Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

331–340 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#331
post #292

Earlier quoted context omitted.

>I heard rumors that the CEO was making two separate teams work [. . .] separately, competing against each other. I don't work in tech, so maybe I'm dumb to this, but why would you ever do this?

This is not surprising to me at all. IMO, the CEO had a bit of a Steve Jobs hero-worship complex, but only all the bad parts. I can absolutely see him putting two teams on the same project, and "may the best product win". The team that "lost" would get canned, obviously (I saw it happen to two separate offices while I was there).

> IMO, the CEO had a bit of a Steve Jobs hero-worship complex, but only all the bad parts.

Part of me wishes Steve Jobs had never been brought back to Apple and died in obscurity. He's such a bad example. People idolize him, but his good parts can't be imitated, his bad parts can, and a lot of people can't seem to tell the difference.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#332

You are required to have internet access to setup something like the UDM-Pro. After it is setup you can create a local admin account and disable remote access. Here is how: 1. Login with your online account credentials and password 2. Choose system settings 3. Choose advanced 4. Disable Remote Access 5. Confirm that "Transfer owner" won't be available if you disable remote access. The issue in general is that the Uni…

I just did this for a controller that is hosted on a VM (via the new controller UI), I went through a couple of additional steps.

1. Disable "Enable Remote Access"

2. Setup SMTP (since disabling remote access stops routing emails through Ubiquiti's backend)

3. Create a new admin not tied to a cloud Ubiquiti account (via "Administrators")

4. Disable "Sync Local Admin with Ubiquiti SSO" (the older UI says "Enable Local Login with UBNT Account")

5. Delete the old admin account

Steps 3 and 5 may not really be necessary, but I did to be safe.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#333
post #189

Earlier quoted context omitted.

Now rewrite your entire comment with s/ubiquiti/sonos/g. So much wasted potential ... so much customer goodwill wasted because (apparently) no company is worth running unless it is a publicly traded unicorn.

Just curious (I agree with you), but what are the s/ and /g for? Samsung and Google?

https://www.cyberciti.biz/faq/how-to-use-sed-to-find-and-rep...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#334
post #189

Earlier quoted context omitted.

Now rewrite your entire comment with s/ubiquiti/sonos/g. So much wasted potential ... so much customer goodwill wasted because (apparently) no company is worth running unless it is a publicly traded unicorn.

Just curious (I agree with you), but what are the s/ and /g for? Samsung and Google?

[deleted]

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#335

You are required to have internet access to setup something like the UDM-Pro. After it is setup you can create a local admin account and disable remote access. Here is how: 1. Login with your online account credentials and password 2. Choose system settings 3. Choose advanced 4. Disable Remote Access 5. Confirm that "Transfer owner" won't be available if you disable remote access. The issue in general is that the Uni…

Just verifying my understanding: this will make it impossible to reach the device from ui.com or otherwise off-network, but an attacker could: 1. use leaked SSO keys to forge an SSO token 2. craft a malicious webpage 3. get an unsuspecting UDMP user (e.g., me) to navigate to that page 4. run scripts on that page that would access & interact with the UDMP from the browser within the network, using the forged SSO Is th…

The difference is that the attack you suggest has to be targeted

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#336

Earlier quoted context omitted.

Telemetry is an extremely important part of making things just work. There's no other way to find the unknown unknowns.

That's awfully convenient for the company offering those products, but I want to control what happens on my network, even if that's inconvenient for some hardware vendor. Case studies, focus groups, surveys and interviews are great ways to find the unknown unknowns. Of course, you need to pay people to participate in them, and then you need to pay expensive employees to conduct, collect and analyze the results. It's…

> Case studies, focus groups, surveys and interviews are great ways to find the unknown unknowns. Of course, you need to pay people to participate in them, and then you need to pay expensive employees to conduct, collect and analyze the results

No they're not, because the vast majority of people simply won't be bothered, and most people probably aren't as reliable as concrete data.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#337
post #144

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Isn't enough to just disable cloud access? Edit: I got upvoted by somebody, but as an UI user I'm genuinely looking for an answer. If it's still possible to get inside if devices aren't connected to UIs cloud.

That’s a part of it. But also:

1. They are now pushing ads to their local controllers. That is a shady tactic. It also means the controller is phoning home. It means they might have an XSS in that code now or in the future.

2. They just deprecated a bunch of relatively new hardware. If I’m going to invest a non-trivial amount into their hardware I want to know it’ll keep working for a long time.

3. They lost trust due to this breach. How can I trust their code to secure my locks network if they can’t secure their own?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#338
post #192

Earlier quoted context omitted.

TP-Link is a Chinese company. Doesn't inspire much confidence..

You could try using an aftermarket, open source firmware. Something like Open-WRT

TPLink newer stuff wasn't supported and wasn't going to be DD-WRT for a while there so check first. They have a crypto blob for the radio binary, or the entire firmware system they the group would need to trust blind and not be able to adjust settings with, or violate the DMCA to reverse engineer.

Don't know if this is the same case still or not, but they did this for FCC compliance around the time 802.11ac was launching. That might have changed that though I'm not sure, I stopped considering them at that time.

Also a good company to look at would be Microtek, I have heard good things, but haven't looked into them directly.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#339
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

So one might call them... ubiquitous?

I'm so sorry. I'll go now.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#340

Earlier quoted context omitted.

They are amazon-owned. I'd be shocked if they weren't collecting and reporting telemetry.

Telemetry is an extremely important part of making things just work. There's no other way to find the unknown unknowns.

I have lots of devices that don’t phone home. Have been working for years. The company needing to know which websites I visit to make my network function does not speak well of the company.
Post reply on HN