So, what happens now? Will Ubiquiti be held to task, by anyone?
They’ve lost my business.
Ubiquiti all but confirms breach response iniquity
21–30 of 322 posts
Re: Ubiquiti all but confirms breach response iniquity
#22Earlier quoted context omitted.
If the compromise is widespread enough then the attackers might have gained control of the update infrastructure allowing them to push out malicious firmware to your devices.
These blanket statements don’t apply to everyone. It depends which Ubiquiti hardware you own and how you’ve configured it. For example, I run the UniFi controller on my FreeNAS server. There are no forced updates to it. It doesn’t update unless I update it. The firmware on my APs doesn’t update unless I update them from my controller.
Just because not everyone installs security patches within a few months after they come out (it says the breach had been ongoing for two months) doesn't mean that therefore it doesn't apply to everyone. In the strict sense, indeed not everyone will have been compromised, but it totally applies to you in the sense that through business as usual (assuming that includes installing security updates), you can be compromised.
Re: Ubiquiti all but confirms breach response iniquity
#23I’m still on board with Uniquiti, tons of equipment and it wouldn’t make sense to switch everything over for small operations. But this is extremely disappointing, they’re definitely moving in a little bit of a different direction then where many of us would hope. More shiny products that increase bottom line is great but many IT officials rely on UniFi as well, I wonder how they’re responding to enterprise customers…
I wonder if you could extract costs of migration from ubiquity with a lawsuit
Re: Ubiquiti all but confirms breach response iniquity
#24Re: Ubiquiti all but confirms breach response iniquity
#25I’m still on board with Uniquiti, tons of equipment and it wouldn’t make sense to switch everything over for small operations. But this is extremely disappointing, they’re definitely moving in a little bit of a different direction then where many of us would hope. More shiny products that increase bottom line is great but many IT officials rely on UniFi as well, I wonder how they’re responding to enterprise customers…
Freudian slip?
Re: Ubiquiti all but confirms breach response iniquity
#26Re: Ubiquiti all but confirms breach response iniquity
#27Has anyone looked at Ubiquiti's firmware signing? Would it be possible to patch it to retain the drivers and kernel but replace the configuration layers? Being able to homebrew some config would make the equipment more valuable to us I think.
People have been running OpenWRT on Ubiquiti gear for quite a long time iirc. [ https://openwrt.org/toh/ubiquiti/start ]
Re: Ubiquiti all but confirms breach response iniquity
#28Has anyone looked at Ubiquiti's firmware signing? Would it be possible to patch it to retain the drivers and kernel but replace the configuration layers? Being able to homebrew some config would make the equipment more valuable to us I think.
People have been running OpenWRT on Ubiquiti gear for quite a long time iirc. [ https://openwrt.org/toh/ubiquiti/start ]
Re: Ubiquiti all but confirms breach response iniquity
#29[1]: https://arstechnica.com/gadgets/2021/03/buffer-overruns-lice...
Re: Ubiquiti all but confirms breach response iniquity
#30Earlier quoted context omitted.
They’ve lost my business.
Ditto and they have also lost my recommendations. If I hear any friends thinking of Ubiquiti, I will be pointing them towards articles like the one we are discussing. I had been a bit wary of then since their push for cloud SSO etc, but these recent events have put the final nail in the coffin for me. Personally I am migrating my family's network to MicroTik gear.
The fact that doing anything, for example assigning a VLAN to a switch port, requires you to first setup a mongodb server on your machine before you can install the controller software tipped me off to the quality of what we had bought. The device also gets like 80°C while idle.
This controller software is now on isolated hardware, we trust the thing about as much as an old Android phone, and that was just from our impression as security people without knowing of any breach.
I see it as a good thing that other friends of $friend will be spared that recommendation after this news.