Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

491–500 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#491

Earlier quoted context omitted.

"Cloud-based" is the implementation; the killer feature is the single pane of glass. It's just hard to implement that without putting a bunch of logic in the cloud. Last I worked at Meraki was 2015; I don't remember any artificial limiting of bandwidth at that time.

"Cloud-based" is the implementation; the killer feature is the single pane of glass. It's just hard to implement that without putting a bunch of logic in the cloud. Hard in what way? As long as the control traffic has paths between all relevant devices over the management LAN, why does the cloud need to be used at all?

1. Putting the management UI on a local system requires some custom networking setup, and is full of security footguns.

2. Most customers who want this have multi-site setups; in that case, you need paths across the public internet too. Again security footguns, and also reliability ones.

3. Remote work is very very common for IT people.

4. Recovery from configuration mess-ups is harder if your control plane has to run on the same network that you've messed up.

There are on-site controllers available. They've just lost out in the market because of the amount of in-house IT expertise they require. No one wants to deal with that shit, and outsourcing the security and reliability problems to a specialized third party is usually a good idea.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#492

Earlier quoted context omitted.

Why is it so easy to snatch defeat from the jaws of victory in tech?

It’s very easy to say “greed” because we want to believe bad things are always the fault of someone’s personal moral failings. Hopefully the tech community will start to realize that when the same problems keep occurring for the same reasons, it points to a systemic failure.

Have you worked for ubiquiti too like GP or are you just sprinkling random whatever words?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#493

Earlier quoted context omitted.

I can't imagine that there isn't a market for this. Look at the number of people recommending Ubiquiti stuff to each other. There are entire YouTube channels dedicated to it. If your whole living space or small office can be covered with a single access point, get a 3-in-1 combo that has a WAP, a router, and a small switch. But if you don't, you are left with, what exactly? There is also some demand for mesh stuff, f…

I had a PC Engines board for awhile and I really liked it, but make sure the one you order can support your internet bandwidth. When I upgraded to 1 gig internet, I was pulling around 450mbps on my PC Engines apu1d4. I ended up getting a Ubiquiti Unifi Secure Gateway and then I was able to pull the full 1 gig. It's pretty hard to recommend Unifi based on how they handled this breach, but the hardware itself has perfo…

Looks like the 1d4 used a Realtek network card while their latest boards use Intel which I guess is the recommended brand for pfsense/OPNsense.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#494

Earlier quoted context omitted.

For their UniFi line, at least, you don't have to use their cloud controller. You can self-host.

Is that true on the UDM-Pro? I couldn’t see an option on setup. I might try block it from internet and see what happens.

Yes, this is true. You can access the Unifi controller on the local internal IP.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#495
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Ruckus seems pretty good. You can use their unleashed APs without cloud/controller/subscription. POE, and can connect up to 75 devices. I just installed at my hotel.

We had ubiquiti, but the power outage usually corrupts the controller, and requires constant resetting.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#496

Earlier quoted context omitted.

They are amazon-owned. I'd be shocked if they weren't collecting and reporting telemetry.

Telemetry is an extremely important part of making things just work. There's no other way to find the unknown unknowns.

Lick the boot harder. How did anything work before telemetry? How does tomato/openwrt work so well?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#497

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Aruba sells IAP instant models that do this. No cloud required. (also sell campus controller local no cloud ... but this route is pricey)

Yup IAP with airwave management is a sweet setup...if you can afford it! Even better combined with clearpass and 802.1x

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#498

Earlier quoted context omitted.

Look on ebay for slightly older models. R710, R720 should be $200-$300. Not a replacement at scale, but the one-off purchase from ebay is fine for home use.

Unfortunately, w/o firmware updates they are just little better than a brick. Especially for WIFI hardware where you cannot control who can access it - better keep your APs patched.

Both R710 and R720 are currently supported. I installed an update last week.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#499

Earlier quoted context omitted.

The early days at Ubiquiti were good. I worked with a lot of good engineers and we shipped good work. The decline is a recent problem. > How the brand hasn't become toxic already is a mystery to me, yet look at the stock price tracker. It's been trending up for years and it has well over doubled in the past six months alone. This is your answer. No incentive to change. All of the bad engineering decisions have been r…

>I heard rumors that the CEO was making two separate teams work [. . .] separately, competing against each other. I don't work in tech, so maybe I'm dumb to this, but why would you ever do this?

Google certainly seems to do this when it comes to chat applications. Ironically though, they've actually (arguably) lost marketshare - they went from gtalk being pretty widely used (in the late 2000s, early 2010s, as Android took off), to having a confused and fragmented ecosystem (Allo, Duo, Hangouts, Chat, Messaging), and it seems none of those have the same market penetration as the original did.

Perhaps internal competition to that extent simply confuses customers?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#500
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Man I really wonder why the lack of proper 2FA is so wide spread? Is it rally cost and complexity? Or just missing awareness? Or the lack of consequences when you get hacked in a way which could easily have been prevented (through then they might have attacked in a different way, tbh.).

> Man I really wonder why the lack of proper 2FA is so wide spread?

Because it's a giant PITA unless you have a dedicated team managing it. And the service companies get this and charge accordingly (aka enterprise levels).

It's why companies like 0Auth get bought for gigabucks.

Post reply on HN