Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

791–800 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#791

Earlier quoted context omitted.

Disclaimer: worked for Meraki (now Cisco Meraki) for several years. Generally, halfway decent wireless APs are all targeted at the enterprise market. Consumer hardware is a brutal race to the bottom, as lay consumers aren't qualified to compare options based on anything but price and UI. Ubiquiti was an outlier in trying to bring enterprise features to the consumer market The problem for enthusiasts and small busines…

> Note, however, that roaming between APs is a feature of the 802.11 standard; In theory yes, but man do a lot of devices have terrible roaming heuristics. "I can still see beacons so id better stay here even though i havent received a packet in the last minute. Wouldnt want to pay the time cost of associating with that other BSS that has 5X the signal"

> In theory yes, but man do a lot of devices have terrible roaming heuristics.

i hear this a lot but never experienced it myself, maybe related to outdated os?

been running multi-ap with same ssid/key no special sauce for years and it just works.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#792
post #609

Earlier quoted context omitted.

I use a small, passively cooled x86 box with 6 1GbE ports that I found on AliExpress. Wrote about it here: https://www.reddit.com/r/homelab/comments/hzvfih/new_router_... It's got a quad-core i5. I run Proxmox and virtualize VyOS as a router, Home assistant, and a couple of other small things like an https reverse proxy for various services that I like to access remotely. Went this route after my old OpenWRT router c…

I recommend PC Engines if you want something with a bit more support: https://pcengines.ch/apu2.htm They’re small passively cooled embedded x86 machines. They haven’t made the jump to 10GBit, and their newest model (the apu2) is getting pretty old. However, they have very long production timeframes (many years) for each board config, which leads to stability over time.

as you said, it's an embedded solution, and it's cpu power is borderline for gige speeds, if you want more than the bare minimum (fw/nat) like qos, dpi or some virtualized services.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#793

Earlier quoted context omitted.

Do you know if you can opt out of the cloud connection on the OC-200?

If you login to the OC200, it's under settings > cloud access. It should be off by default. Or you can login to the cloud interface and forget the OC200 under actions.

Thanks!

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#794
post #770

Earlier quoted context omitted.

[flagged]

Nowhere is it said this was mandated. That’s your assumption not supported by evidence. So let’s run through it. Cisco writes white paper supporting LE back door access. LE/IC use hard coded back doors as revealed in the Snowden and Vault7 leaks. You’re saying it never happened, ever. Maybe you’re right (you’re not) but you spoke so firmly! Do you know something I don’t?

[flagged]

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#795

Earlier quoted context omitted.

No, you do not need one for unleashed.

Good to know, thanks. I had bunch of Ruckus Zoneflex APs that I could not upgrade w/o contract.

if it's a model that supports Unleashed, you can also convert them to the Unleashed firmware without a contract.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#796

Earlier quoted context omitted.

Disclaimer: worked for Meraki (now Cisco Meraki) for several years. Generally, halfway decent wireless APs are all targeted at the enterprise market. Consumer hardware is a brutal race to the bottom, as lay consumers aren't qualified to compare options based on anything but price and UI. Ubiquiti was an outlier in trying to bring enterprise features to the consumer market The problem for enthusiasts and small busines…

> having a trustworthy and secured backend. Ubiquiti had a secured backend - their screw-up was not doing MFA on their admin accounts. I would still like if there was an option for a local-only control panel.

Same here. I don’t need remote access to manage my network. I work from home and spend a majority of my time there.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#797

Earlier quoted context omitted.

I mean, if the password manager’s store is compromised, then sure, okay. But if only the application password is compromised then it’s still 2FA since the attacker cannot authenticate with just the password.

I see what you're saying, but I disagree. The F in 2FA is factor. Satisfying one login request from one factor (password vault) is 1FA. This is why the second factor is normally something that isn't your password vault (historically your head, now a piece of software): a hardware key, a recovery code, etc. A slightly more generous interpretation is 1.49A (rounds down), because someone with a reused username/password…

And the A in 2FA is authentication, not storage. The password vault is not a factor because it is not what is provided for authentication, the individual password is the factor. The fact that the vault being compromised reveals both factors does not make it no longer 2FA.

Colocating the storage factors definitely makes certain attack vectors possible that aren’t otherwise possible, but it’s still 2FA. Are hardware keys best? Likely, but still many probably have their password vault and TOTP application and storage on the same device (e.g. both Bitwarden and Authy on their mobile device) which is a middle-ground convenience vs. security between TOTP in the password vault and hardware keys—but I doubt many would say that it’s not 2FA.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#798

Earlier quoted context omitted.

i've got one of those, and another mikrotik 10gb switch. whatever the 16 port one is. they've been working nicely. i have good luck with fiber SFP+ modules, but it seems picky about 1G copper SFP modules, fwiw.

really i ordered cisco ones do those work?

like actual cisco-brand ones, or cisco compatible ones?

i checked my order history, it looks like ipolex and 10gtk 1000bT copper modules have had troubles in my mikrotik switches. the mikrotik brand works fine. and every 10G fiber module i've tried has worked (lots of fs.com, and i think 10gtek, and probably some other brand off amazon)

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#799

Earlier quoted context omitted.

@c0nsumer My earlier comment was based on a change of policy which happened around 1st March, and any Unleashed quotes as of 1st March (and the two-weeks prior) need to be re-quoted for the new "license per AP" Unleashed model. I've been a bit busy with other work since that bombshell dropped, but if I get a moment I'll try to dig up some pricing. The other thing to note is feature discrepancy between Unleashed and s…

Thanks! I completely glossed over the IPv6 thing... At home I don't get native IPv6 from my ISP, so I just tend to forget about that. Although it would be neat. For me I bought my AP on eBay and just plopped the standalone Unleashed firmware on it and that's all seemed fine. In what I see there's nothing changing? But it sounds like you're running a /much/ larger install.

@c0nsumer

Without going into detail because, well, you never know who's reading ....

TL;DR "WatchDog End User Support" is now mandatory for Unleashed and is sold and priced on a per AP per year basis.

The pricing is not too scary (two digit figure per AP per year). But I'm told the requirement is (will be ?) enforced so its unlikely to be a case of being sneaky and paying the first year and "forgetting" to pay the renewal.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#800
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Check out pepwave, I have a couple of their APs with no cloud management involved. I think there are probably roaming features...
Post reply on HN