> the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee The interesting part of this story is how the employee's LastPass got popped. My guess is their local workstation was compromised, and their LastPass was either not logged out in a browser plugin, or they didn't have 2 factor auth required for each login and a keylogger got the password…
> My guess is their local workstation was compromised Honestly I don't think it was even that complicated, considering when I needed to spend money on some SaaS product the "chief accountant" (because there was no CFO) straight up sent me a photo of the corporate credit card and said "delete that when you're done".
Whistleblower: Ubiquiti Breach “Catastrophic”
591–600 of 815 posts
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#592Earlier quoted context omitted.
For their UniFi line, at least, you don't have to use their cloud controller. You can self-host.
Yes. I run the controller on a raspberry pi 4. Local only. I too am disappointed in UniFi’s direction. I used to recommend them. I don’t now.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#593Earlier quoted context omitted.
Disclaimer: worked for Meraki (now Cisco Meraki) for several years. Generally, halfway decent wireless APs are all targeted at the enterprise market. Consumer hardware is a brutal race to the bottom, as lay consumers aren't qualified to compare options based on anything but price and UI. Ubiquiti was an outlier in trying to bring enterprise features to the consumer market The problem for enthusiasts and small busines…
> having a trustworthy and secured backend. Ubiquiti had a secured backend - their screw-up was not doing MFA on their admin accounts. I would still like if there was an option for a local-only control panel.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#594Earlier quoted context omitted.
Yep, I have my controller running on a Synology 720+ NAS that has zero ‘wide area network’ access. Everything is local to my home. I am deeply saddened by Ubiquiti’s fall from grace... they were so good.
Can you go into more detail about your setup? I have 920+ and am in the market for a new router (controller? Still learning the terminology).
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#595> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed” Perversely, this is exactly the logging that you want to have in place in case of a breach. You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”
Ubiquiti's response is not surprising. Of course they would lie and deflect about the severity of the attack. They have terrible customer support and awful software update communications; besides, they are hostile to analysts and the press. Either Ubiquiti made false material statements, or the company is negligent. In both cases, it will get them into hot water.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#596> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
> Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Isn't one of the major selling points of cloud-everything "How can you possibly secure your service better than BigRespectableCompany?" I know any time I bring up self-hosting E-mail or a web site or whatever, someone always comes out of the woodwork to remind me that I am not an expert in securing Internet services, and tha…
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#597Don’t have time to dig into this right now, but I have a Ubiquiti WiFi AP at my home behind a NAT; does this breach mean my home network is vulnerable/effectively exposed to the Internet? Do I need to log off HN and deal with this now, or can it wait?
It depends. How do you manage said AP? The leaked credentials issue here is specifically in SSO Cloud authentication to Controllers, which are used to administer all the actual hardware devices. However, the devices themselves aren't affected. So depending on how, or for that matter if, you manage them you may be unaffected as well which has always been a major touted advantage of UniFi and has indeed proved true rig…
Saying its only a db *that they know of*.
What about the software repositories that they host somewhere?? Did the admin have access to that?
This is pretty major....
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#598Earlier quoted context omitted.
It’s very easy to say “greed” because we want to believe bad things are always the fault of someone’s personal moral failings. Hopefully the tech community will start to realize that when the same problems keep occurring for the same reasons, it points to a systemic failure.
As in... what, capitalism bad?
I think it’s best to be specific.
It’s the C-Suite circle jerk.
My apologies for the language, but throwing away the advantage and further potential of the USA, in the interest of personal wealth and quarterly profits, is even more disgusting.
The majority of America’s management culture is horribly broken.
On the plus(?) side this management culture sometimes allows for easy external disruption.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#599http://www.globenewswire.com/news-release/2021/03/30/2201903...
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#600> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…