Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

291–300 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#291

Earlier quoted context omitted.

Right. I would never have any device like a camera be directly connected to the internet and instead cut off that device from the internet in my router software and only access it from outside via a VPN. Not that this whole screw-up should be excused in any way or downplayed.

I bought one of their security cameras to act as a nursery cam last year, which I could later convert into a home security camera. The 'in house' software, unifi-video, was discontinued 3 months after I got it set up. All of the apps I use to connect to the system have been pulled from the app store, and you now have to use their camera controller for the one camera, vs the software Im running on my linux box. Their…

I now use the camera in direct rtsp mode. This way it can be used by any rtsp tool including video recording and the lot. For the nursery camera I just use IPCams on iOS on an iPad.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#292

Earlier quoted context omitted.

The early days at Ubiquiti were good. I worked with a lot of good engineers and we shipped good work. The decline is a recent problem. > How the brand hasn't become toxic already is a mystery to me, yet look at the stock price tracker. It's been trending up for years and it has well over doubled in the past six months alone. This is your answer. No incentive to change. All of the bad engineering decisions have been r…

>I heard rumors that the CEO was making two separate teams work [. . .] separately, competing against each other. I don't work in tech, so maybe I'm dumb to this, but why would you ever do this?

This is not surprising to me at all.

IMO, the CEO had a bit of a Steve Jobs hero-worship complex, but only all the bad parts. I can absolutely see him putting two teams on the same project, and "may the best product win".

The team that "lost" would get canned, obviously (I saw it happen to two separate offices while I was there).

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#293
post #76

Earlier quoted context omitted.

These recent posts about Ubiquiti have made me look again at MikroTik. Their hardware is more affordable than I had remembered. Is there any good intro to their hardware - there are certainly a lot more options than you get with Ubiquiti. Even before now there are some limitations with UniFi that have annoyed me. Setting up more complex DNS and firewall rules requires editing the JSON config. IPv6 tunnelling isn’t we…

It may sound strange, but for Mikrotik, I find it more productive to concentrate on setting them up via CLI. It's certainly more trainable. CLI for Port Forward: /ip firewall nat add chain=dstnat dst-port=1234 in-interface=ether1-gateway action=dst-nat protocol=tcp to-address=192.168.1.1 to-port=1234 VS having to document the same task in the GUI: IP->Firewall->Nat-> Add New General Tab Chain: dstnat Protocol: TPC Ds…

The CLI tab-completion is great - you can figure out most of what you need to do just by looking at it.

Highly worth getting one to try out.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#294

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Look into Mikrotik hardware and OpenWRT. Of the Mikrotik-based hardware I'm familiar with, they support PoE. OpenWRT supports roaming and mesh networks, and is a local solution, as opposed to a cloud-based one. There are no licenses you need to pay for, either.

Mikrotik is amazing, for what you get. But of a learning curve but worth the effort, I've seen large scale wireless networks crossing mountains with their kit.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#295
post #154

Earlier quoted context omitted.

No, a local controller that you run on a machine inside your LAN.

Their http interface is reasonable and you can configure/provision the APs from CAPSman from one of the routers/switches in a central location.

You can also script against the Mikrotik CLI - I use it to update the certificates every ~90 days.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#296
post #189

Earlier quoted context omitted.

Now rewrite your entire comment with s/ubiquiti/sonos/g. So much wasted potential ... so much customer goodwill wasted because (apparently) no company is worth running unless it is a publicly traded unicorn.

Why is it so easy to snatch defeat from the jaws of victory in tech?

Greed. 100% greed. While I was there, the CEO loved to just fly between offices (randomly) on his private jet. You never knew where he'd pop up, and that put everybody on edge, because when he was unhappy he tended to fire people in large chunks (and shut down entire offices). Every decision was motivated by how it affected the stock price.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#297

> the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee The interesting part of this story is how the employee's LastPass got popped. My guess is their local workstation was compromised, and their LastPass was either not logged out in a browser plugin, or they didn't have 2 factor auth required for each login and a keylogger got the password…

Easy to imagine they just got a spiked chrome binary installed

How could an attacker make that happen?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#298

Earlier quoted context omitted.

No. They don't care if customers get pwnd. They care if customers become aware of exactly how they got pwnd and launch a class action. It's shitty but entirely predictable behavior common in these situations.

But rotating credentials would not hurt or help that alleged goal of hiding the truth from customers...

“force rotation of all customer credentials” = make customers change their passwords, which is a huge red flag that would draw attention to why they were forcing that.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#299

> the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee The interesting part of this story is how the employee's LastPass got popped. My guess is their local workstation was compromised, and their LastPass was either not logged out in a browser plugin, or they didn't have 2 factor auth required for each login and a keylogger got the password…

> My guess is their local workstation was compromised

Honestly I don't think it was even that complicated, considering when I needed to spend money on some SaaS product the "chief accountant" (because there was no CFO) straight up sent me a photo of the corporate credit card and said "delete that when you're done".

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#300
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

After the Unifi Video fiasco, I bought a UDM Pro to test Unifi Protect. Once I saw it required cloud login I got scared. After I saw an ubiquiti ssh key preinstalled in a device with unfeteted internet access I shut it down to never bring it up again

Wow, are you serious?
Post reply on HN