Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

191–200 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#191

Earlier quoted context omitted.

The problem is that on-prem isn't much better in many cases. Only the largest organizations have the capability to operate deep defenses against these threats whether it's the cloud, or the on-prem. If you and your team have the skills you can operate fairly effectively on a small scale, but that's a pretty luxurious situation. Most home users can't tell the difference between a router and cable modem hence it's in t…

The problem isn't Ubiquiti using AWS. It's Ubquiti forcing customers to use cloud authentication.

Let's be honest, there are a lot of problems here.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#192
post #141

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

As far as I know, TP-Link doesn't require any cloud based service, or even a local controller. They can work fine without any of it and you just manage them locally/directly.

TP-Link is a Chinese company. Doesn't inspire much confidence..

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#194

Should have blown the whistle to the SEC instead. SEC whistleblowers get paid. Up to 30% of eventual penalties paid by the company with no upper limit. Lying about a breach could be securities fraud.

They may already have. Investigation is already pending: https://finance.yahoo.com/news/shareholder-alert-ubiquiti-in...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#195
post #78

Earlier quoted context omitted.

The root account credentials should be used to create a privileged IAM user and then physically locked away in a box after setting up a hardware MFA device (plus a backup MFA) for the root account: https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practi... The privileged IAM user should then be used to administer other IAM users and roles. All IAM users should be required to have hardware security keys like Yubi…

> (plus a backup MFA) IAM doesn't even let you register more than 1 MFA device.

I have accounts for personal use and what I did was set up TOTP for the root account(s) and a U2F (YubiKey) device for the admin account(s). I use 2 YubiKeys; one primary, one spare. The YubiKey has limited TOTP space, but they're perfect for those types of high value accounts. You store the TOTP on both, so if you lose one you can use the root account to fix the admin account.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#196
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Ruckus R710 or R510 unleashed. I was talking about Ubnt's horrendous security in another thread just last night.

https://news.ycombinator.com/item?id=26628198

Or if you just want Wave1 Hardware...R700/R500

You can get these as overstock on the cheap on amazon etc. The unleashed version means it can run the controller on the AP.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#197
post #183

Earlier quoted context omitted.

Are you concerned that TP-Link is a Chinese company? Could your data be exfiltrated back to China?

edit: Oops, disregard, I've violated HN hivemind statutes, despite being completely factually correct! What I meant to say is that US law enforcement, and in particular the FBI, are 100% perfect in every way. Nobody has EVER used lawful request overreach to ruin the lives of innocent people. Praise be to J. Edgar Hoover!

It's a sad commentary on how low the bar has been lowered. "No, you're system isn't secure, but the people that can access it can't really do you bodily harm" is not really the level I would hope we are trying to acheive.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#198
post #6

But the routers have a nice user interface!

My favorite part of the web interface is when it silently reverts changes made at the command line.

The APs and switches are stateless by design (which I sort of like), but if you make CLI changes on the controller using the config file they are not reverted in my experience.

Though it's not super well supported either because they prefer people using the web UI to the config file.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#199

Earlier quoted context omitted.

No, TP-Link's Omada controller can be run locally, I do that at home and at my parents' house. It is not cloud-connected unless you turn that on. Runs surprisingly well on a Raspberry Pi 2, actually. I've got a setup similar to what you're asking for. The TP-Link APs (AC1750, AC1350 and AC1200) support PoE, they're in a wireless mesh, support roaming, and all configuration is handled with one interface, no cloud invo…

Are you concerned that TP-Link is a Chinese company? Could your data be exfiltrated back to China?

As a US citizen, I would love for there to be a reasonably-priced US-made alternative. I guess Netgear could be one[0], but their Insight management system is cloud-only, isn't it? Happy to be corrected.

I think I'd rather take an ostensibly-offline controller from China than a cloud-enabled one from the US, though I'm not really happy with those options. :-(

Are there some good options I missed? Would like to hear about them, if there are any.

[0] I expect their hardware is made in China, even if their controller may not be.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#200
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

For those people here saying "go Ruckus unleashed" ... caveat emptor my friends !

I have it on very good authority that Ruckus have started rolling out a change in their pricing model to require a Unleashed license per AP to operate, a move which obviously increases costs to the end-user.

Some people might say its a deliberate move prevent cannibalisation of their main business model by nudging people away from Unleashed. I couldn't possibly comment.

Post reply on HN