Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

251–260 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#251

Is it just me or are you no longer able to avoid the cloud with the latest software updates for unifi?

If you are using CK, Protect and/or the iOS app, it seems that you need Remote Access (a.k.a. Cloud) enabled for authentication.

No you do not, only setup. You can disable it after. See my other comment.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#252
post #175

Earlier quoted context omitted.

OpenWRT also provides SSH access and CLI tools, so if needed things can be automated the old-fashioned way.

I don't know about you, but I "automate the old-fashioned way" at my day job, I want the damned thing to just work without me bothering with "SSH access and CLI tools" at home.

and how many APs do you have at home?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#253

Earlier quoted context omitted.

Global UI? You mean, AWS-hosted configurator for your network? We just had example of it being security risk. God save Mikrotik from implementing something similar.

No, a local controller that you run on a machine inside your LAN.

nothing stopping you from using a local ubiquiti controller though. you aren't tied to their servers if you don't want to use them. that said, they seem pretty problematic from a security standpoint based on these leaks and your networking infra should be rock solid.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#254

Earlier quoted context omitted.

That's how I run it, but it seems they are now pushing ads to local controllers and between this and deprecating recently released devices, I just completely lost trust in them.

> it seems they are now pushing ads to local controllers The pervasiveness of adtech doesn't cease to impress me.

I really hope that one day it will be remembered the same way we remember ritual sacrafice .

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#255
post #151
post #110

Earlier quoted context omitted.

So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…

> So the question for becomes: is there just not a good enthusiast market for this stuff? No. They just don't want to serve the low end. I'm from SK, Canada and the vast majority of all businesses are small businesses. This site [1] says 98%. The problem is they only account for about 25% of the GDP, so vendors don't consider them worth serving. Everyone wants to sell to the 2% of the businesses that make up 75% of t…

You often do not need long sales processes to get those small companies, they tend to self serve selling to themselves.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#257

Earlier quoted context omitted.

Technically, Ubiquiti does have a local option. You can run the controller locally and disable cloud login.

Protect still needs cloud to be activated for authentication it seems. I used to have remote access turned off and accessed the video streams via the iOS app when my phone was on VPN to the local network. That no longer works. Remote access (cloud) needs to be activated in order for the iOS app to work, no matter if you are on the local network or not.

i've run my own controller locally for years without forced cloud login.. i've never used the ios app, what can you do from it that you can't do from the web interface?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#258

"Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies." Holy... Wow. That is catastrophic. Everything is c…

Or they'll just change their passwords and pretend to have solved the problem.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#259
post #221

Earlier quoted context omitted.

> Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Isn't one of the major selling points of cloud-everything "How can you possibly secure your service better than BigRespectableCompany?" I know any time I bring up self-hosting E-mail or a web site or whatever, someone always comes out of the woodwork to remind me that I am not an expert in securing Internet services, and tha…

You may be smart, and have secured your systems properly, but someone with the same resume as you in another company might not be. As your manager, how can I tell the difference between someone who actually did the work right, and someone who said they did the work right (and also legitimately believes that they did)?

You never can be... but you should already know that being a manager. But if you're the target of an advanced persistent threat. It doesn't matter how good your guys is, they'll win eventually when the next 0day no one knew about shows up. But then your cloud provider will have been broken into dozens of times already. Hundreds of companies have to do a security audit of all of their networks now* because Ubnt got, got. The only ones who don't are idiots, or not using ubnt et al.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#260
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

ubiquiti is fine. you don't have to use the cloud controller. CLI works just fine, at least the products I have used.
Post reply on HN