Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

771–780 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#771

I wonder how difficult it would be to implement a rudimentary controller for their APs. The WLAN configurations are just text files in the /etc directory. Getting feature parity would be a lot of work, but I bet the bar isn't too high for simple functionality. Most of the "magic" is happening in hostapd on the APs anyway.

I think you are wrong. I have been working on https://openwisp.org for some time and implementing a controller which is robust and can handle many different corner cases and offer good functionality and also ease of use is a challenge and requires several people working full time on it. Even simple functionality it's a lot of work, unless for simple you mean really trivial. If it wasn't hard, there would be many alternatives but as far as I know there aren't many.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#772

Earlier quoted context omitted.

Check the Openwrt table of hardware[0] for a well supported device, and you're good to go. Seriously, there is no good vendor software in this space, but the consumer hardware can actually work fine with better firmware. Generic Linux or BSD boxes are ok as routers, but they're not the best switches since they start taking up a lot of space if you need a bunch of NICs. [0] https://openwrt.org/toh/start

Is there a filtered version of that list with hardware that you can currently buy (new)? Or ratings of which current hardware is great for OpenWRT?

Yes! https://openwrt.org/toh/views/toh_available_16128

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#773
post #183

Earlier quoted context omitted.

Are you concerned that TP-Link is a Chinese company? Could your data be exfiltrated back to China?

edit: Oops, disregard, I've violated HN hivemind statutes, despite being completely factually correct! What I meant to say is that US law enforcement, and in particular the FBI, are 100% perfect in every way. Nobody has EVER used lawful request overreach to ruin the lives of innocent people. Praise be to J. Edgar Hoover!

What you did here was vandalism. Please don't make rage edits on HN.

Please do review https://news.ycombinator.com/newsguidelines.html and stick to the rules when commenting, regardless of how wrong other commenters are or you feel they are.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#774

I wonder how difficult it would be to implement a rudimentary controller for their APs. The WLAN configurations are just text files in the /etc directory. Getting feature parity would be a lot of work, but I bet the bar isn't too high for simple functionality. Most of the "magic" is happening in hostapd on the APs anyway.

I think you are wrong. I have been working on https://openwisp.org for some time and implementing a controller which is robust and can handle many different corner cases and offer good functionality and also ease of use is a challenge and requires several people working full time on it. Even simple functionality it's a lot of work, unless for simple you mean really trivial. If it wasn't hard, there would be many alte…

I was definitely shooting my mouth off to some extent. I'd defer to your experience for sure. I took a look at your project pages briefly and I'm going to spend more time looking them later. It definitely looks neat, and much more "feature-ful" than I'd be looking for. I'm particularly interested in looking at your modular configuration system.

My needs definitely don't exercise corner cases. Most of the UniFi gear I've got out there is just running a single SSID w/ WPA-RADIUS and a RADIUS-assigned VLAN. Here or there I've got an SSID w/ a PSK and a hard-set VLAN. Nothing too fancy. Adopting new APs quickly and easily based on a "magic" DNS name, alerting when an AP disappears, and syslog to show association/roaming/disassociation events is about all I want. I'm putting Customer-owned gear in small offices w/ under 10 APs, rather than being a service provider.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#775
post #698
post #628

Earlier quoted context omitted.

I worked for a pharma co for a while, they did have a social media listening department in marketing, also we were trained to report any discussion of the company at all to a special investigations unit that would follow up.

As someone who works in pharma currently, I have seen the same. The pharmacovigilance unit does search the internet/social media for AE's, off-label use, etc (depending on region). Secondly every single person in the company also needs to report events when they see/hear/read them. So not having that social-media department wouldn't be doing much, not all thousands of employees can/will/want to avoid social media.

Thanks. I can well believe my experience (ca. 2014) is a little outdated. I would imagine they is still quite difficult to sell social listening into as a sector, but it makes sense that eventually you have to take your head out of the sand.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#776
post #770

Earlier quoted context omitted.

I’m not conflating anything. Check your facts. “ Way back in 2004, Cisco wrote an IETF proposal for a “lawful intercept” backdoor for routers, which law enforcement could use to remotely log in to routers. Years later, in 2010, an IBM security researcher showed how this protocol could be abused by malicious attackers to take over Cisco IOS routers, which are typically sold to ISPs and other large enterprises.” https:…

[flagged]

Nowhere is it said this was mandated. That’s your assumption not supported by evidence.

So let’s run through it. Cisco writes white paper supporting LE back door access. LE/IC use hard coded back doors as revealed in the Snowden and Vault7 leaks. You’re saying it never happened, ever. Maybe you’re right (you’re not) but you spoke so firmly! Do you know something I don’t?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#777
post #110

Earlier quoted context omitted.

So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…

I use a small, passively cooled x86 box with 6 1GbE ports that I found on AliExpress. Wrote about it here: https://www.reddit.com/r/homelab/comments/hzvfih/new_router_... It's got a quad-core i5. I run Proxmox and virtualize VyOS as a router, Home assistant, and a couple of other small things like an https reverse proxy for various services that I like to access remotely. Went this route after my old OpenWRT router c…

Does this type of setup support a mesh network with multiple APs and SSIDs, VLANs, etc? I have never seen a PC based all-in-one interface that supports all of these things the way Unifi does...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#778
post #110

Earlier quoted context omitted.

So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…

I can't imagine that there isn't a market for this. Look at the number of people recommending Ubiquiti stuff to each other. There are entire YouTube channels dedicated to it. If your whole living space or small office can be covered with a single access point, get a 3-in-1 combo that has a WAP, a router, and a small switch. But if you don't, you are left with, what exactly? There is also some demand for mesh stuff, f…

How are you going to centrally manage the meshing and transition between APs?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#779

At least for home networking, I'll always pick something I can throw OpenWRT on over a managed service, subscription or closed-source option. In the 15 years I've been using OpenWRT, I have never been disappointed with it, and I don't have to worry about some company's "secure" backdoor into my network being exploited.

I’d like to know what you recommend. I’m running asus routers at home, but would like an option that’s easier to upgrade.

Mikrotik hardware if you're looking for hardware you can upgrade.

I haven't found the need to upgrade my hardware in a couple of years so I don't know what the market currently looks like. I'd just look on the OpenWRT wiki or forum and see what is best supported and buy that.

Also, Atheros radios are generally supported really well on Linux, so I stick with hardware that has an Atheros chipset over something with a Broadcom radio.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#780
post #296

Earlier quoted context omitted.

Why is it so easy to snatch defeat from the jaws of victory in tech?

Greed. 100% greed. While I was there, the CEO loved to just fly between offices (randomly) on his private jet. You never knew where he'd pop up, and that put everybody on edge, because when he was unhappy he tended to fire people in large chunks (and shut down entire offices). Every decision was motivated by how it affected the stock price.

I'd say stupidity first, greed second. There are a lot of private companies making a lot of money. Valve and Ikea come to mind.

Being private and successful is hard to achieve in the Capitalistic world we live in, when you achieve it stick to it.

Post reply on HN