Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

131–140 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#131

Earlier quoted context omitted.

No, TP-Link's Omada controller can be run locally, I do that at home and at my parents' house. It is not cloud-connected unless you turn that on. Runs surprisingly well on a Raspberry Pi 2, actually. I've got a setup similar to what you're asking for. The TP-Link APs (AC1750, AC1350 and AC1200) support PoE, they're in a wireless mesh, support roaming, and all configuration is handled with one interface, no cloud invo…

How is the experience otherwise? Roaming? Throughput? Reliability? I generally like their hardware.

Only been using it for a few months but it's been good. I moved the config I mentioned above (the three APs) to my parents' house and they haven't had any problems. Throughput in their case is a little limited but that's expected with the installation (no ethernet and a lotta walls). Hasn't needed a reboot or anything.

I just started using an EAP660 HD[1] at home a week ago, so far so good. Haven't topped out the speeds yet because nothing in my house can take advantage, but I have some AX200 cards coming. I understand there's a throughput bug at the moment that's going to be solved in a future firmware fix[0], but my clients don't go fast enough to hit that yet. TP-Link seems to very actively update their firmware for the pieces I've been using, FWIW.

So I've been pretty happy with it so far. Roaming has been fine, though in one case I think I had non-optimally located a couple of APs because my Linux laptop kept rapid-fire flapping between two of them. I believe that's a client-side problem, though.

I did try a Cisco 240AC and its wifi performance was rock solid. The management interface is non-cloud, and I believe covers the whole network, but it lives inside the AP itself, which I don't love. The management UI is buggy and they seem slow to push bugfixes, and when I added a 142ACM to extend my network it started going flaky -- I had to do a factory reset/reconfigure of the 240AC to resolve it, then it happened again a few weeks later -- so I'm gonna flip my Cisco stuff on eBay. :-(

[0] https://hwp.media/articles/review_and_test_of_the_tp_link_ea...

[1] Tip if you adopt one of these in Omada: You need to give Omada the EAP660's password (default "admin"/"admin") for it to successfully adopt. The other APs never required a password to adopt, so it was a little confusing until the internet came to the rescue.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#132
post #76

Earlier quoted context omitted.

It's a shame that Mikrotik doesn't have a easy to use global GUI. It's the right hardware, and great firmware and wonderful flexibility - but it needs an easy to use GUI controller to make the simple stuff easy to take over from Ubiquiti.

These recent posts about Ubiquiti have made me look again at MikroTik. Their hardware is more affordable than I had remembered. Is there any good intro to their hardware - there are certainly a lot more options than you get with Ubiquiti. Even before now there are some limitations with UniFi that have annoyed me. Setting up more complex DNS and firewall rules requires editing the JSON config. IPv6 tunnelling isn’t we…

It may sound strange, but for Mikrotik, I find it more productive to concentrate on setting them up via CLI. It's certainly more trainable.

CLI for Port Forward: /ip firewall nat add chain=dstnat dst-port=1234 in-interface=ether1-gateway action=dst-nat protocol=tcp to-address=192.168.1.1 to-port=1234

VS having to document the same task in the GUI:

IP->Firewall->Nat-> Add New

General Tab Chain: dstnat Protocol: TPC Dst. Port: Port In. Interface: ether1-gateway

Action Tab Action: dst-nat To Address: IP address of Server To Port: Port # of Service

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#133
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

I have exactly this setup with three Aruba Instant APs (WiFi 5), but afaict they’ve combined the Instant product line with their cloud offering or something? I’m not entirely sure where they’re going with it, but I am very happy with the setup I have.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#134

This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.

Same, my setup is 100% Unifi from back before they started going downhill. At least I was self-hosting the software so I wasn't bitten by this breach.

We should be clear here that there are multiple types of "self-hosted". Ubiquiti makes essentially little (weaker) Raspberry Pi devices with PoE that are dedicated to just the controller, and a few years back they also forced their (garbage) "Protect" onto their hardware only. They (confusingly) call these "Cloud Keys", though they have nothing to do with the cloud. However, you can also get 100% standalone versions of the Controller that will run on any server or VM you've got, Linux, Windows, or Mac. This is just the Java 8-based controller software and that's it, and you can lock those down arbitrarily hard for any WAN access same as any other LAN network software, no general internet access is needed at all and no firmware is involved.

