Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

521–530 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#521

Earlier quoted context omitted.

For their UniFi line, at least, you don't have to use their cloud controller. You can self-host.

Yep, I have my controller running on a Synology 720+ NAS that has zero ‘wide area network’ access. Everything is local to my home. I am deeply saddened by Ubiquiti’s fall from grace... they were so good.

Can you go into more detail about your setup? I have 920+ and am in the market for a new router (controller? Still learning the terminology).

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#522
post #477

Earlier quoted context omitted.

Out of interest, why wouldn't you host it on something like a raspberry pi? Having your local network depend on an external network makes my old school sysadmin bones tingle for some reason.

The Ubiquiti controller is not needed for general operation, unless you're using a guest hotspot. Otherwise if it's offline you just lose ability to do configuration and it's data/stats logging.

It's also needed if you want to have any control over SSID's such as enabling/disabling on a schedule, bandwidth limiting and so on.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#524

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Eero is amazing. It Just Works. Apple style. Plug it in. Never fuck with it. Rock solid.

[deleted]

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#525

Earlier quoted context omitted.

Eero is amazing. It Just Works. Apple style. Plug it in. Never fuck with it. Rock solid.

They are amazon-owned. I'd be shocked if they weren't collecting and reporting telemetry.

They are.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#526
post #110

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…

OpenWRT. Been using that in my home net for the past 12 years or so, on multiple generations of various hardware.

The latest incarnation on linksys ea8500 is slightly bumpy (seems like a kernel crash), but didn’t get annoying enough yet to hook up the serial console and get into kernel bug hunting, yet.

I have about a dozen VLANS that are distributed between different SSIDs and a few L2 switches for wired; bonjour gateway/filtering for the stuff like AirPrint.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#527

Earlier quoted context omitted.

If admin login is using weak credentials, it is by definition not a secure backend. Password/credential management and mandatory MFA are ALWAYS part of security due diligence for suppliers.

Except if it is awscli creds, then of course there is no MFA.

What do you mean? Awscli supports key tokens from your 2fa device if your access keys are configured to require it

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#529

Earlier quoted context omitted.

If admin login is using weak credentials, it is by definition not a secure backend. Password/credential management and mandatory MFA are ALWAYS part of security due diligence for suppliers.

Except if it is awscli creds, then of course there is no MFA.

This has been a concern for me for a while, but it's possible to use aws cli with mfa by throwing an IdP in front of it.

The work flow we used was AWS Vault -> Okta -> short lived AWS creds.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#530
It's not just incompetency, it's malice, to treat your own customers in this fashion. But this is what happens when there is consistently no consequences for these kinds of breaches. Neither government nor market punishes these kinds of events in any meaningful (cost penalty) way. All the cost is shouldered disproportionately by victims.
Post reply on HN