67

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Technically, Ubiquiti does have a local option. You can run the controller locally and disable cloud login.

That's how I run it, but it seems they are now pushing ads to local controllers and between this and deprecating recently released devices, I just completely lost trust in them.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#68

Was days away from refitting my home out with £2,000 of gear. Any other recommendations for routers, wifi and security cameras?

For router check out the Turris Omnia [0]. Seems to be a good choice.

[0]: https://www.turris.com/en/omnia/overview/

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#69
I wish I could say I was surprised :(. Along with a bunch of other people who've used their products for a decade or more now, I've been watching the ever steepening downward spiral of the company really becoming noticeable over the last 3-4 years. In an academic way, it's actually been kind of fascinating to watch happen in real time over the course of years with fairly front room seats. Seeing the deepening technical debt (lots of very old hardware still sold as new with no replacements in sight, inability to migrate their frameworks or keep their sources up to date and more), bikeshedding ramp up and up, the forums start to fall apart, marketing starting to write more and more checks development couldn't keep up with and then that getting brushed under the rug (the SHD and it's dedicated security radio comes to mind), the forums getting nuked entirely in favor of a horrible New Web thing with even worse bug/feature tracking then before and there wasn't any proper one before, ever worsening stability, universally hated UI changes that would just get shoved through anyway, and on and on. It's been everything one reads about, "Ubiquiti's Burning Platform" and all that, and in turn seems like it should be avoidable. Yet on it ground with sickening inevitability. It's just now finally starting to reach critical mass and become visible to the more general public, spreading through the same tech grapevine that gave them such a boost in the first place.

But less academically it's depressing as hell too, because the grapevine liked them for good reason and there still isn't any drop in replacement. Their p2p/p2mp gear is still solid. And UniFi was a wonderful concept solidly executed. It also eschewed the subscription/cloud bullshit so many other players are chasing, which indeed is something of a saving grace here. While there is a cloud option, lots (if not most) people can and do run their UniFi networks completely self-hosted even for remote sites. The single pane of glass, ease of provisioning and recovery, etc made sense and saved time. And they had an incredibly enthusiastic and supportive community, like when they asked about moving L3 switching way back on the old forums (back when the rot was in its earliest stages and not clear yet) they got huge amounts of feedback, their beta testing had many people putting in a lot of good work.

Such a damn stupid waste. And the nature of the beast for tech infrastructure is that market signals are always behind the curve and thus muted until things are already getting to be too late. Robert Pera also owns the majority of their stock IIRC so there isn't any way to effect an outside management change there either. It is odd to me that nobody has sought to go after them directly and aggressively, though I heard rumblings late last year that Cisco was giving a go at something clearly aimed right at the UniFi market (no subscriptions like Meraki)?

At any rate, final straw for me on routing was the flop their "UXG" has been, I finally gave up at long last and began migrating everything to OPNsense a month back. And once the single pane of glass is broken, the barrier to start moving more drops in turn and network effects (harhar) begin to go into reverse. I'd still be happy if they somehow recovered, but if they do I think it'll be a long time. Problems that build for years tend to take years to reverse too, if they can be. I hope we get some stories someday internally on how it all went down.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#70

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

It's a shame that Mikrotik doesn't have a easy to use global GUI. It's the right hardware, and great firmware and wonderful flexibility - but it needs an easy to use GUI controller to make the simple stuff easy to take over from Ubiquiti.

Global UI? You mean, AWS-hosted configurator for your network? We just had example of it being security risk. God save Mikrotik from implementing something similar.
Post reply on HN