A lot of people quite reasonably got CKs seeing them as very easy ways to have a low power always on local controller since they didn't have some other server running 24/7 already. If the firmware on those was updated to require tie-in to Ubiquiti's SSO that's a horrible betrayal. But I'm confident in saying the full standalone Controller doesn't since I have mine locked down from any general net access, remote L3 management was done to IP only at the firewall and I've been switching to just putting it all through WireGuard.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#135

Don’t have time to dig into this right now, but I have a Ubiquiti WiFi AP at my home behind a NAT; does this breach mean my home network is vulnerable/effectively exposed to the Internet? Do I need to log off HN and deal with this now, or can it wait?

I mean, yes, it does. However hopefully the hackers aren't in their system anymore - so if you were at risk it's already probably over.

I guess just change your password and reset your 2FA?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#136
You are required to have internet access to setup something like the UDM-Pro. After it is setup you can create a local admin account and disable remote access.

Here is how:

1. Login with your online account credentials and password 2. Choose system settings 3. Choose advanced 4. Disable Remote Access 5. Confirm that "Transfer owner" won't be available if you disable remote access.

The issue in general is that the UniFi stuff can be crappy and buggy, but it SUCKS LESS then any other complete solution for a home / small enterprise there at the price point.

I personally used to given them a strong recommendation and even now that is a recommendation with some footnotes. They have been growing to fast and the SW quality has gone down. Being on the latest release is not always the best idea.

To be fair in my I have had many conversation with Cisco that started with "no, not the latest GA, but what is the latest proven STABLE GA."

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#137

Earlier quoted context omitted.

Technically, Ubiquiti does have a local option. You can run the controller locally and disable cloud login.

People have reported cloud login can't be disabled now.

I set it up a few months ago with no cloud login, though it was a pain.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#138
It is interesting to do a search of HN for past references to "Ubiquiti". Whenever the topic of routers came up, many comments followed that recommended them above any alternatives. Commenters seemed proud to tell the world they were using Ubiquiti, as if the "HN concensus" for home routers was to choose Ubiquiti.

It seemed to me Ubiquiti would never allow customers the option to install their own OS (e.g., BSD) or boot from external media containing a non-Ubiquiti OS, without sacrificing the benefits of hardware specs that were likely deciding factors in selecting the Ubiquiti hardware above existing alternatives. The intent was clearly to have Ubiquiti retain control over the hardware after purchase. The customer effectively remained tied to Ubiquiti forever, so if the company started serving ads, using AWS unnecessarily, etc., there's no way to opt out. Customer is compelled to accept all updates.

Specs are important, but maybe not as important as control.

Reliance on third parties necessarily increases potential risk. Unnecessary use of third parties is, IMO, poor decision-making. This is of course rampant in "tech" and, IMO, marks a triumph of the salesforce for those third parties over common sense, possibly assisted by network effects. Further, I dislike products where there is a heavy focus on opaque "updates". Again, many customers have been trained to believe that not updating is always the wrong decision. (Meanwhile they have no idea what is in each update.)

As stated in one of the blog post comments:

"It is even worse: Ubiquiti forced all users to use cloud-based authentification even for accessing your controller software on a local network with a local client. This was not even properly communicated but deployed by one of the regular maintenance updates."

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#139
post #110

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…

I can't imagine that there isn't a market for this. Look at the number of people recommending Ubiquiti stuff to each other. There are entire YouTube channels dedicated to it. If your whole living space or small office can be covered with a single access point, get a 3-in-1 combo that has a WAP, a router, and a small switch. But if you don't, you are left with, what exactly? There is also some demand for mesh stuff, for people who rent and don't want to run Ethernet cable.

My plan: OPNsense on a PC Engines board for router + firewall, an unmanaged PoE-providing switch for switching, and something from 2-8 WAPs for indoor/outdoor Wi-Fi.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#140

Earlier quoted context omitted.

Man I really wonder why the lack of proper 2FA is so wide spread? Is it rally cost and complexity? Or just missing awareness? Or the lack of consequences when you get hacked in a way which could easily have been prevented (through then they might have attacked in a different way, tbh.).

Lack of 2FA for the AWS access ? Sure. It might have prevented the attack. The attacker had access to the whole database. Which meant he could alter the 2FA seed. So it wouldn't have mattered much.

They seem to have gained access through getting secrets from developers as far as I understood it.

So with 2FA they would have had a much harder time to gain access to the database.

The part of changing the seed only matters for customers of the hacked company but is (as far as I can tell) unrelated to them gaining access.

Post reply on HN