Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

141–150 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#141

Mentioned it before, but since a few days ago my unifi devices (2 wifi APs, a small switch, plus one Debian VM with the controller, all on it's on VLAN) are not allowed to do outbound traffic anymore, with the exception of NTP, DNS and one trusted apt mirror. Looking at the firewall logs it seems the devices try to ping (ICMP type 8) a bunch of AWS IPs every few hours. The controller tries to connect 80/443 on differ…

LOL sounds like somebody installed a rogue device on your network.

Re: Ubiquiti all but confirms breach response iniquity

#142
post #74

"The Cloud" absolutely can NOT be trusted with anything serious. I'm still amazed serious people actually think it's a smart or wise idea. It's become a "Go to the fridge and get the box" type of mindless laziness by far too many marketers and developers.

It's going to get much worst before it gets better.

Re: Ubiquiti all but confirms breach response iniquity

#143
post #59

Earlier quoted context omitted.

Given they were stupid enough to spin up some VMs, I doubt it was someone that knew what they had access to. A skilled attacker would stay dormant sucking up all data accessible via the AWS API (including s3 stuff) and potentially keep access to the infrastructure for years.

There is no evidence that this did not also happen.

And if it is happening, we might hear about that in a few years' time, if it's discovered, and if it's brought to light in circumstances that are conducive to the vendor making a public disclosure (eg. which are impossible to cover up).

Re: Ubiquiti all but confirms breach response iniquity

#144
post #132

Earlier quoted context omitted.

Only because they made it cloud based. If they never forced people to create a cloud account - and instead allowed people to choose - this would be wildly different.

Did I miss something here? I run a Unifi network with a local account and don‘t recall being forced to create a cloud account.

The UDM, UDM Pro, and I think _all_ newer controller software require cloud login at some point in the process.

Re: Ubiquiti all but confirms breach response iniquity

#146

Mentioned it before, but since a few days ago my unifi devices (2 wifi APs, a small switch, plus one Debian VM with the controller, all on it's on VLAN) are not allowed to do outbound traffic anymore, with the exception of NTP, DNS and one trusted apt mirror. Looking at the firewall logs it seems the devices try to ping (ICMP type 8) a bunch of AWS IPs every few hours. The controller tries to connect 80/443 on differ…

I have said this before, but would like to reiterate that I am never touching or buying anything branded as Ubiquiti or owned by Robert Pera.

This hardware is far from cheap and consumers are literally paying for adware/spyware. I really hope Ubiquiti stock takes a nosedive over the next year.

Re: Ubiquiti all but confirms breach response iniquity

#147
Anyone know if Apple will be putting out a wifi mesh system, maybe integrated into Homepod Minis? Apple already 'owns' me, I might as well have them run my Wifi too and ditch my unifi gear.

At least Apple seems to care about privacy and security, even if it is a self-serving marketing scheme.

Re: Ubiquiti all but confirms breach response iniquity

#148
post #101

Earlier quoted context omitted.

While I've not yet made the purchase, I'm eyeing a Synology RT2600ac ( https://www.synology.com/en-us/products/RT2600ac ) and an MR2200ac ( https://www.synology.com/en-us/products/MR2200ac#specs ). It seems like they'll be adding VLAN support in their 1.3 release ( https://community.synology.com/enu/forum/2/post/130414 ), which should be nice for adding dedicated VPN and guest networks. For me it's one of the few opt…

https://www.amazon.com/gp/customer-reviews/R3GCUBZSITZCYS/

I can at least verify a portion of the second claim of this reviewer's post. A section of the EULA does dictate that Synology grants itself the right to conduct an audit to protect their intellectual property.

"Section 7. Audit.Synology will have the right to audit your compliance with the terms of this EULA. You agree to grant Synology a right to access to your facilities, equipment, books, records and documents and to otherwise reasonably cooperate with Synology in order to facilitate any such audit by Synology or its agent authorized by Synology."

https://www.synology.com/en-us/company/legal/terms_EULA

I can't verify the claims about "Peoples' Republic of China PRC" being allowed to enter a non-Chinese citizen's home (US citizen) to protect IP. Might be applicable to Taiwan or Chinese citizens.

I am not a lawyer so I cant determine whether this EULA is enforceable in the US or EU. Regardless of enforceability, I would be hesitant to buy Synology products as well. Who knows what backdoors they have implemented in order to satisfy the Chinese government.

Re: Ubiquiti all but confirms breach response iniquity

#149

Has anyone looked at Ubiquiti's firmware signing? Would it be possible to patch it to retain the drivers and kernel but replace the configuration layers? Being able to homebrew some config would make the equipment more valuable to us I think.

Ubiquiti does not lock their bootloaders like phone manufacturers do. It is very, very easy to run vanilla Linux (or even OpenBSD) on their hardware. I do exactly this: https://news.ycombinator.com/item?id=26645062 Octeons (not Octeon-TX) are amazing processors. Ubiquiti makes killer hardware. I hear their software is junk but wouldn't really know since I always erase it immediately after unboxing.

New equipment checks firmware signatures.

Re: Ubiquiti all but confirms breach response iniquity

#150
post #65

Earlier quoted context omitted.

I switched from pfsense + Ubiquiti to OpenBSD + Ruckus and couldn't be happier. While the web UIs were cool for a day, with the command line I feel as though I understand exactly what I have setup a bit better. Ruckus UI is also much more friendly than Ubiquiti's - I had to actually install mongo db + VM/dock just to configure my Ubiquiti WAP? Seriously? I just wish I had completely deleted my Ubiquiti account when I…

What Ruckus gear are you running? Last I looked it was pretty expensive.

eBay. The secondary market for high-end network switches is excellent if you’re a buyer.
Post reply on HN