Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

211–220 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#211

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Ruckus R710 or R510 unleashed. I was talking about Ubnt's horrendous security in another thread just last night. https://news.ycombinator.com/item?id=26628198 Or if you just want Wave1 Hardware...R700/R500 You can get these as overstock on the cheap on amazon etc. The unleashed version means it can run the controller on the AP.

The R700/R500 are End-of-Life[1] so be sure you're OK with not getting new firmware.

1. https://support.ruckuswireless.com/product_families/4-eol-ru...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#212

> Adam wrote in his letter. “Legal overrode the repeated requests to force rotation of all customer credentials, and to revert any device access permission changes within the relevant period.” tsk.

Yeah that doesn’t make sense to me. Sales would do something like that. Legal should be erring in the opposite direction.

No. They don't care if customers get pwnd. They care if customers become aware of exactly how they got pwnd and launch a class action. It's shitty but entirely predictable behavior common in these situations.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#213
post #91

I am 100% not surprised. I spent a year working for Ubiquiti, running the Network Controller team. Trust me, this whistle-blower "Adam" (I have a few suspicions of who it actually is), toned it down. The reality is much much worse.

I worked at Ubiquiti while you were there. I can confirm that the company was going downhill fast. The US offices were starting to feel empty because so many people were leaving the company. Only place I've ever worked where engineers would quit before they got another job. Saddest part was all the wasted potential. There were good engineers making good products at Ubiquiti only a few years ago. Once UniFi exploded i…

It's unfortunate what seems to have happened to Ubiquiti. The idea of decent network hardware with a good UI that can support the prosumer to small business segment of the market has a lot going for it.

In the early days, it seemed like Ubiquiti was going to nail it and was building up a strong, loyal following as a result. Then came all the reports of quality problems, promised features never delivered, phoning-home, ads in UIs, the not just security breaches but cover-ups...

How the brand hasn't become toxic already is a mystery to me, yet look at the stock price tracker. It's been trending up for years and it has well over doubled in the past six months alone. Apparently investors aren't too worried about any potential consequences of all these reported problems.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#214
post #192
post #141

Earlier quoted context omitted.

As far as I know, TP-Link doesn't require any cloud based service, or even a local controller. They can work fine without any of it and you just manage them locally/directly.

TP-Link is a Chinese company. Doesn't inspire much confidence..

And Cisco does? With it’s known back doors from the NSA?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#215

Why do people trust any IoT devices these days? Shouldn't we be trying to reduce our exposure to (inevitably insecure) software? What benefits does it provide that are worth the unbounded risks?

It’s not _that_ unbounded? At least not yet! Until a tech savvy neighbor who’s also a creep can easily break into your network and home camera I’m not personally worried.

Why does it have to be a neighbor? It says "internet" on the tin. Do you have confidence that random people on the internet can't do the equivalent of a port-scan on you?

The other way I think of it is, I don't use it right now. It likely has open doors, intentional or unintentional. If the open doors are widely discovered, reliably closing them seems difficult. The highest-leverage point in time to influence this story is before I start using it. "The only winning move is not to play."

Feedback appreciated on this thought process.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#216

Was days away from refitting my home out with £2,000 of gear. Any other recommendations for routers, wifi and security cameras?

I use Mikrotik (or OpenWRT) for routers, but Mikrotik is not that good on WiFi. Peeople recommend Ruckus, but it's pretty expensive (and not that easy to get second hand in Europe, or Spain at least). Is there any (good) brand with pricing between Mikrotik and a Ruckus that doesn't need a cloud connection?

Is it not possible to just add in a separate WAP to the MikroTik device ?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#217

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Eero is amazing. It Just Works. Apple style. Plug it in. Never fuck with it. Rock solid.

They are amazon-owned. I'd be shocked if they weren't collecting and reporting telemetry.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#218

> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed” Perversely, this is exactly the logging that you want to have in place in case of a breach. You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”

"We believe that the hackers obtained read-write access to our database, but we also believe that they were too polite to actually use it for anything."

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#219
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

> Maybe putting your network control plane in 'the cloud' isn't such a good idea after all...

Isn't one of the major selling points of cloud-everything "How can you possibly secure your service better than BigRespectableCompany?" I know any time I bring up self-hosting E-mail or a web site or whatever, someone always comes out of the woodwork to remind me that I am not an expert in securing Internet services, and that BigRespectableCompanies have full-time employees dedicated to security. Surely I should be moving to the cloud for this expertise! This is sounding more and more like FUD to me.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#220
I wonder how difficult it would be to implement a rudimentary controller for their APs. The WLAN configurations are just text files in the /etc directory. Getting feature parity would be a lot of work, but I bet the bar isn't too high for simple functionality. Most of the "magic" is happening in hostapd on the APs anyway.
Post reply on HN