Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

31–40 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#31
> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.”

I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be somebody who raised a stink about all the security problems during their time there.

Form your own opinion, I'm just a guy who worked at Ubiquiti for a year, raising all kinds of hell about the security, architectural, and operational problems that I saw while I was there.

But what do I know...

Re: Ubiquiti all but confirms breach response iniquity

#33
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

I mean, don't get me wrong, there absolutely _is_ somebody who's responsible for it, but I wouldn't place any money on Ubiquiti being able to figure out who it really was.

They want to brush this under the rug as fast as they can, and that means using the opportunity to pin it on somebody that's been "problematic".

Re: Ubiquiti all but confirms breach response iniquity

#34
What no one seems to be really discussing is how paranoid should people be around this breach?

Is it a case of you probably want to rebuild machines that have default usernames/passwords? Or is it more whatever can be seen in the Ubiquiti UI might be been accessed by third parties?

Re: Ubiquiti all but confirms breach response iniquity

#35

Has anyone looked at Ubiquiti's firmware signing? Would it be possible to patch it to retain the drivers and kernel but replace the configuration layers? Being able to homebrew some config would make the equipment more valuable to us I think.

Ubiquiti does not lock their bootloaders like phone manufacturers do.

It is very, very easy to run vanilla Linux (or even OpenBSD) on their hardware. I do exactly this:

https://news.ycombinator.com/item?id=26645062

Octeons (not Octeon-TX) are amazing processors. Ubiquiti makes killer hardware. I hear their software is junk but wouldn't really know since I always erase it immediately after unboxing.

Re: Ubiquiti all but confirms breach response iniquity

#36

Earlier quoted context omitted.

People have been running OpenWRT on Ubiquiti gear for quite a long time iirc. [ https://openwrt.org/toh/ubiquiti/start ]

Afaik performance will be abysmal on edge router series as the npu isn't used.

From firsthand experience: performance is in fact awesome on the edgerouters (4, 6, 8, and 12) using plain-vanilla Linux.

It's a big honking MIPS chip with firehose connections to the ethernet PHYs. Precisely the kind of device you want for a router.

Re: Ubiquiti all but confirms breach response iniquity

#37
post #30

Earlier quoted context omitted.

Ditto and they have also lost my recommendations. If I hear any friends thinking of Ubiquiti, I will be pointing them towards articles like the one we are discussing. I had been a bit wary of then since their push for cloud SSO etc, but these recent events have put the final nail in the coffin for me. Personally I am migrating my family's network to MicroTik gear.

A friend of my boss recommended Ubiquity semi-recently. We're a small IT company, plenty of theoretical expertise but no dedicated network admins, so it made sense to go on a recommendation. The fact that doing anything , for example assigning a VLAN to a switch port, requires you to first setup a mongodb server on your machine before you can install the controller software tipped me off to the quality of what we had…

Meraki has captured my fancy lately. Expensive but a pretty great value prop.

Re: Ubiquiti all but confirms breach response iniquity

#39
post #34

What no one seems to be really discussing is how paranoid should people be around this breach? Is it a case of you probably want to rebuild machines that have default usernames/passwords? Or is it more whatever can be seen in the Ubiquiti UI might be been accessed by third parties?

> Is it a case of you probably want to rebuild machines that have default usernames/passwords?

I mean, regardless, most probably, the answer to this is yes.

Re: Ubiquiti all but confirms breach response iniquity

#40
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

Damn, that's pretty depressing.

I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.

Post reply on HN