Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

281–290 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#281

Earlier quoted context omitted.

Technically, Ubiquiti does have a local option. You can run the controller locally and disable cloud login.

Protect still needs cloud to be activated for authentication it seems. I used to have remote access turned off and accessed the video streams via the iOS app when my phone was on VPN to the local network. That no longer works. Remote access (cloud) needs to be activated in order for the iOS app to work, no matter if you are on the local network or not.

When did that start?

My controller is only on 6.0.43 but i can access it via iOS app on VPN.

My contoller only does Wireless/AP management though. nothing more.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#282
post #189

Earlier quoted context omitted.

I worked at Ubiquiti while you were there. I can confirm that the company was going downhill fast. The US offices were starting to feel empty because so many people were leaving the company. Only place I've ever worked where engineers would quit before they got another job. Saddest part was all the wasted potential. There were good engineers making good products at Ubiquiti only a few years ago. Once UniFi exploded i…

Now rewrite your entire comment with s/ubiquiti/sonos/g. So much wasted potential ... so much customer goodwill wasted because (apparently) no company is worth running unless it is a publicly traded unicorn.

Why is it so easy to snatch defeat from the jaws of victory in tech?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#283
post #92

It really doesn't get worse than this. But isn't Ubiquiti more of a prosumer company, like MikroTik? MikroTik does get a lot of heat when they have a security vulnerability and get downranked for it as if it were far, far away from Ubiquiti's security profile (something like "US vs. some east EU country"), but this event tells a lot about Ubiquiti's upper management and their internal security practices.

Have MikroTik had any security vulnerabilities anywhere close to what has now been revealed about Ubiquiti? MikroTik's firmware seems very solid and I get the impression that they care about security and routines.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#284

> Ubiquiti’s shares have surged from $243 on Jan. 13 to $370 as of today. How are we ever going to solve security as an industry against this? Again we're told that security isn't important. Being the first to market and insecure is the winning play and that's just fucked.

I don't think that it is a solvable problem if the economics stay the same.

SolarWinds is actually trading almost $2/share more than it did 1 year ago today ($15.67 v $17.23). Sure, it is down from its 52 week high ($24.34).

I would argue that SolarWinds should not be allowed to be in business in its current form, considering what a threat they have been to themselves and others in their mis-handling their software practices and subsequent breach. If an individual did what they did as an employee of the government, they would currently be in jail.

It is probably one of the most impactful national security events in our lifetimes and the impact of this event will be felt in certain areas for years or even decades.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#285

> the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee The interesting part of this story is how the employee's LastPass got popped. My guess is their local workstation was compromised, and their LastPass was either not logged out in a browser plugin, or they didn't have 2 factor auth required for each login and a keylogger got the password…

Easy to imagine they just got a spiked chrome binary installed

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#286
post #76

Earlier quoted context omitted.

It's a shame that Mikrotik doesn't have a easy to use global GUI. It's the right hardware, and great firmware and wonderful flexibility - but it needs an easy to use GUI controller to make the simple stuff easy to take over from Ubiquiti.

These recent posts about Ubiquiti have made me look again at MikroTik. Their hardware is more affordable than I had remembered. Is there any good intro to their hardware - there are certainly a lot more options than you get with Ubiquiti. Even before now there are some limitations with UniFi that have annoyed me. Setting up more complex DNS and firewall rules requires editing the JSON config. IPv6 tunnelling isn’t we…

The best intro really is to buy some of their hardware and play around with it. Their routers and APs are all based on the same basic RouterBOARD hardware and run the same RouterOS. The specs for each device is pretty well laid out on their site, but you do have to read through a few product pages to find exactly what you're looking for.

I would start with a hAP ac², a wireless router that is approximately the equivalent of their hEX Ethernet router plus a dual-band AP (cAP/wAP ac). It's a great standalone device and less than $70, or you could get the individual devices for a bit more flexibility.

Avoid the models labeled "lite", those are low-cost versions with lower routing speeds and 2.4GHz WLAN only.

For management you can obviously configure each device separately, or you can use CAPsMAN where one device acts as the controller and handles all configuration. It's not as slick as Ubiquiti, but it works.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#287

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Look into Mikrotik hardware and OpenWRT. Of the Mikrotik-based hardware I'm familiar with, they support PoE. OpenWRT supports roaming and mesh networks, and is a local solution, as opposed to a cloud-based one. There are no licenses you need to pay for, either.

I just ordered a mikrotik 10gb https://mikrotik.com/product/crs305_1g_4s_in. The guys at work recommended it so hoping for the best!

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#288

Earlier quoted context omitted.

This boggles me when I see this option in any password manager (and I think every single one has this 'option'). Why do password managers let people store TOTP next to the password, this completely invalidates the 2FA of TOTP if your password manager get broken into.

Because I already use MFA to access my password manager in the first place, and don't want to deal with managing backups for each flavor of MFA app that is pushed on me.

How do you manage MFA for encryption-at-rest? None of the common TOTP systems do this. LastPass and 1Pass have built-in "local encryption keys", but they're stored in the same place as the store and only protected by your password. I think theoretically you could set this up with Keepass using a Composite Master Key (combining a password-protected key and a certificate-protected key, storing the certificate separately, ideally in an HKM), but I don't know anyone who does this.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#289
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Turris series.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#290

> the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee The interesting part of this story is how the employee's LastPass got popped. My guess is their local workstation was compromised, and their LastPass was either not logged out in a browser plugin, or they didn't have 2 factor auth required for each login and a keylogger got the password…

> My guess is their local workstation was compromised

You mean someone was physically at the laptop/desktop and could access the OS and apps? Maybe if the employee was working remote (covid?) from, say, a cafe and left the laptop unattended when refilling coffee?

Or something else? ... Hmm, could also have been eg a browser zero day that gave someone remote access to the computer? Or a dev tools supply chain attack?

Post reply on HN