Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

161–170 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#161
post #81
post #42

Earlier quoted context omitted.

Not every network hardware provider ties everything to a "Cloud" for reasons. They may have breaches but they won't be this widespread.

Wasn't really a "cloud" hack so much as a hack of a root user. How they accessed that root user's credentials is not detailed. Phishing? Hardware hack? Dumb root user and it was possible to guess his/her credentials? Could even be, that particular root user was in on it with them for all we know? In any case, this sort of a hack of any other company's root users would result in the same spectacularly catastrophic pwn…

The reason people are bringing up cloud is because it's what effects them. If you have (cloud) access through a company to local devices and that company is hacked then that could be a very wide pathway into your local set up. The company being hacked and related implications is still not great for a huge list of reasons but it's the possible local breaches that are more of a worry for a lot of us.

Ubiquiti has recently been pushing there cloud set up (to the point that you can't set up a local controller with out setting up a cloud account) that's why it's so annoying.

*There is probably a way but the last time I tried I couldn't find it in setup and so installed using a previous version.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#162

> Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies. A root user user breach, seemingly on the organiza…

This boggles me when I see this option in any password manager (and I think every single one has this 'option'). Why do password managers let people store TOTP next to the password, this completely invalidates the 2FA of TOTP if your password manager get broken into.

The alternative is to navigate 100 separate token reset processes if you ever lose your phone and all of its TOTP tokens.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#163
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Not 100% sure if that's what you are looking for (I don't do much network works) but I think that Camsat's GlobalCAM-4.5G may be worth checking, with one catch: the company targets CCTV market. Still, that's just a router, without any special license fees or mandatory clouds.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#164
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Maybe Plume Homepass: https://www.plume.com/homepass/ ? I'm not sure if they're 100% equivalent, but it seems to cover a good part of the Ubiquiti feature.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#165
post #78

Earlier quoted context omitted.

The root account credentials should be used to create a privileged IAM user and then physically locked away in a box after setting up a hardware MFA device (plus a backup MFA) for the root account: https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practi... The privileged IAM user should then be used to administer other IAM users and roles. All IAM users should be required to have hardware security keys like Yubi…

> (plus a backup MFA) IAM doesn't even let you register more than 1 MFA device.

If I were a CISO solving this problem today, I would just use TOTP instead of U2F, and store the secret in two places.

Longer term I expect AWS will add this capability.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#166

Don’t have time to dig into this right now, but I have a Ubiquiti WiFi AP at my home behind a NAT; does this breach mean my home network is vulnerable/effectively exposed to the Internet? Do I need to log off HN and deal with this now, or can it wait?

I mean, yes, it does. However hopefully the hackers aren't in their system anymore - so if you were at risk it's already probably over. I guess just change your password and reset your 2FA?

Ugh. Guess I’ll just go wired for now and unplug the AP. Hopefully I’m only paranoid, but I really don’t like the feeling of a hole in the network with my family’s NAS and IoT devices.

Never again with the cloud-connected network appliances. Time to build a router from scratch, I guess.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#168

Was days away from refitting my home out with £2,000 of gear. Any other recommendations for routers, wifi and security cameras?

I have happily upgraded several homes from Mikrotik and/or Ubiquiti to Eero mesh - https://eero.com/

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#169

> Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies. A root user user breach, seemingly on the organiza…

This boggles me when I see this option in any password manager (and I think every single one has this 'option'). Why do password managers let people store TOTP next to the password, this completely invalidates the 2FA of TOTP if your password manager get broken into.

Because I already use MFA to access my password manager in the first place, and don't want to deal with managing backups for each flavor of MFA app that is pushed on me.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#170
post #110

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…

? So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist.

my experience as a professional "network nerd" is that most other people in the networking field run cheap/second hand enterprise gear fetched from their employer at a major discount and simply seem to care less about wifi in general.

Post reply on HN