Earlier quoted context omitted.
Damn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.
I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based net…
Ubiquiti all but confirms breach response iniquity
51–60 of 322 posts
Re: Ubiquiti all but confirms breach response iniquity
#52Ubiquiti has lost my business. And with the recent issues with Netgate/PfSense [1], it looks like OpnSense is the way to go. [1]: https://arstechnica.com/gadgets/2021/03/buffer-overruns-lice...
why would you not just run OpenBSD with PF.
Re: Ubiquiti all but confirms breach response iniquity
#53With the world of work at home exploding there seems to be a big missing link here.
I'm sitting with a big list of q's that I'm not sure I have a decent amount of time to answer. Does switching to pfsense/openwrt/something open source work with mesh? With ease of set up? Do enterprise brands offer anything worthwhile here? Do I have to regress to letting machines connect to unsecured networks?
Re: Ubiquiti all but confirms breach response iniquity
#54> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…
Re: Ubiquiti all but confirms breach response iniquity
#55Re: Ubiquiti all but confirms breach response iniquity
#56> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…
Re: Ubiquiti all but confirms breach response iniquity
#57By now we'll have to ask: Is it realistic to expect hardware-oriented companies to build secure software? (Yes, Apple exists.)
Most hardware companies don’t care in the slightest about software quality. To them, software is just another line item on the Bill Of Materials, like a bolt or piece of sheet metal. You either have some overworked intern who knows C cobble something together that barely works or you buy it from the least expensive supplier. When the build is ramping, at the end of the assembly line somebody is going to flash somethi…
Re: Ubiquiti all but confirms breach response iniquity
#58Earlier quoted context omitted.
They’ve lost my business.
Plaintiff lawyers will come into effect if there were actual damages as a result of this. Has anyone heard of actual breaches of their own networks as a result? If not, probably no actual damages = class action plaintiffs don’t care because no $ for them. Of course this is generalizing but this is usually the calculus. I know this because I am a cyber attorney.
Re: Ubiquiti all but confirms breach response iniquity
#59> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…
Given they were stupid enough to spin up some VMs, I doubt it was someone that knew what they had access to. A skilled attacker would stay dormant sucking up all data accessible via the AWS API (including s3 stuff) and potentially keep access to the infrastructure for years.
Re: Ubiquiti all but confirms breach response iniquity
#60Earlier quoted context omitted.
Damn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.
I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based net…
[1] https://wiki.mikrotik.com/wiki/Manual:CAPsMAN
[2] https://wiki.mikrotik.com/wiki/Manual:Upgrading_RouterOS#Rou...