Earlier quoted context omitted.
I have never ever seen "plausible deniability" keep someone out of trouble. I have seen attempts at applying it several times, but never successfully. As an excuse for why to not do the right thing I really hate "plausible deniability".
Under GDPR, a failure to know about (detect) a breach (and then report it yourself) is in itself a violation. Likewise, failing to have suitable organisational and technical measures in place to protect the data is a breach. I'd certainly argue your inability to account for processing operations after having been breached through lacking knowledge of what was done due to a lack of logs was therefore a breach.
Whistleblower: Ubiquiti Breach “Catastrophic”
641–650 of 815 posts
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#642Earlier quoted context omitted.
After the Unifi Video fiasco, I bought a UDM Pro to test Unifi Protect. Once I saw it required cloud login I got scared. After I saw an ubiquiti ssh key preinstalled in a device with unfeteted internet access I shut it down to never bring it up again
All of this makes me skeptical about ubnt but a few corrections 1) You dont need to turn on cloud acccess 2) My UDM pro doesn't have ssh open to the world so not sure how that would be useful externally
About 2... I guess when you got access to all their source and infra is just a matter of pushing an update to enable ssh and they don't even need to even push a key. My problem with the keys is that they come bundled with it and you don't know it. There's no reason for them to install a key in there without your consent. Imagine Microsoft presetting an Administrator account on every Windows Server without telling anyone... It's just a security problem, even more in a firewall
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#643> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
This is the same for any breach. At least if you're using AWS, you know that your management tools aren't lying to you (as long as you assume AWS itself isn't hacked) and you can use those tools to cleanup. If you run your own machines, you can't assume your management tools work correctly. All your machines could have rootkits, all your tools could contain backdoors, and every attempt to cleanup might just be a fake veneer. See Reflections on Trusting Trust.
Full disclosure I work for a cloud computing company (but not AWS).
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#644Earlier quoted context omitted.
OK, with tongue firmly in cheek, I will try to reply to your points from the perspective of the small organisations I was talking about. But with a cloud-managed system you have a professional, single-purpose organization dealing with those challenges. Just to be clear, are you thinking of the professional, single-purpose organization we've been discussing today in the context of a catastrophic data breach, the one w…
> What cash? When we have a new starter, John or Bob sets up the WiFi on their laptop and company phone and adds those MAC addresses to the whitelist for the network. Normally John works in development and Bob works in sales, but they do know a bit about networks so this is fine. Well, as long as they can get to the GUI, anyway. "Small businesses whose core competence is software/networking, or who by coincidence hav…
OK, let's assume that's true for the sake of discussion. According to your market research and sales numbers, what is the big market for these cloud-managed products among smaller organisations, and how do those organisations generally manage their IT facilities?
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#645Earlier quoted context omitted.
Why is it so easy to snatch defeat from the jaws of victory in tech?
Greed. 100% greed. While I was there, the CEO loved to just fly between offices (randomly) on his private jet. You never knew where he'd pop up, and that put everybody on edge, because when he was unhappy he tended to fire people in large chunks (and shut down entire offices). Every decision was motivated by how it affected the stock price.
Based on this, it seems more like an asshole with some attitude problems rather than greed per se.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#646Earlier quoted context omitted.
This boggles me when I see this option in any password manager (and I think every single one has this 'option'). Why do password managers let people store TOTP next to the password, this completely invalidates the 2FA of TOTP if your password manager get broken into.
> this completely invalidates the 2FA of TOTP if your password manager get broken into I think that's the big "if". If you assume the password manager is secure (which something clearly wasn't in this case, but that seems like an outlier), TOTP secret in the password manager still secures the account. Is such a setup as protective as a separate storage method? No, but it's leagues more convenient. A cloud-based PW ma…
Which, incidentally, when you store you TOTP secrets with your passwords, is what you have.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#647Earlier quoted context omitted.
So what, you are suggesting a strategy of staying away from large services and hoping that you won't be targeted? I posit that it doesn't take burning a zero day, or a coordinated effort by the CIA, the FSB, and Randy Waterhouse to break the typical DIY self-hosted security implementation. (And that the manager paying someone to build it has no ability to tell between a great , a good and a bad DIY job.)
A network controller for local WiFi shouldn’t be reachable from the Internet at all. I’ll take a vulnerability ridden controller on an isolated management VLAN over cloud shit any day.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#648Earlier quoted context omitted.
"It is even worse: Ubiquiti forced all users to use cloud-based authentification even for accessing your controller software on a local network with a local client. This was not even properly communicated but deployed by one of the regular maintenance updates." Uh? that is demonstrably not true. Any more details?
No opinion myself, but someone did mention something to this effect in a different thread: https://news.ycombinator.com/item?id=26638671
But shady as f*ck and kind of sets the tone.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#649> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#650Earlier quoted context omitted.
> My guess is their local workstation was compromised You mean someone was physically at the laptop/desktop and could access the OS and apps? Maybe if the employee was working remote (covid?) from, say, a cafe and left the laptop unattended when refilling coffee? Or something else? ... Hmm, could also have been eg a browser zero day that gave someone remote access to the computer? Or a dev tools supply chain attack?
It's not that complicated. The local workstation could have had a trojan or virus that installed a keylogger or screengrabber.