Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

601–610 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#601
post #374
post #291

Earlier quoted context omitted.

I now use the camera in direct rtsp mode. This way it can be used by any rtsp tool including video recording and the lot. For the nursery camera I just use IPCams on iOS on an iPad.

Yep, I also use their cameras as baby monitors. RTSP mode to VLC on an old chromebook as an always-on monitor. The Protect app works pretty well now assuming you have a controller to connect to, but the time between the Video app shutting down and Protect actually working properly was very frustrating. I would never trust the Protect app to stay connected while I'm asleep, though. It's definitely not stable enough fo…

The very first night I got the camera set up was the night that there was a level 3 outage and major internet snafu, making it so that I couldnt actually get into the app to view the camera. RTSP mode sounds pretty good at this point with only one camera.

(Ignoring the fact that Ubiquity marketed these cameras as having a speaker, when, in fact, you cannot send audio to the camera, only that it makes noise on its own)

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#602

> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed” Perversely, this is exactly the logging that you want to have in place in case of a breach. You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”

Reminds me a little bit of Adverse Event Reporting in pharma. If a drug manufacturer finds out about an adverse event (i.e. a bad reaction) to a drug, it kicks off all sorts of obligations that have the potential to be time-consuming and expensive. So pharma is the one sector you won't see with a "social media listening/analysis" department in marketing. They actively avoid tracking or learning about discussion of th…

Sounds like a case of poor incentives. It's easy to wag our fingers and say "well they shouldn't be doing that" but difficult to come up with a system of incentives that makes everyone want to do what's socially beneficial. In this case, it seems like there should be a separate organization in charge of looking for adverse events that is rewarded for finding events (instead of punished). We use some strategies like this currently when regulating the finance industry

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#603
The description of the incident in their quarterly financial statement seems to match this description. It doesn't downplay it quite as much as the email they sent customers.

> For example, in January 2021, we became aware that certain of our information technology systems hosted by a third party cloud provider were improperly accessed and certain of our source code and the credentials used to access the information technology systems themselves had been compromised. We received a threat to publicly release these materials unless we made a payment, which we have not done. As a result, it is possible that the source code and other information could be publicly disclosed or made available to our competitors. Due to the nature of the source code and the other information that we believe was improperly accessed, we at this time do not believe that any public disclosure will have a material adverse effect on our business or operations, but it is impossible to gauge the precise impact of any such disclosure. We have taken, and will continue to take, steps to remediate access controls to our information technology systems.

http://ir.ui.com/sites/default/files/2021-02/ui-10q-12-31-20...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#605

Earlier quoted context omitted.

Are you me? Just finished setting up my Ubiquiti-based home network that includes a dream machine, 6 access-points, and a wireless bridge to an outbuilding. All told about a $1,500 investment I made because I thought I was investing in "best-in-class" hardware and software. Sigh.

Same here. This is just depressing.

I've done the same, with the only difference being that I bought the stuff a few years back. I never enabled cloud management nor remote access though so I think I'm OK for now.

Not buying any more hardware from them though, unless things significantly change.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#606
I looked into Ubiquiti years ago while trying to find a decent access point. Couldn't stand the thought of having to configure stuff "in the cloud" or running the then giant Java based controller locally.

Floundered some with random enterprise access points used off of ebay that either drew too much power or was still buggy (netgear was the worst).

Then I came across Mikrotik. Their hardware and conformance is somewhat dated, but I've never had anything run so stable. Haven't looked back and been going on 4 years now.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#607
post #110

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…

Check the Openwrt table of hardware[0] for a well supported device, and you're good to go. Seriously, there is no good vendor software in this space, but the consumer hardware can actually work fine with better firmware.

Generic Linux or BSD boxes are ok as routers, but they're not the best switches since they start taking up a lot of space if you need a bunch of NICs.

[0] https://openwrt.org/toh/start

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#608
post #110

Earlier quoted context omitted.

So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…

I use a small, passively cooled x86 box with 6 1GbE ports that I found on AliExpress. Wrote about it here: https://www.reddit.com/r/homelab/comments/hzvfih/new_router_... It's got a quad-core i5. I run Proxmox and virtualize VyOS as a router, Home assistant, and a couple of other small things like an https reverse proxy for various services that I like to access remotely. Went this route after my old OpenWRT router c…

Have you looked at DANOS?

I have an ER4 which works for now but plan to go down the custom route once the ER4 is unable to push packets quickly enough. My hope is that VyOS/DANOS is sufficiently stable by then to run as a VM on say a Odroid H2+ replacement (or something similar)

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#609
post #110

Earlier quoted context omitted.

So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…

I use a small, passively cooled x86 box with 6 1GbE ports that I found on AliExpress. Wrote about it here: https://www.reddit.com/r/homelab/comments/hzvfih/new_router_... It's got a quad-core i5. I run Proxmox and virtualize VyOS as a router, Home assistant, and a couple of other small things like an https reverse proxy for various services that I like to access remotely. Went this route after my old OpenWRT router c…

I recommend PC Engines if you want something with a bit more support:

https://pcengines.ch/apu2.htm

They’re small passively cooled embedded x86 machines. They haven’t made the jump to 10GBit, and their newest model (the apu2) is getting pretty old. However, they have very long production timeframes (many years) for each board config, which leads to stability over time.

Post reply on HN