Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

221–230 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#221
post #60

Earlier quoted context omitted.

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.

I use three unifi AP-Pros for my 3500 sq ft home plus front and back yard.

I possibly could have done it with two if I ignored the outside areas but one definitely wasn’t enough even with careful placement.

Edit: obviously 2.4ghz penetrates further, but 4k streaming on multiple TVs doesn’t go well with the bandwidth (and interference) on 2,4

Re: Ubiquiti all but confirms breach response iniquity

#222

Mentioned it before, but since a few days ago my unifi devices (2 wifi APs, a small switch, plus one Debian VM with the controller, all on it's on VLAN) are not allowed to do outbound traffic anymore, with the exception of NTP, DNS and one trusted apt mirror. Looking at the firewall logs it seems the devices try to ping (ICMP type 8) a bunch of AWS IPs every few hours. The controller tries to connect 80/443 on differ…

The ping is probably the uptime and connectivity monitor, which can be disabled. It regularly sends a ping to ping.ubnt.com.

Re: Ubiquiti all but confirms breach response iniquity

#223
post #64
post #52

Earlier quoted context omitted.

Why should I choose OpenBSD over FreeBSD or even Linux with nftables?

If you’re really asking, and not making a point; PF is created and primarily maintained by OpenBSD OpenBSD’s base system (without extra packages) includes PF and has a focus on security. PF in freebsd is several major versions old. nftables (like iptables before it) is rule based and not bucket based. So high numbers of rules will not affect pf’s performance like it does with nftables. But, for home users, probably n…

>nftables (like iptables before it) is rule based and not bucket based.

What does this even mean? Do you have any documentation to explain?

>So high numbers of rules will not affect pf’s performance like it does with nftables.

This is wrong. From OpenBSD documentation:

"More lines being evaluated for each packet will result in slower performance."

[0]https://www.openbsd.org/faq/pf/perf.html

It's not 2001 any more. Nftables and Linux have left the BSDs in the dust.

Re: Ubiquiti all but confirms breach response iniquity

#224

Mentioned it before, but since a few days ago my unifi devices (2 wifi APs, a small switch, plus one Debian VM with the controller, all on it's on VLAN) are not allowed to do outbound traffic anymore, with the exception of NTP, DNS and one trusted apt mirror. Looking at the firewall logs it seems the devices try to ping (ICMP type 8) a bunch of AWS IPs every few hours. The controller tries to connect 80/443 on differ…

The ping is probably the uptime and connectivity monitor, which can be disabled. It regularly sends a ping to ping.ubnt.com.

Or configured to a different (your own) endpoint

Re: Ubiquiti all but confirms breach response iniquity

#225
post #43

Earlier quoted context omitted.

Damn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.

I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based net…

I was going to look at OpenWISP, which looks like it can centrally manage a whole bunch of kit, including openwrt and also edgeswitch devices.

Re: Ubiquiti all but confirms breach response iniquity

#226

On this subject, does anyone know what is up with the reddit sub, r/ubiquiti? Seems to be run by u/briellie. She(?) seems like a really toxic person with some kind of business relationship with Ubiquiti like a reseller or something. The Reddit sub seems like they are actively trying to suppress discussion of this issue. There's some allegations of censorship on the sub, but I'm not seeing it... which might actually j…

There was a recent discussion[1] on the sub with 1K upvotes and over 500 comments about the breach and I routinely see unabated salty posts and comments about Ubiquiti's downward spiral. I have lurked on the sub for several years (I manage a bunch of Ubiquiti gear) and I never got the impression people were being censored or moderated into submission.

Are there any particular examples of suppression or links to the allegations of censorship? The sub did recently begin allowing equipment picture posts again by popular demand. [2] I suppose an uncharitable interpretation is that that move was appeasement to distract from the breach issue.

[1] https://www.reddit.com/r/Ubiquiti/comments/mgm4o7/whistleblo...

[2] https://www.reddit.com/r/Ubiquiti/comments/mi0679/rule_chang...

Edit: Formatting

Re: Ubiquiti all but confirms breach response iniquity

#228

Earlier quoted context omitted.

That would be the reverse of the usual strategy, wouldn't it? Most companies seem to try to pin breaches on sophisticated hacker groups backed by nation states. But then, they benefit from the perception of a threat that's impossible to defend from (so there wasn't anything they could do) - whereas Ubiquiti benefits from people thinking the attack was just a small actor that couldn't possibly threaten Ubiquiti's cust…

> nation states Nation state is not a fancy infosec way of saying country

Nah, most of the time it's just a fancy infosec way of saying "it was likely ordinary criminals, or even some script kiddies, but it would be quite embarrassing to admit that".

Re: Ubiquiti all but confirms breach response iniquity

#230

Earlier quoted context omitted.

That would be the reverse of the usual strategy, wouldn't it? Most companies seem to try to pin breaches on sophisticated hacker groups backed by nation states. But then, they benefit from the perception of a threat that's impossible to defend from (so there wasn't anything they could do) - whereas Ubiquiti benefits from people thinking the attack was just a small actor that couldn't possibly threaten Ubiquiti's cust…

Accusing whistleblowers of criminal activity? That's a pretty common ploy. Been there, done that. Early in my career when I was naive enough to try to whistleblow on things over my head.

Accusing whistleblowers and reporters is indeed common - it pretty much seems the standard behavior in infosec in particular.

What I meant was something different. The breach, as I understand it, was quite critical. Ubiquiti in this case could take the standard corporate spiel of "it has hallmarks of a nation state attack, there was nothing we could do" bullshit disclaimer - but given the nature of this breach, every customer of theirs would now be wondering if $Enemy has put malware in their infra, and whether it isn't a good idea to smash it all with a hammer and buy new one from someone else. So I suspect Ubiquiti is going the other way, blaming it on a single, inconsequential individual, that absolutely, positively didn't give access to anyone else, and thus nobody's infra was in any danger.

(Note: I have no inside knowledge, or even any deep knowledge, of this topic - I'm just a random Internet person speculating.)

Post reply on HN