Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

181–190 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#181
post #51

Earlier quoted context omitted.

I always thought that the main selling point of their devices was that you can run your own Ubiquiti server at home and keep everything local? They are always portrayed as the not-so-shitty IoT company.

If you don't have remote access enabled and aren't running their surveillance camera software, it is not clear to me that there is any risk to the customer from this event (outside of the source code being used to generate new exploits). It doesn't sound like the attackers were able to abuse automated firmware update functions, and losing credentials to a UI account has no impact on users running cloud key locally wi…

Right. I would never have any device like a camera be directly connected to the internet and instead cut off that device from the internet in my router software and only access it from outside via a VPN.

Not that this whole screw-up should be excused in any way or downplayed.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#182
post #81
post #42

Earlier quoted context omitted.

Not every network hardware provider ties everything to a "Cloud" for reasons. They may have breaches but they won't be this widespread.

Wasn't really a "cloud" hack so much as a hack of a root user. How they accessed that root user's credentials is not detailed. Phishing? Hardware hack? Dumb root user and it was possible to guess his/her credentials? Could even be, that particular root user was in on it with them for all we know? In any case, this sort of a hack of any other company's root users would result in the same spectacularly catastrophic pwn…

IIRC it says that they got the LastPass data for an employee which had (non two factored?) AWS access credentials.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#183

Earlier quoted context omitted.

No, TP-Link's Omada controller can be run locally, I do that at home and at my parents' house. It is not cloud-connected unless you turn that on. Runs surprisingly well on a Raspberry Pi 2, actually. I've got a setup similar to what you're asking for. The TP-Link APs (AC1750, AC1350 and AC1200) support PoE, they're in a wireless mesh, support roaming, and all configuration is handled with one interface, no cloud invo…

Are you concerned that TP-Link is a Chinese company? Could your data be exfiltrated back to China?

edit: Oops, disregard, I've violated HN hivemind statutes, despite being completely factually correct!

What I meant to say is that US law enforcement, and in particular the FBI, are 100% perfect in every way. Nobody has EVER used lawful request overreach to ruin the lives of innocent people. Praise be to J. Edgar Hoover!

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#184

Was days away from refitting my home out with £2,000 of gear. Any other recommendations for routers, wifi and security cameras?

For firewall, I suggest an OPNSense box. You could run it on a thin client, a Protectli etc.

For AP, OpenWRT seems decent.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#185
post #141

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

As far as I know, TP-Link doesn't require any cloud based service, or even a local controller. They can work fine without any of it and you just manage them locally/directly.

[deleted]

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#186
post #164

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Maybe Plume Homepass: https://www.plume.com/homepass/ ? I'm not sure if they're 100% equivalent, but it seems to cover a good part of the Ubiquiti feature.

Interesting. Subscription-based services in the home seem like a disaster waiting to happen. Unless you can self host in the event of a company shut-down, you're beholden to a company and their solvency.

Can't see anything on their website for a transition plan in the event of shutdown (and of course, why would they post that and potentially signal lack of confidence in their longevity).

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#187

Earlier quoted context omitted.

This boggles me when I see this option in any password manager (and I think every single one has this 'option'). Why do password managers let people store TOTP next to the password, this completely invalidates the 2FA of TOTP if your password manager get broken into.

The alternative is to navigate 100 separate token reset processes if you ever lose your phone and all of its TOTP tokens.

Or just keep them somewhere that isn’t directly beside the password?

I have my password in a password database, and my TOTP tokens on my phone and a Yubikey.

I have a second “break glass in case of emergency” password database that contains TOTP secrets for all my most essential accounts and a backup of the key loaded on my Yubikey.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#188

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Technically, Ubiquiti does have a local option. You can run the controller locally and disable cloud login.

I have been suspicious of their cloud config and run a docker image of the controller locally.

I'm still on version 5.14 and all of the cloud features are optional. I just ignore them. I guess now I know not to upgrade!

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#189
post #91

I am 100% not surprised. I spent a year working for Ubiquiti, running the Network Controller team. Trust me, this whistle-blower "Adam" (I have a few suspicions of who it actually is), toned it down. The reality is much much worse.

I worked at Ubiquiti while you were there. I can confirm that the company was going downhill fast. The US offices were starting to feel empty because so many people were leaving the company. Only place I've ever worked where engineers would quit before they got another job. Saddest part was all the wasted potential. There were good engineers making good products at Ubiquiti only a few years ago. Once UniFi exploded i…

Now rewrite your entire comment with s/ubiquiti/sonos/g.

So much wasted potential ... so much customer goodwill wasted because (apparently) no company is worth running unless it is a publicly traded unicorn.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#190

Earlier quoted context omitted.

Technically, Ubiquiti does have a local option. You can run the controller locally and disable cloud login.

That's how I run it, but it seems they are now pushing ads to local controllers and between this and deprecating recently released devices, I just completely lost trust in them.

> it seems they are now pushing ads to local controllers

The pervasiveness of adtech doesn't cease to impress me.

Post reply on HN