Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

181–190 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#181
post #152

Earlier quoted context omitted.

It's not a massive ask to install MongoDB. Unifi stuff is quite cheap for what you get for a simple reason: Each one does not need to run a webserver and all that stuff. This means that the pretty stuff has to run elsewhere. For a single site you can use a phone app and for multi site setups and MSPs you have the controllers. The controller can be run on a Windows PC with a next next install or a Linux box with prett…

Whatever one may thing of the quality of MongoDB, they are asking you to install a defunct version.

And it only works with MongoDB shipped with older versions of Debian. The current Debian doesn't even have the most current version of MongoDB (due to Debian policy of backporting security fixes only) but even that is too new! In the future it would not surprise me the least to find that the only way to use the Unifi controller will be by using a non-supported distro.

Re: Ubiquiti all but confirms breach response iniquity

#182
post #112

Earlier quoted context omitted.

> replacing my USG with my existing home server I like this idea too, but would prefer that the router was physically separated and before any hardware that was in the network. Is this a pointless concern?

It's hard to say whether or not the concern is pointless without knowing its basis. Why do you want it physically separated?

I had assumed a setup which had several VMs, with one being a PFSense or similar to be less secure than a standalone firewall. Reading about the pros and cons leads me to conclude that security in a virtual setup is just fine.

Re: Ubiquiti all but confirms breach response iniquity

#183
post #176

Earlier quoted context omitted.

It seems the hackers currently in your network must value those same features. Very convenient.

I don't use a UI.com account to connect to the Unifi controller I host (as I don't need their inconsistently working NAT traversal to get to my controller), hopefully the networks I support are safe due to not being entangled with Ubiquiti's cloud infrastructure. Anyone who is forced to get a UI.com account (eg: UniFi Dream Machine and UDM-Pro owners) should change their credentials and do a factory reset on their ro…

> do a factory reset on their routers and Access Points ASAP

This is a miserable user experience. If you do a reset and don’t know the SSH password on APs or cameras you get to spend a hellish few hours crawling though ceiling insulation, climbing ladders and physically resetting devices. It’s so shit. I’ve just done it, but not due to security concerns, but instead because of a UDM-P crapping out randomly.

Re: Ubiquiti all but confirms breach response iniquity

#184
post #60

Earlier quoted context omitted.

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.

Getting signal to devices isn’t a problem, but it’s not easy having an AP receive signal from a low power device. Multiple APs is the way to go in my experience.

Re: Ubiquiti all but confirms breach response iniquity

#185
post #136
post #18

Earlier quoted context omitted.

Unless you're manually verifying the content of your AP firmware updates (which is a bit hard since they're closedsource), I don't understand what you're trying to say. The firmware could be compromised at the source so your FreeNAS doesn't help at all when you download and apply a compromised firmware update. Unless you're not updating your APs and keeping them vulnerable in that way :)

I was addressing "attackers might have gained control of the update infrastructure allowing them to push out malicious firmware to your devices." In my case, no, they cannot push anything to my devices. Obviously, I could pull down compromised firmware. But that's always a risk with software that I don't personally verify, which is like 99.9% of software. As a side note: obviously this security incident doesn't give…

Depending on your configuration, you can ssh in from the UniFi cloud portal. If so, the cloud could easily ignore your settings and push a persistent backdoor.

Re: Ubiquiti all but confirms breach response iniquity

#186
post #172

Earlier quoted context omitted.

Mine's only slightly larger than that (mostly by virtue of having 3.5 levels, not by X-Y size), but the original plaster walls attenuate the hell out of 5GHz signals. I have two APs, one in the basement and one on the second floor and even with that, I'm considering adding two more inside and a dedicated one outside to serve the patio/BBQ area as I can readily tell the speed difference to internal file and backup ser…

> the original plaster walls Ah, the ones that have wire mesh underneath? That would do it.

Somehow I have managed to spend most my time in a house that has concrete and brick stopping 5G, a house with wooden walls that block RF and foil insulation under the floor which is even worse, and a workplace environment that has literal faraday cages all around.

I like UniFi in wall access points in the room I’m inside.

Re: Ubiquiti all but confirms breach response iniquity

#187
post #146

Mentioned it before, but since a few days ago my unifi devices (2 wifi APs, a small switch, plus one Debian VM with the controller, all on it's on VLAN) are not allowed to do outbound traffic anymore, with the exception of NTP, DNS and one trusted apt mirror. Looking at the firewall logs it seems the devices try to ping (ICMP type 8) a bunch of AWS IPs every few hours. The controller tries to connect 80/443 on differ…

I have said this before, but would like to reiterate that I am never touching or buying anything branded as Ubiquiti or owned by Robert Pera. This hardware is far from cheap and consumers are literally paying for adware/spyware. I really hope Ubiquiti stock takes a nosedive over the next year.

How is it "adware/spyware"?

Re: Ubiquiti all but confirms breach response iniquity

#188
post #102

Earlier quoted context omitted.

If I can vent for a second, this company has no leadership . None. Things may have changed in 2 years, but I doubt it. I was messaged almost daily by random employees asking wtf was going on with the company. They were afraid for their jobs. Practically no one respected the CEO, and he was the only C-suite exec. There. Was. No. Leadership. There was no company wide communication, and all communication channels were m…

> There was no company wide communication, and all communication channels were made private I couldn't understand why the ex-Amazon cloud lead was also in charge of Slack. When he made all channels private and put a Slackbot in every channel to monitor conversations, I knew it was all over. I'm worried his Slackbot logs are part of the leak. Guy had his hands in everything :( Same guy who took over GitHub and forced…

> Same guy who took over GitHub and forced everyone into his self hosted source control because he couldn't trust Github.

sounds smart to me. I wouldn't trust github either.

Re: Ubiquiti all but confirms breach response iniquity

#189

Earlier quoted context omitted.

It's pretty hard to deny that Chinese US relations are heating up. Supporting your own supply chain is becoming a matter of national security, both in terms of potential attacks (what if they load state software on Chinese devices, especially as a response to military action), and in terms of supporting your own industry.

I don’t deny any of that. But where is most of the hardware for just about any network and computing equipment manufactured? Questioning if tplink is made in China is pretty low effort and pointless. A thoughtful analysis would ask why an onshore supplier would fundamentally be any less vulnerable to political adversaries.

being made in china and being a Chinese company are very different things and the risks are different.

Re: Ubiquiti all but confirms breach response iniquity

#190

Earlier quoted context omitted.

Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.

Depends a lot on the house. My house is It wasn’t a problem until covid when multiple meeting or other streams just performed poorly on a marginal network. The Ubiquiti gear made it easier to run antennas for optimal signal. The hot thing to do is to shit on them, but I’ll be sticking with it. They’ll emerge better from this crisis and if you think that any competitor in this price point is better, you’re delusional.

COVID had me setting up more UniFi APs. It held up incredibly well for moving large files across VPNs and running multiple Zooms for work places and school.

COVID must have been a massive boost to their bottom line.

I’m no market analyst, but the last year, even including the last week, has been very good to Ubiquiti.

https://www.nasdaq.com/market-activity/stocks/ui/advanced-ch...

Post reply on HN