Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

461–470 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#461

> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed” Perversely, this is exactly the logging that you want to have in place in case of a breach. You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”

Ubiquiti's response is not surprising. Of course they would lie and deflect about the severity of the attack. They have terrible customer support and awful software update communications; besides, they are hostile to analysts and the press. Either Ubiquiti made false material statements, or the company is negligent. In both cases, it will get them into hot water.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#462

Earlier quoted context omitted.

Are you concerned that TP-Link is a Chinese company? Could your data be exfiltrated back to China?

What data would they even want? My WiFi password? My PPPoE password? All my https packets?

Do you work from home? Does your company have any valuable intellectual property?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#463

Earlier quoted context omitted.

> having a trustworthy and secured backend. Ubiquiti had a secured backend - their screw-up was not doing MFA on their admin accounts. I would still like if there was an option for a local-only control panel.

For their UniFi line, at least, you don't have to use their cloud controller. You can self-host.

This is what I do. I host a controller in AWS on an EC2 instance in my account. It works great.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#464

Earlier quoted context omitted.

Surely 802.11r has a purpose, yes?

Yes, roaming by sharing SSID and passcode is a world of pain. 802.11r solves all those pains, I've been using it on OpenWRT for months without a glitch.

how do you enable 802.11r on openwrt? on which model of router

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#465
post #110

Earlier quoted context omitted.

So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…

? So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. my experience as a professional "network nerd" is that most other people in the networking field run cheap/second hand enterprise gear fetched from their employer at a major discount and simply seem to care less about wifi in g…

The wireless is something for guests, and is hacked together with something you know works with an open router OS, or something off-the-shelf on an isolated VLAN.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#466

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Is pfSense, vyos, stuff like that out of fashion? Or too hard to maintain? Automating that stuff with ansible should solve the central management bit...

Can you run pfsense on an AP or switch or does it only handle gateway/firewall/routing tasks?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#467

What is good cheap consumer gear for putting OpenWRT on? Similar to WRT54G was, back in the day.

T-mobile sold a bunch of rebranded asus routers a couple of years back that are still excellent today and can be had for pretty cheap. Comes with some shitty tmobile spyware I think, but you can flash openwrt on it.

Speed tests are pretty unreliable, but the peak unobstructed wifi speeds I've gotten from that have been better than what I get from my Unifi 6 lite, which supports wifi 6, even on wifi 6 devices. (couple hundred mbps on a home gigabit plan from Nazi Germany I mean Comcast)

EDIT: it's called the T-Mobile AC-1900

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#468
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

For me OpenWRT does that. No cloud.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#469
post #110

Earlier quoted context omitted.

So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…

I can't imagine that there isn't a market for this. Look at the number of people recommending Ubiquiti stuff to each other. There are entire YouTube channels dedicated to it. If your whole living space or small office can be covered with a single access point, get a 3-in-1 combo that has a WAP, a router, and a small switch. But if you don't, you are left with, what exactly? There is also some demand for mesh stuff, f…

I had a PC Engines board for awhile and I really liked it, but make sure the one you order can support your internet bandwidth. When I upgraded to 1 gig internet, I was pulling around 450mbps on my PC Engines apu1d4. I ended up getting a Ubiquiti Unifi Secure Gateway and then I was able to pull the full 1 gig.

It's pretty hard to recommend Unifi based on how they handled this breach, but the hardware itself has performed very well. Hopefully the new PC Engines boards can accommodate your needs.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#470
post #202

Well this absolutely sucks :(. I've been a huge supporter of Ubiquiti ever since I was buying mini their PCI cards and sticking them into soekris engineering boards (ubiquiti started out as a hardware company). The magic thing that absolutely sold me on their equipment was the ease with with you could provision and mesh new gear. Does anybody have anything that compares with that ease of use? To explain what I mean:…

I can vouch for Google WiFi. Very simple to set up.

If you give away your data, it can't be stolen. That's fool-proof security!
Post reply on HN