Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

21–30 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#21

So, what happens now? Will Ubiquiti be held to task, by anyone?

They’ve lost my business.

Ditto and they have also lost my recommendations. If I hear any friends thinking of Ubiquiti, I will be pointing them towards articles like the one we are discussing. I had been a bit wary of then since their push for cloud SSO etc, but these recent events have put the final nail in the coffin for me. Personally I am migrating my family's network to MicroTik gear.

Re: Ubiquiti all but confirms breach response iniquity

#22
post #11
post #9

Earlier quoted context omitted.

If the compromise is widespread enough then the attackers might have gained control of the update infrastructure allowing them to push out malicious firmware to your devices.

These blanket statements don’t apply to everyone. It depends which Ubiquiti hardware you own and how you’ve configured it. For example, I run the UniFi controller on my FreeNAS server. There are no forced updates to it. It doesn’t update unless I update it. The firmware on my APs doesn’t update unless I update them from my controller.

So it's a game of luck, depending on whether you updated your firmware? I would call that "affected" rather than "unaffected".

Just because not everyone installs security patches within a few months after they come out (it says the breach had been ongoing for two months) doesn't mean that therefore it doesn't apply to everyone. In the strict sense, indeed not everyone will have been compromised, but it totally applies to you in the sense that through business as usual (assuming that includes installing security updates), you can be compromised.

Re: Ubiquiti all but confirms breach response iniquity

#23
post #5

I’m still on board with Uniquiti, tons of equipment and it wouldn’t make sense to switch everything over for small operations. But this is extremely disappointing, they’re definitely moving in a little bit of a different direction then where many of us would hope. More shiny products that increase bottom line is great but many IT officials rely on UniFi as well, I wonder how they’re responding to enterprise customers…

I wonder if you could extract costs of migration from ubiquity with a lawsuit

You shouldn’t.

Re: Ubiquiti all but confirms breach response iniquity

#25
post #5

I’m still on board with Uniquiti, tons of equipment and it wouldn’t make sense to switch everything over for small operations. But this is extremely disappointing, they’re definitely moving in a little bit of a different direction then where many of us would hope. More shiny products that increase bottom line is great but many IT officials rely on UniFi as well, I wonder how they’re responding to enterprise customers…

>I’m still on board with Uniquiti

Freudian slip?

Re: Ubiquiti all but confirms breach response iniquity

#26

So, what happens now? Will Ubiquiti be held to task, by anyone?

As Matt Levine often reminds us, everything is securities fraud. This looks like a good case for a class-action shareholder lawsuit?

I am looking forward to my cheque in three years for $5.37.

Re: Ubiquiti all but confirms breach response iniquity

#27

Has anyone looked at Ubiquiti's firmware signing? Would it be possible to patch it to retain the drivers and kernel but replace the configuration layers? Being able to homebrew some config would make the equipment more valuable to us I think.

People have been running OpenWRT on Ubiquiti gear for quite a long time iirc. [ https://openwrt.org/toh/ubiquiti/start ]

Afaik performance will be abysmal on edge router series as the npu isn't used.

Re: Ubiquiti all but confirms breach response iniquity

#28

Has anyone looked at Ubiquiti's firmware signing? Would it be possible to patch it to retain the drivers and kernel but replace the configuration layers? Being able to homebrew some config would make the equipment more valuable to us I think.

People have been running OpenWRT on Ubiquiti gear for quite a long time iirc. [ https://openwrt.org/toh/ubiquiti/start ]

couldnt find dream machine support there unfortunately, shame since I have one gathering dust now

Re: Ubiquiti all but confirms breach response iniquity

#30

Earlier quoted context omitted.

They’ve lost my business.

Ditto and they have also lost my recommendations. If I hear any friends thinking of Ubiquiti, I will be pointing them towards articles like the one we are discussing. I had been a bit wary of then since their push for cloud SSO etc, but these recent events have put the final nail in the coffin for me. Personally I am migrating my family's network to MicroTik gear.

A friend of my boss recommended Ubiquity semi-recently. We're a small IT company, plenty of theoretical expertise but no dedicated network admins, so it made sense to go on a recommendation.

The fact that doing anything, for example assigning a VLAN to a switch port, requires you to first setup a mongodb server on your machine before you can install the controller software tipped me off to the quality of what we had bought. The device also gets like 80°C while idle.

This controller software is now on isolated hardware, we trust the thing about as much as an old Android phone, and that was just from our impression as security people without knowing of any breach.

I see it as a good thing that other friends of $friend will be spared that recommendation after this news.

Post reply on HN