Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

591–600 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#591

> the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee The interesting part of this story is how the employee's LastPass got popped. My guess is their local workstation was compromised, and their LastPass was either not logged out in a browser plugin, or they didn't have 2 factor auth required for each login and a keylogger got the password…

> My guess is their local workstation was compromised Honestly I don't think it was even that complicated, considering when I needed to spend money on some SaaS product the "chief accountant" (because there was no CFO) straight up sent me a photo of the corporate credit card and said "delete that when you're done".

Sure, but to be fair, credit cards really aren't that dangerous of a credential to wave around. You can cancel your card at anytime, and even dispute the charges. Its like instant key rotation, with a way to also roll back time.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#592
post #569

Earlier quoted context omitted.

For their UniFi line, at least, you don't have to use their cloud controller. You can self-host.

Yes. I run the controller on a raspberry pi 4. Local only. I too am disappointed in UniFi’s direction. I used to recommend them. I don’t now.

What do you use/recommend now?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#593

Earlier quoted context omitted.

Disclaimer: worked for Meraki (now Cisco Meraki) for several years. Generally, halfway decent wireless APs are all targeted at the enterprise market. Consumer hardware is a brutal race to the bottom, as lay consumers aren't qualified to compare options based on anything but price and UI. Ubiquiti was an outlier in trying to bring enterprise features to the consumer market The problem for enthusiasts and small busines…

> having a trustworthy and secured backend. Ubiquiti had a secured backend - their screw-up was not doing MFA on their admin accounts. I would still like if there was an option for a local-only control panel.

I run a local controller with no remote access for unifi - i would never use any networking hardware that needed a cloud controller/connection for breaches exactly like this.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#594

Earlier quoted context omitted.

Yep, I have my controller running on a Synology 720+ NAS that has zero ‘wide area network’ access. Everything is local to my home. I am deeply saddened by Ubiquiti’s fall from grace... they were so good.

Can you go into more detail about your setup? I have 920+ and am in the market for a new router (controller? Still learning the terminology).

I have a UDMpro which self-hosts a controller, thou personally if i knew it couldn't be joined to another controller i'd have gotten something else so i could throw it in docker (which runs on a NUC with the storage off a synology)

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#595

> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed” Perversely, this is exactly the logging that you want to have in place in case of a breach. You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”

Ubiquiti's response is not surprising. Of course they would lie and deflect about the severity of the attack. They have terrible customer support and awful software update communications; besides, they are hostile to analysts and the press. Either Ubiquiti made false material statements, or the company is negligent. In both cases, it will get them into hot water.

In Ubiquiti's defense, I once brought a disclosure to their attention on Twitter a few years back and they very swiftly issued an update. I guess things have gone downhill since then. It boggles the mind why a company whose core business is catering to the self-hosting crowd, would try to force self-hosters onto its cloud plantation, when it can't even protect its own house.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#596
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

> Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Isn't one of the major selling points of cloud-everything "How can you possibly secure your service better than BigRespectableCompany?" I know any time I bring up self-hosting E-mail or a web site or whatever, someone always comes out of the woodwork to remind me that I am not an expert in securing Internet services, and tha…

Managed services with state of the art IAM policies are more secure than lifting and shifting a Linux box running whatever PAM configuring was setup on it in 2005.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#597
post #320

Don’t have time to dig into this right now, but I have a Ubiquiti WiFi AP at my home behind a NAT; does this breach mean my home network is vulnerable/effectively exposed to the Internet? Do I need to log off HN and deal with this now, or can it wait?

It depends. How do you manage said AP? The leaked credentials issue here is specifically in SSO Cloud authentication to Controllers, which are used to administer all the actual hardware devices. However, the devices themselves aren't affected. So depending on how, or for that matter if, you manage them you may be unaffected as well which has always been a major touted advantage of UniFi and has indeed proved true rig…

If they got in this far, what else did they get access to? How long have they had access?

Saying its only a db *that they know of*.

What about the software repositories that they host somewhere?? Did the admin have access to that?

This is pretty major....

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#598

Earlier quoted context omitted.

It’s very easy to say “greed” because we want to believe bad things are always the fault of someone’s personal moral failings. Hopefully the tech community will start to realize that when the same problems keep occurring for the same reasons, it points to a systemic failure.

As in... what, capitalism bad?

> As in... what, capitalism bad?

I think it’s best to be specific.

It’s the C-Suite circle jerk.

My apologies for the language, but throwing away the advantage and further potential of the USA, in the interest of personal wealth and quarterly profits, is even more disgusting.

The majority of America’s management culture is horribly broken.

On the plus(?) side this management culture sometimes allows for easy external disruption.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#600
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

I was under the impression that Omada had a non-cloud configuration?
Post reply on HN