Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

751–760 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#752
post #194

Should have blown the whistle to the SEC instead. SEC whistleblowers get paid. Up to 30% of eventual penalties paid by the company with no upper limit. Lying about a breach could be securities fraud.

They may already have. Investigation is already pending: https://finance.yahoo.com/news/shareholder-alert-ubiquiti-in...

That's not the SEC, it's just some ambulance-chasing law firm.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#753
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

[deleted]

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#754

This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.

I picked up an EdgeRouter and none of the cloudkey/unifi stuff. I initially felt like maybe I should have picked the unifi gear and maybe a dumb switch, but now I don’t regret the EdgeRouter. Couldn’t be happier with it. I don’t trust anything that tries to solve the “firewall problem” by setting up a cloud service for what should be a local appliance.

I bought the EdgeRouter X a year or two ago because I was tired of having to reboot my router constantly. Still use it, still love it.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#755

It is interesting to do a search of HN for past references to "Ubiquiti". Whenever the topic of routers came up, many comments followed that recommended them above any alternatives. Commenters seemed proud to tell the world they were using Ubiquiti, as if the "HN concensus" for home routers was to choose Ubiquiti. It seemed to me Ubiquiti would never allow customers the option to install their own OS (e.g., BSD) or b…

> It seemed to me Ubiquiti would never allow customers the option to install their own OS I run plain-vanilla Debian on all my Ubiquiti boxes, six or seven of them at this point. debootstrap --arch=mips Octeons are awesome. Ubiquiti hardware is the bomb. I hear their software is junk, but I wouldn't know anything about that, I always erase it right after unboxing the device.

I'd like to hear more about your setup, because I'm tempted to try something similar. How do you actually bootstrap it? How do you configure it? Just a bunch of iptables rules? How do you configure the WiFi? What packages do you install?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#756

Earlier quoted context omitted.

> My guess is their local workstation was compromised You mean someone was physically at the laptop/desktop and could access the OS and apps? Maybe if the employee was working remote (covid?) from, say, a cafe and left the laptop unattended when refilling coffee? Or something else? ... Hmm, could also have been eg a browser zero day that gave someone remote access to the computer? Or a dev tools supply chain attack?

It's not that complicated. The local workstation could have had a trojan or virus that installed a keylogger or screengrabber.

Most password managers protect against keylogging and screenshots.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#757
post #499

Earlier quoted context omitted.

>I heard rumors that the CEO was making two separate teams work [. . .] separately, competing against each other. I don't work in tech, so maybe I'm dumb to this, but why would you ever do this?

Google certainly seems to do this when it comes to chat applications. Ironically though, they've actually (arguably) lost marketshare - they went from gtalk being pretty widely used (in the late 2000s, early 2010s, as Android took off), to having a confused and fragmented ecosystem (Allo, Duo, Hangouts, Chat, Messaging), and it seems none of those have the same market penetration as the original did. Perhaps internal…

They essentially destroyed all competition (AIM, YIM, ICQ, MSN etc), the open source solution that would standardize chat (XMPP) and themselves. Making people just go and use proprietary solution like WhatsUp.

XMPP was so promising.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#760
post #567

Is it just me or are you no longer able to avoid the cloud with the latest software updates for unifi?

Only if you have the newer Cloud Key or Dream Machine. The older Cloud Key isn't fast enough to handle the new OS (which ended up being good in this case, since it's still getting security updates).

> Only if you have the newer Cloud Key

that would explain it then.

Post reply on HN