Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

91–100 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#91
post #72
post #64

Earlier quoted context omitted.

If you’re really asking, and not making a point; PF is created and primarily maintained by OpenBSD OpenBSD’s base system (without extra packages) includes PF and has a focus on security. PF in freebsd is several major versions old. nftables (like iptables before it) is rule based and not bucket based. So high numbers of rules will not affect pf’s performance like it does with nftables. But, for home users, probably n…

Could you expand on what you mean by "bucket based"? Maybe the so-called "tables"? They sound pretty identical to ipset on Linux.

Here's how a packet flows through netfilter[0], and here's how it flows through pf[1].

[0]: https://upload.wikimedia.org/wikipedia/commons/3/37/Netfilte...

[1]: http://mailing.openbsd.misc.narkive.com/jtIB9W3w/pf-packet-f...

Re: Ubiquiti all but confirms breach response iniquity

#92
post #6

What I’m curious about is, if I run my own controller on my own hardware, do I need to be concerned about this? I could understand supply chain concerns... I’ve held off updating anything while this plays out. But all these “breach! breach!” stories fail to spell out who is affected and what they need to do.

You probably don't need to be concerned(ish). I run a controller for 32 "sites" across the UK with 1 to 13 APs per site and a few switches. I keep it behind HAProxy but with fairly minimal changes (from memory.)

I have stuck with controller 5.13.32 rather than moving to 6.x just yet. It's an LTS version and I'm still waiting for the whinging to stop on the forums. I also watch the AP firmware and that has had some interesting times over the last few months. I've confirmed dodgy AP versions on my sites and backrevved and held accordingly.

I treat the whole thing the same way I do any other system. I come out in spots when people mention clouds and IT in the same sentence, so I have not knowingly enabled any cloudy integrations from my controller to UBNT. Specifically, I have not enabled "Remote Access".

Re: Ubiquiti all but confirms breach response iniquity

#93

Has anyone looked at Ubiquiti's firmware signing? Would it be possible to patch it to retain the drivers and kernel but replace the configuration layers? Being able to homebrew some config would make the equipment more valuable to us I think.

Ubiquiti does not lock their bootloaders like phone manufacturers do. It is very, very easy to run vanilla Linux (or even OpenBSD) on their hardware. I do exactly this: https://news.ycombinator.com/item?id=26645062 Octeons (not Octeon-TX) are amazing processors. Ubiquiti makes killer hardware. I hear their software is junk but wouldn't really know since I always erase it immediately after unboxing.

> An intel goldmont won’t use much more power and can easily do gigabit sqm and wireguard/IPSec without breaking a sweat. Can any of these nearly 2 decade old MIPS/ARM designs come close? I don’t understand the hype for the hardware either.

Re: Ubiquiti all but confirms breach response iniquity

#94

Has anyone looked at Ubiquiti's firmware signing? Would it be possible to patch it to retain the drivers and kernel but replace the configuration layers? Being able to homebrew some config would make the equipment more valuable to us I think.

Ubiquiti does not lock their bootloaders like phone manufacturers do. It is very, very easy to run vanilla Linux (or even OpenBSD) on their hardware. I do exactly this: https://news.ycombinator.com/item?id=26645062 Octeons (not Octeon-TX) are amazing processors. Ubiquiti makes killer hardware. I hear their software is junk but wouldn't really know since I always erase it immediately after unboxing.

Can you still take advantage of the hardware accelerated features? Because I use a little er-x and if you turn on qos, that disables the hardware acceleration and top speeds are cut considerably.

Re: Ubiquiti all but confirms breach response iniquity

#95
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

Are you volunteering for the role? It almost reads as if you are expecting to be named on a list of potential suspects.

Re: Ubiquiti all but confirms breach response iniquity

#96
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

Are you volunteering for the role? It almost reads as if you are expecting to be named on a list of potential suspects.

Or he _is_ the culprit trying to get ahead of the story.

Re: Ubiquiti all but confirms breach response iniquity

#97

Has anyone looked at Ubiquiti's firmware signing? Would it be possible to patch it to retain the drivers and kernel but replace the configuration layers? Being able to homebrew some config would make the equipment more valuable to us I think.

Ubiquiti does not lock their bootloaders like phone manufacturers do. It is very, very easy to run vanilla Linux (or even OpenBSD) on their hardware. I do exactly this: https://news.ycombinator.com/item?id=26645062 Octeons (not Octeon-TX) are amazing processors. Ubiquiti makes killer hardware. I hear their software is junk but wouldn't really know since I always erase it immediately after unboxing.

AFAIK they've started locking them now, since about v5 if memory serves. Got a couple gathering dust now because of this.

Re: Ubiquiti all but confirms breach response iniquity

#98
post #65

Earlier quoted context omitted.

why would you not just run OpenBSD with PF.

I switched from pfsense + Ubiquiti to OpenBSD + Ruckus and couldn't be happier. While the web UIs were cool for a day, with the command line I feel as though I understand exactly what I have setup a bit better. Ruckus UI is also much more friendly than Ubiquiti's - I had to actually install mongo db + VM/dock just to configure my Ubiquiti WAP? Seriously? I just wish I had completely deleted my Ubiquiti account when I…

What hardware are you using?

Re: Ubiquiti all but confirms breach response iniquity

#99
post #60
post #43

Earlier quoted context omitted.

I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based net…

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

> Why do you need in a home environment?

To answer this for me personally (and I suspect this is a pretty common answer): To use the best, and to explore technologies that I might suggest to business clients.

Business clients love central management interfaces.

As well, I’m honestly kind of done with managing fiddly “snowflake” devices, and central management interfaces usually come with the ability to standardize the config across devices.

Re: Ubiquiti all but confirms breach response iniquity

#100
Can companies be held responsible for damages from data breaches?

If they could, it seems like it would incentivize more caution about what data is collected, and more investment in the security of that data.

I also imagine an insurance industry, where the insurers then have expectations about what kinds of security must be in place to get reasonable premiums.

Post reply on HN