Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

271–280 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#271

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Mikrotik, but unfortunately getting reasonable throughput for wireless clients is a serious challenge (I always have better results with openwrt on the same hardware). Still, nice to have local control and not have to rely on some cloud service just to use the hardware I bought.

I wonder what is reasonable WiFi throughput for you?

With my 5 year old Mikrotik hAP AC I am able to get up to 500 Mbit/s on lan.

And my old phone now shows 250 Mbit/s on speedtest.net both directions.

How much more are we talking about? Have I missed some big hardware upgrade recently?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#272
I’m willing to see what Ubiquiti will do to make it right before I switch away, because I have a local-only setup of EdgeRouter and UniFi APs that’s been absolutely great in the years I’ve had it, but this is really last chance saloon stuff now.

I’m looking for a proper post-mortem and the steps to make sure it can’t happen again, recommitment to local-only users and respect of the customer, and a step back from the push to cloud everything.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#273

Earlier quoted context omitted.

I have happily upgraded several homes from Mikrotik and/or Ubiquiti to Eero mesh - https://eero.com/

"an amazon company" already makes some warning lights blink in my head. Do they have cloud integration of any kind?

It's cloud managed and sends network information to Amazon.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#274

> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed” Perversely, this is exactly the logging that you want to have in place in case of a breach. You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”

"We believe that the hackers obtained read-write access to our database, but we also believe that they were too polite to actually use it for anything."

"Hacker came in through the server hard-line" <-- HollyWoods favorite Hacker Trope.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#275

Earlier quoted context omitted.

It's unfortunate what seems to have happened to Ubiquiti. The idea of decent network hardware with a good UI that can support the prosumer to small business segment of the market has a lot going for it. In the early days, it seemed like Ubiquiti was going to nail it and was building up a strong, loyal following as a result. Then came all the reports of quality problems, promised features never delivered, phoning-home…

The early days at Ubiquiti were good. I worked with a lot of good engineers and we shipped good work. The decline is a recent problem. > How the brand hasn't become toxic already is a mystery to me, yet look at the stock price tracker. It's been trending up for years and it has well over doubled in the past six months alone. This is your answer. No incentive to change. All of the bad engineering decisions have been r…

What do you suggest for someone leaning on an EdgeRouter Lite (with EdgeOS v1.10.11, staying far away from v2.x) and a Unifi UAP-AC-PRO access point?

The router will probably reliably carry me until saturating 1Gbps becomes a daily occurrence and the access point will be retired when WiFi 6E comes around (assuming Ubiquiti's WiFi 6E access points aren't required to connect to the cloud.)

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#276

Earlier quoted context omitted.

Yeah that doesn’t make sense to me. Sales would do something like that. Legal should be erring in the opposite direction.

No. They don't care if customers get pwnd. They care if customers become aware of exactly how they got pwnd and launch a class action. It's shitty but entirely predictable behavior common in these situations.

But rotating credentials would not hurt or help that alleged goal of hiding the truth from customers...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#277

Earlier quoted context omitted.

They are amazon-owned. I'd be shocked if they weren't collecting and reporting telemetry.

Telemetry is an extremely important part of making things just work. There's no other way to find the unknown unknowns.

That's awfully convenient for the company offering those products, but I want to control what happens on my network, even if that's inconvenient for some hardware vendor.

Case studies, focus groups, surveys and interviews are great ways to find the unknown unknowns. Of course, you need to pay people to participate in them, and then you need to pay expensive employees to conduct, collect and analyze the results.

It's often just cheaper to spy on customers, though, and pretend that there is no other possible way to conduct business.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#278

Earlier quoted context omitted.

It's unfortunate what seems to have happened to Ubiquiti. The idea of decent network hardware with a good UI that can support the prosumer to small business segment of the market has a lot going for it. In the early days, it seemed like Ubiquiti was going to nail it and was building up a strong, loyal following as a result. Then came all the reports of quality problems, promised features never delivered, phoning-home…

The early days at Ubiquiti were good. I worked with a lot of good engineers and we shipped good work. The decline is a recent problem. > How the brand hasn't become toxic already is a mystery to me, yet look at the stock price tracker. It's been trending up for years and it has well over doubled in the past six months alone. This is your answer. No incentive to change. All of the bad engineering decisions have been r…

>I heard rumors that the CEO was making two separate teams work [. . .] separately, competing against each other.

I don't work in tech, so maybe I'm dumb to this, but why would you ever do this?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#279
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

If you don't feel like configuring hostapd and dnsmasq I'm pretty sure there's an nmcli one-liner that will have network manager run a WAP for you. I use 'hotspot' on my phone all the time.

WAPs have been absolute crap for years.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#280
post #129
post #114

Earlier quoted context omitted.

Im a bit confused by this. I run a UniFi Controller in a docker container, have a few APs and a router, and everything works fine. No cloud stuff going on here. Am i just lucky or something that i havent been forced to the cloud yet, or is it something i am missing here?

I think its just the cloud key. I have a unifi controller install as well and use a local account with no issues.

I have a cloud key with no cloud access. It's just that cloud access is the user directed workflow for sure. Setup without cloud access was not clear at all [1].

[1]: I don't even remember the steps, to be honest!

Post reply on HN