Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

221–230 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#221
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

> Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Isn't one of the major selling points of cloud-everything "How can you possibly secure your service better than BigRespectableCompany?" I know any time I bring up self-hosting E-mail or a web site or whatever, someone always comes out of the woodwork to remind me that I am not an expert in securing Internet services, and tha…

You may be smart, and have secured your systems properly, but someone with the same resume as you in another company might not be.

As your manager, how can I tell the difference between someone who actually did the work right, and someone who said they did the work right (and also legitimately believes that they did)?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#222
post #157

Earlier quoted context omitted.

It's a long-tail if I had to guess. In my "circle" of coworkers almost every last one has ubiquiti today, and every last one is planning to replace it with something else when they make the jump to WiFi-6. Maybe we're the anomaly, but I have a feeling 2 years from now if they continue down the path they're on, their earnings will not be quite so rosy.

My point is partly, let's check in a year from now. I'd wager not one of your coworkers switched. Zero.

You'd have lost that bet already. One of them switched to Aruba last week. I've already replaced several pieces of ubnt gear as well and posted for sale on ebay. The APs I'm holding off until there are some solid WiFi 6E options.

I know of at least two others that currently have hardware on order to replace existing ubnt routers with OPNsense so you can add them to the list by the end of April.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#223

Earlier quoted context omitted.

I worked at Ubiquiti while you were there. I can confirm that the company was going downhill fast. The US offices were starting to feel empty because so many people were leaving the company. Only place I've ever worked where engineers would quit before they got another job. Saddest part was all the wasted potential. There were good engineers making good products at Ubiquiti only a few years ago. Once UniFi exploded i…

It's unfortunate what seems to have happened to Ubiquiti. The idea of decent network hardware with a good UI that can support the prosumer to small business segment of the market has a lot going for it. In the early days, it seemed like Ubiquiti was going to nail it and was building up a strong, loyal following as a result. Then came all the reports of quality problems, promised features never delivered, phoning-home…

The early days at Ubiquiti were good. I worked with a lot of good engineers and we shipped good work. The decline is a recent problem.

> How the brand hasn't become toxic already is a mystery to me, yet look at the stock price tracker. It's been trending up for years and it has well over doubled in the past six months alone.

This is your answer. No incentive to change. All of the bad engineering decisions have been rewarded by increasing stock price and continued sales.

Most of the original engineers have quit by now. I lost track of how many UniFi engineering leads joined and then quit after it started falling apart. Before I quit, I heard rumors that the CEO was making two separate teams work on the Dream Machine project separately, competing against each other. That made more people quit. I think they were trying to reboot engineering in foreign countries when I left because it felt like we were forgotten in the US offices.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#225
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Mikrotik have products that are exactly like that.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#226
post #194

Should have blown the whistle to the SEC instead. SEC whistleblowers get paid. Up to 30% of eventual penalties paid by the company with no upper limit. Lying about a breach could be securities fraud.

They may already have. Investigation is already pending: https://finance.yahoo.com/news/shareholder-alert-ubiquiti-in...

This might just be a law-firm fishing for people willing to be plaintiffs when they sue. So, this in itself might not mean much of anything. This might just be a lawyer who read the news and though "Hey, let's see if we can find enough people willing to sue!"

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#227
post #183

Earlier quoted context omitted.

Are you concerned that TP-Link is a Chinese company? Could your data be exfiltrated back to China?

edit: Oops, disregard, I've violated HN hivemind statutes, despite being completely factually correct! What I meant to say is that US law enforcement, and in particular the FBI, are 100% perfect in every way. Nobody has EVER used lawful request overreach to ruin the lives of innocent people. Praise be to J. Edgar Hoover!

Kinda like spreading the risks

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#228
post #183

Earlier quoted context omitted.

Are you concerned that TP-Link is a Chinese company? Could your data be exfiltrated back to China?

edit: Oops, disregard, I've violated HN hivemind statutes, despite being completely factually correct! What I meant to say is that US law enforcement, and in particular the FBI, are 100% perfect in every way. Nobody has EVER used lawful request overreach to ruin the lives of innocent people. Praise be to J. Edgar Hoover!

I'm not sure where your router connects upstream, but they don't have to swim very far to find somewhere to feed.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#229

Earlier quoted context omitted.

I almost did the same thing, but it was clear a year ago that they were moving towards "cloud based" services, something I didn't want to participate in. Looks like it was a good decision, in retrospect.

So what did you go with?

Ended up with some used Cisco equipment aimed at the small business segment. Similar-ish price to new Ubiquiti gear, and I've spent essentially 0 time maintaining the stuff beyond initial setup. Still don't have APs set up though, I've just been making do with what I had laying around.
Post reply on HN