Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

381–390 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#381

At least for home networking, I'll always pick something I can throw OpenWRT on over a managed service, subscription or closed-source option. In the 15 years I've been using OpenWRT, I have never been disappointed with it, and I don't have to worry about some company's "secure" backdoor into my network being exploited.

What prosumer level OpenWRT devices do you recommend? I don't want to flash a subpar consumer router.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#382
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

You can absolutely manage ubiquiti local. Even with a ridiculously named local appliance called a cloud key. Their cameras are unfortunately another story.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#383

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Disclaimer: worked for Meraki (now Cisco Meraki) for several years. Generally, halfway decent wireless APs are all targeted at the enterprise market. Consumer hardware is a brutal race to the bottom, as lay consumers aren't qualified to compare options based on anything but price and UI. Ubiquiti was an outlier in trying to bring enterprise features to the consumer market The problem for enthusiasts and small busines…

My personal experience with Meraki has been the very definition of vendor lock-in.

The security appliance was relatively cheap, then we saw the fine print that the total bandwidth was artificially limited and increased only adaquetly two product levels up. Sorry Mr BubbleTime, you need to buy a new applicance and a new license. Your old one is worth nothing and non-transferable, watch it rot.

The switches seem absurdly expensive when you consider the 5-7 year licensing costs. And the quality is poor at best considering Meraki went and pushed a firmware update that bricked every fan in every 48 port switch we had. But you have the security appliance so it “only makes sense” to pay for these switches.

We had an IPSEC incompatibility between a vendor with an ASA and our Meraki gear. The solution was to buy a Cisco device just for that one connection.

All in all, it’s passable, but because of the lock-in it’s not like I have a cost effective choice to get away from it. I wouldn’t chose it again.

That said, it does offer a mediocre IT tech a single pane of glass they have to try to mess up.

Of all the Meraki factors I’ve learned and considered, that it is cloud-based is the least important towards my recommendation or lack of. There are lots of people that would be happy to explain all the ways my experience is wrong, but whatever.

Short version, I wouldn’t do it again.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#384
post #296

Earlier quoted context omitted.

Why is it so easy to snatch defeat from the jaws of victory in tech?

Greed. 100% greed. While I was there, the CEO loved to just fly between offices (randomly) on his private jet. You never knew where he'd pop up, and that put everybody on edge, because when he was unhappy he tended to fire people in large chunks (and shut down entire offices). Every decision was motivated by how it affected the stock price.

Even if greed is the only factor. Being unwilling to take a short term loss or hit while you rebuild or reinvest is just short sighted.

Most successes come with some amount of risk or foresight to anticipate the market.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#385
post #110

Earlier quoted context omitted.

So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…

? So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. my experience as a professional "network nerd" is that most other people in the networking field run cheap/second hand enterprise gear fetched from their employer at a major discount and simply seem to care less about wifi in g…

A lot of that changed with my peer group either due to caring about managing from a phone or caring about power/noise. The latter are especially not things real enterprise gear tends to optimize for.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#386

Cloud managed anything has a giant red target painted on it. Especially infrastructure equipment. I'm still surprised anyone think's it's ok to use their ISP provided router and wifi, let alone having it be managed remotely by the manufacturer.

The problem is that on-prem isn't much better in many cases. Only the largest organizations have the capability to operate deep defenses against these threats whether it's the cloud, or the on-prem. If you and your team have the skills you can operate fairly effectively on a small scale, but that's a pretty luxurious situation. Most home users can't tell the difference between a router and cable modem hence it's in t…

on-prem is much better in most cases because if there is a bug an attacker would have to scan the internet and find you before a patch is released and you update. If that bug is only accessible from inside of your network to begin with, then that means the attacker would already have to be inside your network.

As far as the team having skills, there is not much that ubiquity does that can't be handled on prem, I mean you're already installing physical devices, how much more effort is it to install a controller? Sure, that means you're on the hook for upgrades, but in most cases you're better off not getting them instantly anyway.

And to clarify my point about ISP gear, I agree that the average user can't be expected to understand or care. I meant so called technical users.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#387
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

I hear Cardi B and Megan Thee Stallion have some pretty excellent WAP's.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#388
post #379

Earlier quoted context omitted.

As a former enthusiast in this area, I need the time for other more pressing interests and have reverted my home network to Eeros pinned to an IQrouter. All of them require some central service to operate, and I rarely if ever have to pay any attention to them. They also provide better coverage and less radio interference than the prior gold standard, Apple Airport devices. The IQ runs some sort of ssh *nix variant a…

Do they make an Eero yet with more than two Ethernet ports? I love the product, I just want to plug 4-5 devices in as well as use the WiFi.

You can buy a 5-port unmanaged switch for roughly $30, just FYI.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#389

Earlier quoted context omitted.

Are you concerned that TP-Link is a Chinese company? Could your data be exfiltrated back to China?

As a US citizen, I would love for there to be a reasonably-priced US-made alternative. I guess Netgear could be one[0], but their Insight management system is cloud-only, isn't it? Happy to be corrected. I think I'd rather take an ostensibly-offline controller from China than a cloud-enabled one from the US, though I'm not really happy with those options. :-( Are there some good options I missed? Would like to hear a…

Seems like an opportunity for router software with great UI and management on linux or pi to excel. then run it on anything.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#390

Earlier quoted context omitted.

I worked at Ubiquiti while you were there. I can confirm that the company was going downhill fast. The US offices were starting to feel empty because so many people were leaving the company. Only place I've ever worked where engineers would quit before they got another job. Saddest part was all the wasted potential. There were good engineers making good products at Ubiquiti only a few years ago. Once UniFi exploded i…

It's unfortunate what seems to have happened to Ubiquiti. The idea of decent network hardware with a good UI that can support the prosumer to small business segment of the market has a lot going for it. In the early days, it seemed like Ubiquiti was going to nail it and was building up a strong, loyal following as a result. Then came all the reports of quality problems, promised features never delivered, phoning-home…

I think the brand isn’t toxic because of the state of the competition.

Even with this hack, their stuff is still the best available for home use. Netgear or Linksys consumer routers are awful. The mesh devices are okay, but serve of a different market.

The other stuff people recommend is often 2-3x the Unifi price and 2-3x more complicated to setup and configure.

Any ex-employees want to start a company making this stuff that doesn’t suck?

Post reply on HN