> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…
Whistleblower: Ubiquiti Breach “Catastrophic”
261–270 of 815 posts
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#262Earlier quoted context omitted.
I mean, yes, it does. However hopefully the hackers aren't in their system anymore - so if you were at risk it's already probably over. I guess just change your password and reset your 2FA?
Ugh. Guess I’ll just go wired for now and unplug the AP. Hopefully I’m only paranoid, but I really don’t like the feeling of a hole in the network with my family’s NAS and IoT devices. Never again with the cloud-connected network appliances. Time to build a router from scratch, I guess.
1. https://help.ui.com/hc/en-us/articles/360012282453-UniFi-Set...
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#263How are we ever going to solve security as an industry against this? Again we're told that security isn't important. Being the first to market and insecure is the winning play and that's just fucked.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#264> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
It's odd how the big cloud vendors have been able to escape criticism for being completely open by default. Other vendors have been taken to task and have adopted better security practices. For example, SuperMicro IPMI comes with a random password now. It's extremely difficult to lock down an AWS account when there are a bajillion services, IAM policies, roles, etc.. I've been trying for the last few days and it's so…
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#265Was days away from refitting my home out with £2,000 of gear. Any other recommendations for routers, wifi and security cameras?
I have happily upgraded several homes from Mikrotik and/or Ubiquiti to Eero mesh - https://eero.com/
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#266Why? Coincidence?
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#267Earlier quoted context omitted.
Use Organizations. If you’re creating new standalone independent accounts for teams you’re just seeking yourself up for some kind of billing/security/governance catastrophe down the road.
I was referring to the root accounts in your organization. The blast radius is more limited, but still a root account that has access to everything within that AWS account.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#268> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
It's odd how the big cloud vendors have been able to escape criticism for being completely open by default. Other vendors have been taken to task and have adopted better security practices. For example, SuperMicro IPMI comes with a random password now. It's extremely difficult to lock down an AWS account when there are a bajillion services, IAM policies, roles, etc.. I've been trying for the last few days and it's so…
While your concerns are 100% valid, we need to remember too that setting up access in restricted ways and inviting users to understand the protection and remove the correct barriers, or implement the concerns necessary to interact with those for themselves, always runs the risk that some users will find your protections cumbersome and instead find a (totally incorrect) way to baffle them, or otherwise even route around them entirely mooting any efforts to secure a platform.
And every time I hear this played out in conversation, the answer is "that's on them!" But it's clearly a balancing act, it's a trade off; tautologically, when you make the service less accessible then... it is, well, ... made less accessible.
Besides facilitation of the secure access also sales conversion ratios will depend on that accessibility. The crux of your argument stands, the defaults are too open, and we need to do more to ensure that naive users aren't handed a loaded gun to aim at their own feet.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#269Well this absolutely sucks :(. I've been a huge supporter of Ubiquiti ever since I was buying mini their PCI cards and sticking them into soekris engineering boards (ubiquiti started out as a hardware company). The magic thing that absolutely sold me on their equipment was the ease with with you could provision and mesh new gear. Does anybody have anything that compares with that ease of use? To explain what I mean:…
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#270Earlier quoted context omitted.
Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…
It's a shame that Mikrotik doesn't have a easy to use global GUI. It's the right hardware, and great firmware and wonderful flexibility - but it needs an easy to use GUI controller to make the simple stuff easy to take over from Ubiquiti.