Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

41–50 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#41
post #29

Ubiquiti has lost my business. And with the recent issues with Netgate/PfSense [1], it looks like OpnSense is the way to go. [1]: https://arstechnica.com/gadgets/2021/03/buffer-overruns-lice...

why would you not just run OpenBSD with PF.

Does OpenBSD with PF have a nice web interface to administrate the firewall, DHCP server, WLANs, etc from?

Re: Ubiquiti all but confirms breach response iniquity

#42
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

yeah this is just a good as just saying it "has the hallmarks of a state-level attack", pointing at Russia and calling it a day

everyone believes it

Re: Ubiquiti all but confirms breach response iniquity

#43
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

Damn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.

I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack.

I really just want to manage an OpenWRT based network with one central web interface and not have to deal with corporate/state entities deciding to push fun changes out in the management interfaces that power these systems.

Re: Ubiquiti all but confirms breach response iniquity

#44
It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response.

At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewhat pricey; but, not totally unreasonable option for the home.

Any suggestions from the HN crowd?

Re: Ubiquiti all but confirms breach response iniquity

#45
post #30

Earlier quoted context omitted.

A friend of my boss recommended Ubiquity semi-recently. We're a small IT company, plenty of theoretical expertise but no dedicated network admins, so it made sense to go on a recommendation. The fact that doing anything , for example assigning a VLAN to a switch port, requires you to first setup a mongodb server on your machine before you can install the controller software tipped me off to the quality of what we had…

Meraki has captured my fancy lately. Expensive but a pretty great value prop.

Frankly, all we needed was a switch where you can add VLAN tags and send them to a trunk port. And I suppose a password on the "I would like this VLAN on this port, please" interface is also necessary, but I think that already concludes the grand list of requirements. Everything else we control on the router.

It doesn't have to be network equipment in the traditional sense: any old linux server will do, it's just that it needs to have a couple dozen network ports. Traffic can be limited to a gigabit per second between all the ports combined (no need for multi-gigabit backplanes or switch fabrics or what the correct term for that is). I'd almost buy a big USB hub and connect USB–Ethernet adapters, but that feels more hacky than core infrastructure is supposed to be.

Re: Ubiquiti all but confirms breach response iniquity

#46
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

I hope you don't end up fulfilling your own prophecy

Re: Ubiquiti all but confirms breach response iniquity

#47
post #32

By now we'll have to ask: Is it realistic to expect hardware-oriented companies to build secure software? (Yes, Apple exists.)

Most hardware companies don’t care in the slightest about software quality. To them, software is just another line item on the Bill Of Materials, like a bolt or piece of sheet metal. You either have some overworked intern who knows C cobble something together that barely works or you buy it from the least expensive supplier. When the build is ramping, at the end of the assembly line somebody is going to flash something on the device, and they are not going to stop the line to worry about a security hole.

Re: Ubiquiti all but confirms breach response iniquity

#48
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

Damn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.

During this week I've been playing around with replacing my USG with my existing home server - it already has two NICs - my first thought was to run OPNSense in a VM but nftables on NixOS seems to work well enough - there are a few examples floating online [0,1]. OpenBSD even supports the USG [2] but I couldn't think of much reason to keep the extra hardware.

The next thing I want to do is reflash my Unifi APs with OpenWRT [3] - the hardware is fine, but at that point I'll get all the support without the controller software.

My home environment is fairly basic so moving away isn't too hard - this would obviously be much harder for a small business...

[0] - https://francis.begyn.be/blog/nixos-home-router

[1] - http://www.willghatch.net/blog/2020/06/22/nixos-raspberry-pi...

[2] - https://www.openbsd.org/octeon.html

[3] - https://openwrt.org/toh/ubiquiti/start

Re: Ubiquiti all but confirms breach response iniquity

#49
post #46
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

I hope you don't end up fulfilling your own prophecy

I'm pretty sure I'm safe. I left as soon as I could (almost 2 years ago) once I realized how institutionally broken the company was.

Re: Ubiquiti all but confirms breach response iniquity

#50

It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response. At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewh…

That is my exact configuration, too. Would love to have alternatives.
Post reply on HN