Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

231–240 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#231
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

After the Unifi Video fiasco, I bought a UDM Pro to test Unifi Protect.

Once I saw it required cloud login I got scared. After I saw an ubiquiti ssh key preinstalled in a device with unfeteted internet access I shut it down to never bring it up again

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#232
post #141

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

As far as I know, TP-Link doesn't require any cloud based service, or even a local controller. They can work fine without any of it and you just manage them locally/directly.

I've never had good luck with TP-Link hardware though. Constant crashes/disconnections once you get past a few devices on the network, mysterious failures, hardware quickly getting dumped into the unsupported list, and so on. I've sworn off of them entirely.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#233

This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.

I picked up an EdgeRouter and none of the cloudkey/unifi stuff. I initially felt like maybe I should have picked the unifi gear and maybe a dumb switch, but now I don’t regret the EdgeRouter. Couldn’t be happier with it.

I don’t trust anything that tries to solve the “firewall problem” by setting up a cloud service for what should be a local appliance.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#234
> the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee

The interesting part of this story is how the employee's LastPass got popped. My guess is their local workstation was compromised, and their LastPass was either not logged out in a browser plugin, or they didn't have 2 factor auth required for each login and a keylogger got the password. In either case, it's a good reminder to be paranoid about your password manager, make sure it's got a logout timer, and use 2 factor auth.

I also don't let my cloud password managers touch a mobile device. It's fairly inconvenient, so I hesitate to recommend this to others. But I don't trust mobile devices very much. Anyone have thoughts on this?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#235

Why do people trust any IoT devices these days? Shouldn't we be trying to reduce our exposure to (inevitably insecure) software? What benefits does it provide that are worth the unbounded risks?

It’s not _that_ unbounded? At least not yet! Until a tech savvy neighbor who’s also a creep can easily break into your network and home camera I’m not personally worried.

been doing it for years. meet the new boss, same as the old boss.

this is the other side of the coin of "you don't need privacy if you have nothing to hide", and it's exactly as stupid in application here as it ever is.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#236
post #141

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

As far as I know, TP-Link doesn't require any cloud based service, or even a local controller. They can work fine without any of it and you just manage them locally/directly.

Yep, this is what I do. I used the EAP245 and now the EAP 660 HD. Both were rock solid devices. Managed locally via a web browser. Plugs into a netgear switch, into a pfsense router.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#237
post #192
post #141

Earlier quoted context omitted.

As far as I know, TP-Link doesn't require any cloud based service, or even a local controller. They can work fine without any of it and you just manage them locally/directly.

TP-Link is a Chinese company. Doesn't inspire much confidence..

You could try using an aftermarket, open source firmware. Something like Open-WRT

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#238
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

> can we really trust them to clean up all their tokens and fully eradicate all forms of persistence the hackers may have gotten?

The state of security in the tech industry is miserable. The only companies we should trust not to leak our data are those that never collected it in the first place.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#239
post #183

Earlier quoted context omitted.

edit: Oops, disregard, I've violated HN hivemind statutes, despite being completely factually correct! What I meant to say is that US law enforcement, and in particular the FBI, are 100% perfect in every way. Nobody has EVER used lawful request overreach to ruin the lives of innocent people. Praise be to J. Edgar Hoover!

It's a sad commentary on how low the bar has been lowered. "No, you're system isn't secure, but the people that can access it can't really do you bodily harm" is not really the level I would hope we are trying to acheive.

This isn't useful input on where the actual bar is since these are all just conspiracy theories. Who is doing any of this?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#240

Earlier quoted context omitted.

Man I really wonder why the lack of proper 2FA is so wide spread? Is it rally cost and complexity? Or just missing awareness? Or the lack of consequences when you get hacked in a way which could easily have been prevented (through then they might have attacked in a different way, tbh.).

He could have had 2fa on his console account but saved an access key for CLI access. Many large organizations have an infrastructure where you exchange your corporate authentication (including 2FA) for a short lived AWS access key, but AFAIK this isn’t out of the box.

AWS SSO does offer this "out of the box", but many large organizations use their own custom SSO setup with custom-built tools to get temporary tokens.
Post reply on HN