Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

71–80 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#71
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

yeah this is just a good as just saying it "has the hallmarks of a state-level attack", pointing at Russia and calling it a day everyone believes it

That may have worn thin, nowadays. The average response here would have been described as cynical in the past. The Russia/China scapegoat had been way overused to the point where I'm cynical every time it comes up probably even where it's actually true, one time in a hundred or whatever.

Nobody blames the NSA in these circumstances, ever.

Re: Ubiquiti all but confirms breach response iniquity

#72
post #64
post #52

Earlier quoted context omitted.

Why should I choose OpenBSD over FreeBSD or even Linux with nftables?

If you’re really asking, and not making a point; PF is created and primarily maintained by OpenBSD OpenBSD’s base system (without extra packages) includes PF and has a focus on security. PF in freebsd is several major versions old. nftables (like iptables before it) is rule based and not bucket based. So high numbers of rules will not affect pf’s performance like it does with nftables. But, for home users, probably n…

Could you expand on what you mean by "bucket based"? Maybe the so-called "tables"? They sound pretty identical to ipset on Linux.

Re: Ubiquiti all but confirms breach response iniquity

#75
post #60
post #43

Earlier quoted context omitted.

I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based net…

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

I have a good deal of experience with Mikrotik's offerings, and I am not looking to power networks I support with a patchwork of different systems that each have their own interface.

Most of the value proposition of the Unifi lineup is I can look at a single website that I host and see the WiFi clients connected to an access point, what switch feeds that access point internet (and whether its linked at gigabit or 100Mbps), uptime on all devices involved in the stack, whether the client has poor WiFi quality, trouble DHCPing, etc.

The single pane of glass to view everything when I am many miles from the networks I support is essential. Compared to when these sites were on PFSense before migrating, these networks have improved uptime, rapid remediation of issues, and changing VLANs, SSIDs and labeling each client on the network is a snap.

Edit: Borrowed /u/bpye's single pane of glass term

Re: Ubiquiti all but confirms breach response iniquity

#76
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

Given they were stupid enough to spin up some VMs, I doubt it was someone that knew what they had access to. A skilled attacker would stay dormant sucking up all data accessible via the AWS API (including s3 stuff) and potentially keep access to the infrastructure for years.

This kind of analysis is basically worthless because you don’t know whether they are operating at multiple levels of deception by, e.g., making you think they are a stupid script kiddie and that you successfully wiped them out.

Re: Ubiquiti all but confirms breach response iniquity

#77

It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response. At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewh…

While I've not yet made the purchase, I'm eyeing a Synology RT2600ac ( https://www.synology.com/en-us/products/RT2600ac ) and an MR2200ac ( https://www.synology.com/en-us/products/MR2200ac#specs ). It seems like they'll be adding VLAN support in their 1.3 release ( https://community.synology.com/enu/forum/2/post/130414 ), which should be nice for adding dedicated VPN and guest networks. For me it's one of the few opt…

I recently went with two 2200acs. Been mostly pleased, but there were some settings i had to play with to get the right router to use some of the more distant devices.. without custom settings it trys to load balance devices over choosing based on signal strength, thus a far device from the main router had an unusable connection..

Re: Ubiquiti all but confirms breach response iniquity

#78
post #51
post #43

Earlier quoted context omitted.

I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based net…

It's an interesting idea to have a single pane of glass management experience for OpenWRT - given that all config is under UCI [0] it seems very possible. One of the things on my todo list is to try and get Nix to push config to my Unifi APs when I flash them with OpenWRT. [0] - https://openwrt.org/docs/guide-user/base-system/uci

Take a look at https://openwisp.io/docs/ as it can accomplish this today.

Re: Ubiquiti all but confirms breach response iniquity

#79
post #58

Earlier quoted context omitted.

Plaintiff lawyers will come into effect if there were actual damages as a result of this. Has anyone heard of actual breaches of their own networks as a result? If not, probably no actual damages = class action plaintiffs don’t care because no $ for them. Of course this is generalizing but this is usually the calculus. I know this because I am a cyber attorney.

even without actual damages, there will be a securities class-action lawsuit for anyone that lost money on the stock.; and as usual lawyers will collect big payouts, and shareholders will get a few dollars if they are lucky.

Get a few dollars from who? The owners of the company will have to pay themselves because they messed up? What a great reason to pay lawyers and clog up courts at taxpayers' expense.

Re: Ubiquiti all but confirms breach response iniquity

#80
post #30

Earlier quoted context omitted.

A friend of my boss recommended Ubiquity semi-recently. We're a small IT company, plenty of theoretical expertise but no dedicated network admins, so it made sense to go on a recommendation. The fact that doing anything , for example assigning a VLAN to a switch port, requires you to first setup a mongodb server on your machine before you can install the controller software tipped me off to the quality of what we had…

Meraki has captured my fancy lately. Expensive but a pretty great value prop.

I support two Meraki MX64 routers, they are definitely expensive and have repeatedly caused issues for my clients when their ISPs force an upgrade of the associated modem. Not sure what shenanigans Cisco has done with Meraki, but I have wasted hours with them on the phone trying to get these MX64's to DHCP from a new cable modem.

Ended up swapping in an Archer C7 on OpenWRT with a LTE modem to ensure business continuity for the client while working with Meraki's abysmal support to get their router to work correctly.

Post reply on HN