Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

151–160 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#151
post #110

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…

> So the question for becomes: is there just not a good enthusiast market for this stuff?

No. They just don't want to serve the low end. I'm from SK, Canada and the vast majority of all businesses are small businesses. This site [1] says 98%. The problem is they only account for about 25% of the GDP, so vendors don't consider them worth serving. Everyone wants to sell to the 2% of the businesses that make up 75% of the GDP.

There's a lot of money to be made in the small business sector. It's just not *enough* money for huge tech companies.

1. https://www.bizadv.ca/by-the-numbers-saskatchewan-business-s...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#152
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

The TP-link offering looks very similar to Ubiquiti from a quick scan a month or two back.

Both will run from locally hosted controllers if desired.

I've been seeing more Cisco "Meraki Go" kit around as well, which looks to target the same use cases as Ubiquiti (very very similar gear, WAPs, low end switches & gateways), albeit without a local controller option, but at least without the usual steep Meraki subscription charges.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#153
post #78

Earlier quoted context omitted.

What is the right way store credentials to something like this? Hardware keys?

The root account credentials should be used to create a privileged IAM user and then physically locked away in a box after setting up a hardware MFA device (plus a backup MFA) for the root account: https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practi... The privileged IAM user should then be used to administer other IAM users and roles. All IAM users should be required to have hardware security keys like Yubi…

> (plus a backup MFA)

IAM doesn't even let you register more than 1 MFA device.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#154

Earlier quoted context omitted.

Global UI? You mean, AWS-hosted configurator for your network? We just had example of it being security risk. God save Mikrotik from implementing something similar.

No, a local controller that you run on a machine inside your LAN.

Their http interface is reasonable and you can configure/provision the APs from CAPSman from one of the routers/switches in a central location.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#155

Earlier quoted context omitted.

This is a lot harder to do if you have lots of AWS accounts and create new ones over time on-demand (e.g. AWS account per team).

Use Organizations. If you’re creating new standalone independent accounts for teams you’re just seeking yourself up for some kind of billing/security/governance catastrophe down the road.

I was referring to the root accounts in your organization. The blast radius is more limited, but still a root account that has access to everything within that AWS account.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#156
post #55
post #29

Earlier quoted context omitted.

> Legal isn't there to make sure the company complies with the laws. Legal is there to advise on and minimize legal risk. Breaking laws is one sure way to increase legal liability.

Only if you get caught.

And be successfully prosecuted.

I'm sure someone in legal knows someone at the AG's office who might be "considering the private sector" in the near future.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#157
post #56

Ubiquiti is another one of these companies where if you did nothing but read about them on HN, Reddit, et al, you would think they're filing for bankruptcy tomorrow, set orphanages on fire, kill puppies, etc. The negative hyperbole around this company is something else, hack or not. And yet, all they do is thrive...

It's a long-tail if I had to guess. In my "circle" of coworkers almost every last one has ubiquiti today, and every last one is planning to replace it with something else when they make the jump to WiFi-6.

Maybe we're the anomaly, but I have a feeling 2 years from now if they continue down the path they're on, their earnings will not be quite so rosy.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#158
post #68

Was days away from refitting my home out with £2,000 of gear. Any other recommendations for routers, wifi and security cameras?

For router check out the Turris Omnia [0]. Seems to be a good choice. [0]: https://www.turris.com/en/omnia/overview/

That looks pretty nice. Too bad I didn't see this a week earlier since I just upgrade my home network last week.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#159

Earlier quoted context omitted.

Technically, Ubiquiti does have a local option. You can run the controller locally and disable cloud login.

People have reported cloud login can't be disabled now.

It can still be disabled from the controller:

New UI: Settings > System Settings > Administration > Enable Remote Access

"Classic" UI: Settings > Remote Access > Enable Remote Access

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#160

Why do people trust any IoT devices these days? Shouldn't we be trying to reduce our exposure to (inevitably insecure) software? What benefits does it provide that are worth the unbounded risks?

It’s not _that_ unbounded? At least not yet! Until a tech savvy neighbor who’s also a creep can easily break into your network and home camera I’m not personally worried.
Post reply on HN