Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

641–650 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#641
post #506

Earlier quoted context omitted.

I have never ever seen "plausible deniability" keep someone out of trouble. I have seen attempts at applying it several times, but never successfully. As an excuse for why to not do the right thing I really hate "plausible deniability".

Under GDPR, a failure to know about (detect) a breach (and then report it yourself) is in itself a violation. Likewise, failing to have suitable organisational and technical measures in place to protect the data is a breach. I'd certainly argue your inability to account for processing operations after having been breached through lacking knowledge of what was done due to a lack of logs was therefore a breach.

[deleted]

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#642
post #633

Earlier quoted context omitted.

After the Unifi Video fiasco, I bought a UDM Pro to test Unifi Protect. Once I saw it required cloud login I got scared. After I saw an ubiquiti ssh key preinstalled in a device with unfeteted internet access I shut it down to never bring it up again

All of this makes me skeptical about ubnt but a few corrections 1) You dont need to turn on cloud acccess 2) My UDM pro doesn't have ssh open to the world so not sure how that would be useful externally

There was no option to bypass cloud login when it got to my hands, apparently that has been "fixed" with some update, but if you buy a device and it comes with an outdated firmware, as it tends to be the case with their cameras and APs, your only choice is activate on cloud, setup, update, factory reset, setup on local.

About 2... I guess when you got access to all their source and infra is just a matter of pushing an update to enable ssh and they don't even need to even push a key. My problem with the keys is that they come bundled with it and you don't know it. There's no reason for them to install a key in there without your consent. Imagine Microsoft presetting an Administrator account on every Windows Server without telling anyone... It's just a security problem, even more in a firewall

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#643
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

>If this is true, and whoever breached them had full access to their AWS account, can we really trust them to clean up all their tokens and fully eradicate all forms of persistence the hackers may have gotten?

This is the same for any breach. At least if you're using AWS, you know that your management tools aren't lying to you (as long as you assume AWS itself isn't hacked) and you can use those tools to cleanup. If you run your own machines, you can't assume your management tools work correctly. All your machines could have rootkits, all your tools could contain backdoors, and every attempt to cleanup might just be a fake veneer. See Reflections on Trusting Trust.

Full disclosure I work for a cloud computing company (but not AWS).

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#644

Earlier quoted context omitted.

OK, with tongue firmly in cheek, I will try to reply to your points from the perspective of the small organisations I was talking about. But with a cloud-managed system you have a professional, single-purpose organization dealing with those challenges. Just to be clear, are you thinking of the professional, single-purpose organization we've been discussing today in the context of a catastrophic data breach, the one w…

> What cash? When we have a new starter, John or Bob sets up the WiFi on their laptop and company phone and adds those MAC addresses to the whitelist for the network. Normally John works in development and Bob works in sales, but they do know a bit about networks so this is fine. Well, as long as they can get to the GUI, anyway. "Small businesses whose core competence is software/networking, or who by coincidence hav…

You have that expertise in house. Having looked at sales numbers and market research for a company that sold internationally and cross-industry: yes, your experience is very unrepresentative.

OK, let's assume that's true for the sake of discussion. According to your market research and sales numbers, what is the big market for these cloud-managed products among smaller organisations, and how do those organisations generally manage their IT facilities?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#645
post #296

Earlier quoted context omitted.

Why is it so easy to snatch defeat from the jaws of victory in tech?

Greed. 100% greed. While I was there, the CEO loved to just fly between offices (randomly) on his private jet. You never knew where he'd pop up, and that put everybody on edge, because when he was unhappy he tended to fire people in large chunks (and shut down entire offices). Every decision was motivated by how it affected the stock price.

I'm just an outsider looking in based on a short paragraph, but that doesn't strike me as greed. How does firing entire batches of people help the stock price? Anyone with more business acumen than a cat will understand that it doesn't. "Oh, that office made a mistake? Let's fire the lot of them so they'll learn how to do better next time!"

Based on this, it seems more like an asshole with some attitude problems rather than greed per se.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#646

Earlier quoted context omitted.

This boggles me when I see this option in any password manager (and I think every single one has this 'option'). Why do password managers let people store TOTP next to the password, this completely invalidates the 2FA of TOTP if your password manager get broken into.

> this completely invalidates the 2FA of TOTP if your password manager get broken into I think that's the big "if". If you assume the password manager is secure (which something clearly wasn't in this case, but that seems like an outlier), TOTP secret in the password manager still secures the account. Is such a setup as protective as a separate storage method? No, but it's leagues more convenient. A cloud-based PW ma…

You know what's also convenient? 1FA.

Which, incidentally, when you store you TOTP secrets with your passwords, is what you have.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#647
post #438

Earlier quoted context omitted.

So what, you are suggesting a strategy of staying away from large services and hoping that you won't be targeted? I posit that it doesn't take burning a zero day, or a coordinated effort by the CIA, the FSB, and Randy Waterhouse to break the typical DIY self-hosted security implementation. (And that the manager paying someone to build it has no ability to tell between a great , a good and a bad DIY job.)

A network controller for local WiFi shouldn’t be reachable from the Internet at all. I’ll take a vulnerability ridden controller on an isolated management VLAN over cloud shit any day.

But if you have multiple sites you need to reach it remotely. Maybe over vpn but still remotely.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#648
post #565
post #246

Earlier quoted context omitted.

"It is even worse: Ubiquiti forced all users to use cloud-based authentification even for accessing your controller software on a local network with a local client. This was not even properly communicated but deployed by one of the regular maintenance updates." Uh? that is demonstrably not true. Any more details?

No opinion myself, but someone did mention something to this effect in a different thread: https://news.ycombinator.com/item?id=26638671

Thread only seems to handle about the cloud key, which is hardly everyone. I self-host and don't have the issue.

But shady as f*ck and kind of sets the tone.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#649
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Complete failure of security here. No single credentials should be able to grant that much privileged access.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#650

Earlier quoted context omitted.

> My guess is their local workstation was compromised You mean someone was physically at the laptop/desktop and could access the OS and apps? Maybe if the employee was working remote (covid?) from, say, a cafe and left the laptop unattended when refilling coffee? Or something else? ... Hmm, could also have been eg a browser zero day that gave someone remote access to the computer? Or a dev tools supply chain attack?

It's not that complicated. The local workstation could have had a trojan or virus that installed a keylogger or screengrabber.

Or someone watched over their shoulder. 1Password makes it all too easy to accidentally reveal your password within the app. Someone with a video camera just needs one clear frame - 1/60th of a second - with a good enough view.
Post reply on HN