Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

171–180 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#171
post #102
post #55

You get great insight into the character of the leaders of a company watching how breaches are handled. Companies that put the customer first are transparent, and quickly take action (even if painful to customers) to ensure that customers’ data and systems stay intact and confidential. Companies that try to gloss over, hide or downplay things indicate that the leadership does not respect their customers and is only i…

If I can vent for a second, this company has no leadership . None. Things may have changed in 2 years, but I doubt it. I was messaged almost daily by random employees asking wtf was going on with the company. They were afraid for their jobs. Practically no one respected the CEO, and he was the only C-suite exec. There. Was. No. Leadership. There was no company wide communication, and all communication channels were m…

> There was no company wide communication, and all communication channels were made private

I couldn't understand why the ex-Amazon cloud lead was also in charge of Slack. When he made all channels private and put a Slackbot in every channel to monitor conversations, I knew it was all over. I'm worried his Slackbot logs are part of the leak. Guy had his hands in everything :(

Same guy who took over GitHub and forced everyone into his self hosted source control because he couldn't trust Github. That decision didn't pay off.

Re: Ubiquiti all but confirms breach response iniquity

#172

Earlier quoted context omitted.

Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.

Mine's only slightly larger than that (mostly by virtue of having 3.5 levels, not by X-Y size), but the original plaster walls attenuate the hell out of 5GHz signals. I have two APs, one in the basement and one on the second floor and even with that, I'm considering adding two more inside and a dedicated one outside to serve the patio/BBQ area as I can readily tell the speed difference to internal file and backup ser…

> the original plaster walls

Ah, the ones that have wire mesh underneath? That would do it.

Re: Ubiquiti all but confirms breach response iniquity

#173
post #19
post #16

Earlier quoted context omitted.

Agreed. My only gear is an EdgeRouter-4. Unlike the Mikrotik it replaced you have go up, find the latest fw file, download and install (that Mikrotik router wasn't designed to handle 1 Gbps and at the time the next step up cost more than the ER).

So unless it hits news channels major enough that you hear about it or there is a bug that you isolate to be due to outdated firmware, you probably won't ever patch security issues in your edge (outside-facing) router?

I've got a recurring calendar item that prompts me to go up and check for updates every week, and I do what it says because after over 25 years in sysadmin I _know_ that the first time I ignore it I'm going to get stung. With Mikrotik I originally had auto update turned on, but later had a script that emailed me when an update was available (so I could schedule a manual update a couple of days later after checking the forums for anything apocalyptic).

Re: Ubiquiti all but confirms breach response iniquity

#174

Earlier quoted context omitted.

The UDM, UDM Pro, and I think _all_ newer controller software require cloud login at some point in the process.

It's definitely not all the new controllers, although with the UDM line you might be right. I think there's a huge intersection between people who would buy those specific devices and people who are perfectly happy to have remote access to their control plane in the cloud.

The UDM and UDM-Pro force you to set up a UI.com account, and cannot be used with external Unifi controllers like one you might run on a server, PC or cloud key (Ubiquiti's management software on a Power over Ethernet powered dongle, does not require a UI.com account).

Re: Ubiquiti all but confirms breach response iniquity

#175
post #5

I’m still on board with Uniquiti, tons of equipment and it wouldn’t make sense to switch everything over for small operations. But this is extremely disappointing, they’re definitely moving in a little bit of a different direction then where many of us would hope. More shiny products that increase bottom line is great but many IT officials rely on UniFi as well, I wonder how they’re responding to enterprise customers…

> they’re definitely moving in a little bit of a different direction then where many of us would hope

it pains me to say this because I was there for the UniFi glory days: The old Ubiquiti is dead and gone. Almost everyone I know quit.

I hope they can land on their feet and return to the glory days but I don't have much hope. The company got toxic fast at the end

Re: Ubiquiti all but confirms breach response iniquity

#176
post #75

Earlier quoted context omitted.

I have a good deal of experience with Mikrotik's offerings, and I am not looking to power networks I support with a patchwork of different systems that each have their own interface. Most of the value proposition of the Unifi lineup is I can look at a single website that I host and see the WiFi clients connected to an access point, what switch feeds that access point internet (and whether its linked at gigabit or 100…

It seems the hackers currently in your network must value those same features. Very convenient.

I don't use a UI.com account to connect to the Unifi controller I host (as I don't need their inconsistently working NAT traversal to get to my controller), hopefully the networks I support are safe due to not being entangled with Ubiquiti's cloud infrastructure.

Anyone who is forced to get a UI.com account (eg: UniFi Dream Machine and UDM-Pro owners) should change their credentials and do a factory reset on their routers and Access Points ASAP.

Re: Ubiquiti all but confirms breach response iniquity

#177

Earlier quoted context omitted.

Is ubiquiti a Chinese company? Really, what a low effort idiotic post.

It's pretty hard to deny that Chinese US relations are heating up. Supporting your own supply chain is becoming a matter of national security, both in terms of potential attacks (what if they load state software on Chinese devices, especially as a response to military action), and in terms of supporting your own industry.

30 years ago, my, then-Representative, Mike Pence was going around supporting tariffs on Chinese steel. I thought tariffs were a Bad Idea, prima facie. Pence explained that if we allowed China to decimate our steel industry, we wouldn't be able to make tanks, domestically. Cogito ergo sum, it was a _literal_ national defense issue.

I don't know where the steel issue stands any more, but we've already been at war with China over intellectual property for 20 years. It would make a great deal of sense to subsidize domestic silicon fabs and computer hardware manufacturing, and tariff foreign versions, for the same reason.

It's no secret why Facebook is not allowed in China. They know exactly what it really does, and what its true value is, and they're not willing to allow that leverage to the US, and it's disturbing that their lack of reciprocity doesn't seem to cause much concern.

It's kind of disgusting that we've outsourced so much of our infrastructure to a country which, in another generation, is going to become the world's most powerful. China is playing the long game. We're willingly giving up our lead because we've built our post-70's society on the almighty stock option, and our myopic focus on only the next quarter.

Re: Ubiquiti all but confirms breach response iniquity

#179
post #168

Earlier quoted context omitted.

Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.

Probably not big by US standards, but WiFi attenuation across multiple floors is such that an AP in the living room won't provide any decent signal one floor straight up. Depends on the materials and layout of your house...

This also means you can re-use a frequency with just one floor in between and no issues, and with a horizontally directional antenna, possibly even on adjacent floors.

Re: Ubiquiti all but confirms breach response iniquity

#180
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

So, did you do it?
Post reply on HN