Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

541–550 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#541
post #509

> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed” Perversely, this is exactly the logging that you want to have in place in case of a breach. You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”

Can you provide more information regarding a system that can log these types of breaches (and all other activity, as required) and that would be deemed "safe" and reliable post-breach? i.e.: A system that can provide logging and that can *assert* that all logs, even in the event of a breach, are asserted CIA?

AWS offers object locking, which is similar to a WORM drive (Write Once Read Many). This prevents logs from being deleted. The other approach is to ship logs to another AWS account.

https://aws.amazon.com/blogs/storage/protecting-data-with-am...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#542
> Ubiquiti’s stock price has grown remarkably since the company’s breach disclosure Jan. 16. After a brief dip following the news, Ubiquiti’s shares have surged from $243 on Jan. 13 to $370 as of today. By market close Tuesday, UI had slipped to $349.

Until these companies are held massively accountable for such negligence, nothing will change. Similar to what happened to Facebook and all they had to do was pay chump change fines.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#543

Earlier quoted context omitted.

It’s not _that_ unbounded? At least not yet! Until a tech savvy neighbor who’s also a creep can easily break into your network and home camera I’m not personally worried.

Why does it have to be a neighbor? It says "internet" on the tin. Do you have confidence that random people on the internet can't do the equivalent of a port-scan on you? The other way I think of it is, I don't use it right now. It likely has open doors, intentional or unintentional. If the open doors are widely discovered, reliably closing them seems difficult. The highest-leverage point in time to influence this st…

The question is what incentive a random person in the internet has into finding and targeting me. I’m a single dude who’s not rich, and I’m not gullible to scams (at least not easily). So unless they have a personal grudge against me, I would probably not be currently worried about installing a doorbell camera for example. The threat modeling will Change the moment I have a family of course.

I see it no different from driving a car. You can get carjacked, you can get in a crash, you don’t just not drive a car because of it, you just calculate your risk tolerance and do it.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#544

Earlier quoted context omitted.

What data would they even want? My WiFi password? My PPPoE password? All my https packets?

Do you work from home? Does your company have any valuable intellectual property?

What's the specific mechanism of data capture you would be worried about?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#545
post #470

Earlier quoted context omitted.

I can vouch for Google WiFi. Very simple to set up.

If you give away your data, it can't be stolen. That's fool-proof security!

Ha I get it. The way I look at it is, I have chosen my security sin and that's Google. I turn off ad settings, pay for GSuite, YT premium and Google one, have ad block/ad guard everywhere and buy their nest home products.

Smaller threat area, much larger utility plus they by default have more resources than any other company to have better security.

Don't get me wrong, I was looking forward to moving to ubiquity but that's not happening anymore unfortunately.

As far as I'm aware Google has not had this magnitude of hack recently.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#546
I was looking at upgrading my home networking equipment with Ubiquiti, but with the breach and the hidden advertisements in their products. I have ultimately decided against it. They have lost $1000s of dollars in potential sales (from me anyways).

Guess I will just have to go bargain hunting on the used enterprise market, or just ask my BigCorp networking team to see if they sell or give away any of their equipment and try to repair it myself. My only concern would be noise generation and power consumption since they were built for use in data centers.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#547

Earlier quoted context omitted.

What is the right way store credentials to something like this? Hardware keys?

For AWS root account? Generate a long random password, print it out and then lock it in a safe without allowing anyone to see it. Turn on 2FA and then lock the second factor in a different safe. There’s virtually never a need for the root account and it’s impossible to attenuate (by design).

Printing out the AWS root password and putting in a safe is almost useless. Root password can be easily reset without MFA by having access to the email associated to the root AWS account.

MFA is the important one to keep it safe for AWS root accounts, set for the master AWS account and lock root access for all member accounts via SCPs.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#548

Earlier quoted context omitted.

So SSO is disabled here. You just use a local account. IE, I go to https://192.168.27.1 to get to my UDMP and the account to auth is locally stored.

Hmm, I followed your steps and my ui.com account can still log into the device. I have also created a local account, that I can use to log in alongside my ui.com one, but I cannot disable my ui.com SSO from being able to sign into the device.

Let's make sure we are talking about the same thing.

You have local and SSO account.

You disable remote access in your local cloud key.

You open the local IP for the CK and are able to sign in using the SSO account is what you are saying, so auth token is coming from remote.

Question if I got this correct, can you go to the ui.com portal, the UI cloud based one in a web browser do you see the controller still? Can you login and still manage it through the remote web portal? This is what turning off remote access does. You should not be able to manage the system remotely.

Disabling remote access is for the remote web base ui site portal and that should not work after you disable remote access (my understanding). It is possible that you can connect to the local controller and use SSO to authorize vs web and be passed a valid token to login however that would be local only and not remote. Ie the hacker would have to have your SSO AND be on your local network.

Have you tired / are you able to delete the SSO account in the local CK? I have not tried but will later.

Hope that makes sense.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#549
post #296

Earlier quoted context omitted.

Why is it so easy to snatch defeat from the jaws of victory in tech?

Greed. 100% greed. While I was there, the CEO loved to just fly between offices (randomly) on his private jet. You never knew where he'd pop up, and that put everybody on edge, because when he was unhappy he tended to fire people in large chunks (and shut down entire offices). Every decision was motivated by how it affected the stock price.

At least a handful of Glassdoor reviews verify this sort of micromanagement. How awful and what an asshole.

That's a company that needs to be re-worked from the top. All C-level management fired, no golden parachute.

edit: Robert Pera owns 75% of the company, looks like C-level mgmt will never get fired. If you are at this company, just leave.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#550

Earlier quoted context omitted.

I think the brand isn’t toxic because of the state of the competition. Even with this hack, their stuff is still the best available for home use. Netgear or Linksys consumer routers are awful. The mesh devices are okay, but serve of a different market. The other stuff people recommend is often 2-3x the Unifi price and 2-3x more complicated to setup and configure. Any ex-employees want to start a company making this s…

The other stuff people recommend is often 2-3x the Unifi price and 2-3x more complicated to setup and configure. I don't know about 2-3x the price, at least not here in the UK. We looked into this when fitting out a new office with the networking essentials a couple of years ago, and Ubiquiti wasn't particularly attractive on headline prices compared to the other typical brands that get mentioned in that space (Mikro…

The prices we are comparing against are Meraki, Aruba, Ruckus, etc. I would be shocked if Ubiquiti was similar in price to those even in the UK.
Post reply on HN