Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

261–270 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#261
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Look into Mikrotik hardware and OpenWRT. Of the Mikrotik-based hardware I'm familiar with, they support PoE. OpenWRT supports roaming and mesh networks, and is a local solution, as opposed to a cloud-based one. There are no licenses you need to pay for, either.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#262

Earlier quoted context omitted.

I mean, yes, it does. However hopefully the hackers aren't in their system anymore - so if you were at risk it's already probably over. I guess just change your password and reset your 2FA?

Ugh. Guess I’ll just go wired for now and unplug the AP. Hopefully I’m only paranoid, but I really don’t like the feeling of a hole in the network with my family’s NAS and IoT devices. Never again with the cloud-connected network appliances. Time to build a router from scratch, I guess.

You can run the AP locally with the standalone controller appliance in a container or VM[1]. Pretty simple, and doesn't require a UNBT login. Probably still worth doing a factory reset on your AP first, if you're paranoid like me...

1. https://help.ui.com/hc/en-us/articles/360012282453-UniFi-Set...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#263
> Ubiquiti’s shares have surged from $243 on Jan. 13 to $370 as of today.

How are we ever going to solve security as an industry against this? Again we're told that security isn't important. Being the first to market and insecure is the winning play and that's just fucked.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#264
post #179
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

It's odd how the big cloud vendors have been able to escape criticism for being completely open by default. Other vendors have been taken to task and have adopted better security practices. For example, SuperMicro IPMI comes with a random password now. It's extremely difficult to lock down an AWS account when there are a bajillion services, IAM policies, roles, etc.. I've been trying for the last few days and it's so…

You can use AWS Accounts like microservices. The biggest security walls in AWS are the account barriers. Those have to be specifically configured to cross. Sometimes (1%) its unavoidable, but if you have multiple services running on an account, you force yourself to weave arcane webs of IAM permissions crisscrossing all over to get what you need where. It's a terrible model that people inflict on themselves because it's how everything used to work.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#265

Was days away from refitting my home out with £2,000 of gear. Any other recommendations for routers, wifi and security cameras?

I have happily upgraded several homes from Mikrotik and/or Ubiquiti to Eero mesh - https://eero.com/

"an amazon company" already makes some warning lights blink in my head. Do they have cloud integration of any kind?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#267

Earlier quoted context omitted.

Use Organizations. If you’re creating new standalone independent accounts for teams you’re just seeking yourself up for some kind of billing/security/governance catastrophe down the road.

I was referring to the root accounts in your organization. The blast radius is more limited, but still a root account that has access to everything within that AWS account.

You can restrict what the root account can do in a member account using SCPs as an additional safeguard as well.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#268
post #179
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

It's odd how the big cloud vendors have been able to escape criticism for being completely open by default. Other vendors have been taken to task and have adopted better security practices. For example, SuperMicro IPMI comes with a random password now. It's extremely difficult to lock down an AWS account when there are a bajillion services, IAM policies, roles, etc.. I've been trying for the last few days and it's so…

The triangle says Confidentiality, Availability, Integrity.

While your concerns are 100% valid, we need to remember too that setting up access in restricted ways and inviting users to understand the protection and remove the correct barriers, or implement the concerns necessary to interact with those for themselves, always runs the risk that some users will find your protections cumbersome and instead find a (totally incorrect) way to baffle them, or otherwise even route around them entirely mooting any efforts to secure a platform.

And every time I hear this played out in conversation, the answer is "that's on them!" But it's clearly a balancing act, it's a trade off; tautologically, when you make the service less accessible then... it is, well, ... made less accessible.

Besides facilitation of the secure access also sales conversion ratios will depend on that accessibility. The crux of your argument stands, the defaults are too open, and we need to do more to ensure that naive users aren't handed a loaded gun to aim at their own feet.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#269
post #202

Well this absolutely sucks :(. I've been a huge supporter of Ubiquiti ever since I was buying mini their PCI cards and sticking them into soekris engineering boards (ubiquiti started out as a hardware company). The magic thing that absolutely sold me on their equipment was the ease with with you could provision and mesh new gear. Does anybody have anything that compares with that ease of use? To explain what I mean:…

I can vouch for Google WiFi. Very simple to set up.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#270

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

It's a shame that Mikrotik doesn't have a easy to use global GUI. It's the right hardware, and great firmware and wonderful flexibility - but it needs an easy to use GUI controller to make the simple stuff easy to take over from Ubiquiti.

Stick OpenWRT or pfSense on them, and you've got yourself a nice GUI. You can use the CLIs if you want to, too.
Post reply on HN