Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

301–310 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#301

Earlier quoted context omitted.

Man I really wonder why the lack of proper 2FA is so wide spread? Is it rally cost and complexity? Or just missing awareness? Or the lack of consequences when you get hacked in a way which could easily have been prevented (through then they might have attacked in a different way, tbh.).

He could have had 2fa on his console account but saved an access key for CLI access. Many large organizations have an infrastructure where you exchange your corporate authentication (including 2FA) for a short lived AWS access key, but AFAIK this isn’t out of the box.

You can force 2fa even for cli access as far as I remember but It's not on by default.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#302

Earlier quoted context omitted.

The early days at Ubiquiti were good. I worked with a lot of good engineers and we shipped good work. The decline is a recent problem. > How the brand hasn't become toxic already is a mystery to me, yet look at the stock price tracker. It's been trending up for years and it has well over doubled in the past six months alone. This is your answer. No incentive to change. All of the bad engineering decisions have been r…

>I heard rumors that the CEO was making two separate teams work [. . .] separately, competing against each other. I don't work in tech, so maybe I'm dumb to this, but why would you ever do this?

I imagine it comes from some flawed business belief in the survival of the fittest. I've never heard a tech person advocate for it, I only ever hear it from business types.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#303
post #284

> Ubiquiti’s shares have surged from $243 on Jan. 13 to $370 as of today. How are we ever going to solve security as an industry against this? Again we're told that security isn't important. Being the first to market and insecure is the winning play and that's just fucked.

I don't think that it is a solvable problem if the economics stay the same. SolarWinds is actually trading almost $2/share more than it did 1 year ago today ($15.67 v $17.23). Sure, it is down from its 52 week high ($24.34). I would argue that SolarWinds should not be allowed to be in business in its current form, considering what a threat they have been to themselves and others in their mis-handling their software p…

I feel like we have to regulate this at a governmental level to get anywhere. We keep automating more and more of our society and its clear we're unable to protect it but the casuals don't get that and keep charging ahead and we enable them. The amount of power we gift to a given attacker seems to just grow and grow.

But how do we achieve political intervention when technologists and politics appear to be completely incompatible? The closest I've seen is the Pirate Party which never get more than a few percent or that democratic candidate (Yang was it?) and he was pretty fucking clueless on the tech when poked with any significant vigour.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#304
post #10

Well, guess I won't be about to drop a few thousand on Ubiquiti gear anymore until we get some more details. Hopefully this account isn't fully truthful, otherwise Ubiquiti has really screwed up.

> Hopefully this account isn't fully truthful Brian Krebs is a reputable source who has a lot to lose if he makes unsubstantiated claims.

He's quoting a source. I don't doubt Krebs in the slightest but he's simply forwarding someone elses account.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#305
post #180

Earlier quoted context omitted.

That's basically what MikroTik CAPsMAN is, depending on your needs. I think it's specific to Access Points, so not a general purpose centralized controller for MikroTik equipment, but... centralizing access point management seems to be the main thing under discussion here.

CAPsMAN is a royal PITA to set up. You have to manually add all the wifi channels, map each AP to the channels it'll use, and a lot of busywork. Once it's set up, though, it works fine, and lets you upgrade all devices from the manager, etc.

> You have to manually add all the wifi channels, map each AP to the channels it'll use, and a lot of busywork.

No, you don't? I mean you can but you don't need to.

There are cases when that is useful, true - for example, the automatic channel selection makes some curious choices sometimes.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#306
post #189

Earlier quoted context omitted.

I worked at Ubiquiti while you were there. I can confirm that the company was going downhill fast. The US offices were starting to feel empty because so many people were leaving the company. Only place I've ever worked where engineers would quit before they got another job. Saddest part was all the wasted potential. There were good engineers making good products at Ubiquiti only a few years ago. Once UniFi exploded i…

Now rewrite your entire comment with s/ubiquiti/sonos/g. So much wasted potential ... so much customer goodwill wasted because (apparently) no company is worth running unless it is a publicly traded unicorn.

Just curious (I agree with you), but what are the s/ and /g for? Samsung and Google?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#307

Earlier quoted context omitted.

How is the experience otherwise? Roaming? Throughput? Reliability? I generally like their hardware.

Only been using it for a few months but it's been good. I moved the config I mentioned above (the three APs) to my parents' house and they haven't had any problems. Throughput in their case is a little limited but that's expected with the installation (no ethernet and a lotta walls). Hasn't needed a reboot or anything. I just started using an EAP660 HD[1] at home a week ago, so far so good. Haven't topped out the spe…

SOLD! Thank you.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#308
Yikes. I have a (Ubiquiti) EdgeRouter X that I previously used for a fiber setup (and it's shelved now because it doesn't like this ISP's modem), had planned to get a ER-4 later down the road. Been on the fence for any of their APs for months upon months, now I'm glad I bought neither.

Technically EdgeRouter gear is unaffected as it's very cloud-optional, but I can't bring myself to trust any firmware from them at this point. It supports OpenWRT so I guess I'll install it and go back to OpenWRT.

I see this thread already has people discussing alternatives, so I won't ask for ones -- just had to put it out there that if you own an EdgeRouter, chances are that OpenWRT has a build for it.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#310

You are required to have internet access to setup something like the UDM-Pro. After it is setup you can create a local admin account and disable remote access. Here is how: 1. Login with your online account credentials and password 2. Choose system settings 3. Choose advanced 4. Disable Remote Access 5. Confirm that "Transfer owner" won't be available if you disable remote access. The issue in general is that the Uni…

Just verifying my understanding: this will make it impossible to reach the device from ui.com or otherwise off-network, but an attacker could:

1. use leaked SSO keys to forge an SSO token

2. craft a malicious webpage

3. get an unsuspecting UDMP user (e.g., me) to navigate to that page

4. run scripts on that page that would access & interact with the UDMP from the browser within the network, using the forged SSO

Is this still a possible vector? Presumably UI would have rotated their SSO keys by now, but since there's no way to disable SSO-based login to the UDMP....

Post reply on HN