Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

11–20 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#11
post #9
post #6

What I’m curious about is, if I run my own controller on my own hardware, do I need to be concerned about this? I could understand supply chain concerns... I’ve held off updating anything while this plays out. But all these “breach! breach!” stories fail to spell out who is affected and what they need to do.

If the compromise is widespread enough then the attackers might have gained control of the update infrastructure allowing them to push out malicious firmware to your devices.

These blanket statements don’t apply to everyone. It depends which Ubiquiti hardware you own and how you’ve configured it.

For example, I run the UniFi controller on my FreeNAS server. There are no forced updates to it. It doesn’t update unless I update it. The firmware on my APs doesn’t update unless I update them from my controller.

Re: Ubiquiti all but confirms breach response iniquity

#12
So this week, I have gone from having a single little USG and a massive order planned for loads of kit to stopping them automatically updating the firmware and dropping that order. Extremely annoying, but not as annoying as if this had happened in a couple of weeks.

Re: Ubiquiti all but confirms breach response iniquity

#14
post #5

I’m still on board with Uniquiti, tons of equipment and it wouldn’t make sense to switch everything over for small operations. But this is extremely disappointing, they’re definitely moving in a little bit of a different direction then where many of us would hope. More shiny products that increase bottom line is great but many IT officials rely on UniFi as well, I wonder how they’re responding to enterprise customers…

I wonder if you could extract costs of migration from ubiquity with a lawsuit

Re: Ubiquiti all but confirms breach response iniquity

#15

Has anyone looked at Ubiquiti's firmware signing? Would it be possible to patch it to retain the drivers and kernel but replace the configuration layers? Being able to homebrew some config would make the equipment more valuable to us I think.

People have been running OpenWRT on Ubiquiti gear for quite a long time iirc.

[https://openwrt.org/toh/ubiquiti/start]

Re: Ubiquiti all but confirms breach response iniquity

#16
post #11
post #9

Earlier quoted context omitted.

If the compromise is widespread enough then the attackers might have gained control of the update infrastructure allowing them to push out malicious firmware to your devices.

These blanket statements don’t apply to everyone. It depends which Ubiquiti hardware you own and how you’ve configured it. For example, I run the UniFi controller on my FreeNAS server. There are no forced updates to it. It doesn’t update unless I update it. The firmware on my APs doesn’t update unless I update them from my controller.

Agreed. My only gear is an EdgeRouter-4. Unlike the Mikrotik it replaced you have go up, find the latest fw file, download and install (that Mikrotik router wasn't designed to handle 1 Gbps and at the time the next step up cost more than the ER).

Re: Ubiquiti all but confirms breach response iniquity

#17
post #6

What I’m curious about is, if I run my own controller on my own hardware, do I need to be concerned about this? I could understand supply chain concerns... I’ve held off updating anything while this plays out. But all these “breach! breach!” stories fail to spell out who is affected and what they need to do.

If you read the original post, the they noticed a breach when someone put an "unknown" VM on their server infrastructure. The attackers also got signing keys for firmware.

So even if you run a local controller, I see two very serious vectors:

1. The "Ubiquiti account signin" functionality - you probably had it off, but I'd like a confirmation that it doesn't keep a backdoor open anyway.

2. Having a malicious firmware update put on the servers. If it took months for someone to find the vulnerability, who knows how long the servers could push a compromised controller/firmware builds for the hardware.

Re: Ubiquiti all but confirms breach response iniquity

#18
post #11
post #9

Earlier quoted context omitted.

If the compromise is widespread enough then the attackers might have gained control of the update infrastructure allowing them to push out malicious firmware to your devices.

These blanket statements don’t apply to everyone. It depends which Ubiquiti hardware you own and how you’ve configured it. For example, I run the UniFi controller on my FreeNAS server. There are no forced updates to it. It doesn’t update unless I update it. The firmware on my APs doesn’t update unless I update them from my controller.

Unless you're manually verifying the content of your AP firmware updates (which is a bit hard since they're closedsource), I don't understand what you're trying to say.

The firmware could be compromised at the source so your FreeNAS doesn't help at all when you download and apply a compromised firmware update.

Unless you're not updating your APs and keeping them vulnerable in that way :)

Re: Ubiquiti all but confirms breach response iniquity

#19
post #16
post #11

Earlier quoted context omitted.

These blanket statements don’t apply to everyone. It depends which Ubiquiti hardware you own and how you’ve configured it. For example, I run the UniFi controller on my FreeNAS server. There are no forced updates to it. It doesn’t update unless I update it. The firmware on my APs doesn’t update unless I update them from my controller.

Agreed. My only gear is an EdgeRouter-4. Unlike the Mikrotik it replaced you have go up, find the latest fw file, download and install (that Mikrotik router wasn't designed to handle 1 Gbps and at the time the next step up cost more than the ER).

So unless it hits news channels major enough that you hear about it or there is a bug that you isolate to be due to outdated firmware, you probably won't ever patch security issues in your edge (outside-facing) router?

Re: Ubiquiti all but confirms breach response iniquity

#20
post #5

I’m still on board with Uniquiti, tons of equipment and it wouldn’t make sense to switch everything over for small operations. But this is extremely disappointing, they’re definitely moving in a little bit of a different direction then where many of us would hope. More shiny products that increase bottom line is great but many IT officials rely on UniFi as well, I wonder how they’re responding to enterprise customers…

I wonder if you could extract costs of migration from ubiquity with a lawsuit

Sounds like a pain that’s not worth it.
Post reply on HN