Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

481–490 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#481

The plot Thickens: "SHAREHOLDER ALERT: Ubiquiti, Inc. Investigated for Possible Securities Laws Violations by Block & Leviton LLP; Investors Should Contact the Firm" https://finance.yahoo.com/news/shareholder-alert-ubiquiti-in...

This is just class action ambulance chasing. Almost all of these guys are assholes.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#482
post #252
post #175

Earlier quoted context omitted.

I don't know about you, but I "automate the old-fashioned way" at my day job, I want the damned thing to just work without me bothering with "SSH access and CLI tools" at home.

and how many APs do you have at home?

Right now? 1. But that's about to change, that's why I'm reading these comments. I was planning on buying a bunch of Ubiquiti APs.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#483

Earlier quoted context omitted.

> having a trustworthy and secured backend. Ubiquiti had a secured backend - their screw-up was not doing MFA on their admin accounts. I would still like if there was an option for a local-only control panel.

For their UniFi line, at least, you don't have to use their cloud controller. You can self-host.

Yep, I have my controller running on a Synology 720+ NAS that has zero ‘wide area network’ access. Everything is local to my home.

I am deeply saddened by Ubiquiti’s fall from grace... they were so good.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#484
post #458
post #428

Earlier quoted context omitted.

Garbage was a bit of an indulgent word. It certainly is relevant and useful technology. It just isn't useful for home users, at least none that I've ever met.

It is as useful at home as it is anywhere else. Failures just cost less at home. All my switches are bonded to one another, and it was handy when something snapped one of the fiber runs. That side of the house kept connectivity until the weekend when I could crawl around and run a new cable. (Never did figure out why it broke, though. Guessing the house shifted in just the right way.) It would have hardly been the en…

I mean, sure. If you have the capability and the inclination, go for it. I live in a house that is quite large and I can't come close to fully populating a 24 port switch in a useful way.

I would not detract from your network going the extra mile. I suspect that for most people, the value-to-effort ratio of link aggregation just isn't there in a residential setting.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#485

Earlier quoted context omitted.

My personal experience with Meraki has been the very definition of vendor lock-in. The security appliance was relatively cheap, then we saw the fine print that the total bandwidth was artificially limited and increased only adaquetly two product levels up. Sorry Mr BubbleTime, you need to buy a new applicance and a new license. Your old one is worth nothing and non-transferable, watch it rot. The switches seem absurd…

"Cloud-based" is the implementation; the killer feature is the single pane of glass. It's just hard to implement that without putting a bunch of logic in the cloud. Last I worked at Meraki was 2015; I don't remember any artificial limiting of bandwidth at that time.

"Cloud-based" is the implementation; the killer feature is the single pane of glass. It's just hard to implement that without putting a bunch of logic in the cloud.

Hard in what way? As long as the control traffic has paths between all relevant devices over the management LAN, why does the cloud need to be used at all?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#486
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Really glad I decided to go with a TP-Link Omada network over Ubiquiti now.

My TL-R605 router, OC300, HD660s, and 8 port 2.5 gigabit switch are going strong, and I put the whole network together for under $1000.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#487
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

My Synologies do that across several locations in my city. Not sure what PoE is, but Synology has site to site vpn which is amazing !

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#488

Earlier quoted context omitted.

This isn't useful input on where the actual bar is since these are all just conspiracy theories. Who is doing any of this?

I'm not sure what you're calling conspiracy theories since it looks like the GP edited his content, but if you think China is not exfiltrating data from hardware, let me know. I'll provide you with copious references from the recent past. Sure, the US is doing it, too.

I certainly think they do for businesses, but worrying about state actors attacking your home network is kind of pretentious until they actually do it. Are you that special?

The comment was something about how if you get the FBI mad they'll fabricate a drug case against you which somehow involves hacking into your home router or possibly subpoenaing your ISP.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#489

Earlier quoted context omitted.

Yes, roaming by sharing SSID and passcode is a world of pain. 802.11r solves all those pains, I've been using it on OpenWRT for months without a glitch.

how do you enable 802.11r on openwrt? on which model of router

Install the wpad pkg and 802.11r should show up in wireless config screens. See https://forum.openwrt.org/t/802-11r-fast-roaming-in-luci/117...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#490

Earlier quoted context omitted.

It's unfortunate what seems to have happened to Ubiquiti. The idea of decent network hardware with a good UI that can support the prosumer to small business segment of the market has a lot going for it. In the early days, it seemed like Ubiquiti was going to nail it and was building up a strong, loyal following as a result. Then came all the reports of quality problems, promised features never delivered, phoning-home…

I think the brand isn’t toxic because of the state of the competition. Even with this hack, their stuff is still the best available for home use. Netgear or Linksys consumer routers are awful. The mesh devices are okay, but serve of a different market. The other stuff people recommend is often 2-3x the Unifi price and 2-3x more complicated to setup and configure. Any ex-employees want to start a company making this s…

I kept thinking that all the laments about Ubiquiti and others are enterprise-level stuff and are sysadmins' headaches, so was thankful I don't need to worry about it. But more and more I wonder how I managed to choose an Asus 5 GHz router by reviews, bought it secondhand, and now have it chugging along for something like eight years with only some hiccups in summers from heat. With no ‘cloud’ shenanigans.

Also, there are DD-WRT, OpenWRT and such. How comes people don't use those instead of whatever broken software the manufacturer bestows on them?

Post reply on HN