Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

421–430 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#421
post #76

Earlier quoted context omitted.

These recent posts about Ubiquiti have made me look again at MikroTik. Their hardware is more affordable than I had remembered. Is there any good intro to their hardware - there are certainly a lot more options than you get with Ubiquiti. Even before now there are some limitations with UniFi that have annoyed me. Setting up more complex DNS and firewall rules requires editing the JSON config. IPv6 tunnelling isn’t we…

I use the edgerouter line for firewalls, and unifi (running on a local "cloud key", with cloud login turned off) for only access-points and some switches. This news (covering up, legal overriding good security practices) is super concerning though, and I'm definitely going to start looking around as well.

Yea. I only have an edgerouter 4 as far as Ubiquiti equipment goes. It works great for its intended purpose (I needed a dual WAN router and consumer level gear generally doesn't do that). I was eyeing their WAPs, but I believe I'll pass on them now.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#422
> Ubiquiti’s stock price has grown remarkably since the company’s breach disclosure Jan. 16. After a brief dip following the news, Ubiquiti’s shares have surged from $243 on Jan. 13 to $370 as of today. By market close Tuesday, UI had slipped to $349.

Aaannd this is why we can't have nice things. Like trust in our vendors. Or security. Or consequences.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#423
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

i did the same research 3mo ago. Was torn between a Ubiquiti (mostly because a coworker was bugging me) and a Ruckus Unleashed.

I wish i had gone with the Ruckus.

The lie that you can easily self host your own controller for ubiquiti is vastly exaggerated. Spent several hours of a Saturday patching extremely ancient versions of mongodb and compiling stuff. Not to mention that if you have a VM and turn the controller off, several features of the APs will stop working. and range for their Pro AP is lacking at most.

I wish ubiquiti just published the damn shell commands so i could be able to manage it without the silly troublesome "controller" which is just an annoying web ui. So condescending and inefficient just for the sake of exploiting the customer base for lock-in effect. They are just a little cisco.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#424
By the way, reporting to krebsonsecurity is a giant waste of potential income. This is what the SEC whistleblower program is for. You get paid for submissions there that lead to successful enforcement actions, and the payouts can be very substantial. Furthermore because payouts exist, there's an industry of competent lawyers that will happily take cases with compensation coming exclusively from your payout.

Also, how is this a securities case? The company did not disclose the scale of the breach to shareholders.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#425
post #46

Earlier quoted context omitted.

Parent’s place? Go Eero Pro. Your future time management self will thank you.

I'll take a look at it, but also note that I need in total: Router, Wifi AP (probably two to get full coverage), Powerline extender, Point-to-point extender with a switch on the other end. Stupid outbuildings. Anyway, thanks for the tip!

Decent chance you don’t need all that.

Eero Pro (not standard) kit comes with 3 identical boxes, each with a third radio band for backhaul mesh, each can be wired or wireless as well.

https://evanmccann.net/blog/eero-vs-eero-pro

See comparison table illustration here:

https://evanmccann.net/blog/2021/2/eero-6-vs-eero-6-pro

Not sure if still the case, but last time I dug into it, eero was also the only consumer grade software-defined-radio router/ap, allowing them to rapidly patch for various vulns that others couldn’t necessarily or took much longer for.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#427

> Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies. A root user user breach, seemingly on the organiza…

This boggles me when I see this option in any password manager (and I think every single one has this 'option'). Why do password managers let people store TOTP next to the password, this completely invalidates the 2FA of TOTP if your password manager get broken into.

> Why do password managers let people store TOTP next to the password

One absolutely invaluable use-case is that it lets multiple employees share access to an account with 2FA enabled.

Many systems don’t have appropriate role/permission systems to allow for 2FA otherwise.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#428
post #110

Earlier quoted context omitted.

So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…

When did link aggregation become "fancy corporate garbage"?

Garbage was a bit of an indulgent word. It certainly is relevant and useful technology. It just isn't useful for home users, at least none that I've ever met.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#429
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Aruba sells IAP instant models that do this. No cloud required.

(also sell campus controller local no cloud ... but this route is pricey)

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#430

Earlier quoted context omitted.

Disclaimer: worked for Meraki (now Cisco Meraki) for several years. Generally, halfway decent wireless APs are all targeted at the enterprise market. Consumer hardware is a brutal race to the bottom, as lay consumers aren't qualified to compare options based on anything but price and UI. Ubiquiti was an outlier in trying to bring enterprise features to the consumer market The problem for enthusiasts and small busines…

> having a trustworthy and secured backend. Ubiquiti had a secured backend - their screw-up was not doing MFA on their admin accounts. I would still like if there was an option for a local-only control panel.

For their UniFi line, at least, you don't have to use their cloud controller. You can self-host.
Post reply on HN