Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

271–280 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#271
post #166
post #60

Earlier quoted context omitted.

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

Similar to the other responses, it's the fact that I can manage my network remotely from a simple app or UI. This helps me answer phone calls from my family asking why Netflix doesn't work on TV #2, when I'm not at home. Won't solve all problems, but at least I can narrow it down and troubleshoot. And I like the fact that I can an overview of the state of my network; one of my wired links to an AP would degrade to 10…

You might be interested in Gl.inet.

It uses OpenWRT, and you can access it remotely.

Re: Ubiquiti all but confirms breach response iniquity

#272
post #148
post #101

Earlier quoted context omitted.

https://www.amazon.com/gp/customer-reviews/R3GCUBZSITZCYS/

I can at least verify a portion of the second claim of this reviewer's post. A section of the EULA does dictate that Synology grants itself the right to conduct an audit to protect their intellectual property. "Section 7. Audit.Synology will have the right to audit your compliance with the terms of this EULA. You agree to grant Synology a right to access to your facilities, equipment, books, records and documents and…

Microsoft can and does the same thing for Windows licensing compliance..

Re: Ubiquiti all but confirms breach response iniquity

#273

Earlier quoted context omitted.

Fwiw, Ubiquiti hardware is actually quite cheap.

Depending on your viewpoint. Compared to an enterprise setup with similar features? Basically free. Compared to your average all-in-one home router, however, these are very expensive.

[deleted]

Re: Ubiquiti all but confirms breach response iniquity

#274
post #185
post #136

Earlier quoted context omitted.

I was addressing "attackers might have gained control of the update infrastructure allowing them to push out malicious firmware to your devices." In my case, no, they cannot push anything to my devices. Obviously, I could pull down compromised firmware. But that's always a risk with software that I don't personally verify, which is like 99.9% of software. As a side note: obviously this security incident doesn't give…

Depending on your configuration, you can ssh in from the UniFi cloud portal. If so, the cloud could easily ignore your settings and push a persistent backdoor.

I do not have remote access enabled.

Re: Ubiquiti all but confirms breach response iniquity

#275
post #102
post #55

You get great insight into the character of the leaders of a company watching how breaches are handled. Companies that put the customer first are transparent, and quickly take action (even if painful to customers) to ensure that customers’ data and systems stay intact and confidential. Companies that try to gloss over, hide or downplay things indicate that the leadership does not respect their customers and is only i…

If I can vent for a second, this company has no leadership . None. Things may have changed in 2 years, but I doubt it. I was messaged almost daily by random employees asking wtf was going on with the company. They were afraid for their jobs. Practically no one respected the CEO, and he was the only C-suite exec. There. Was. No. Leadership. There was no company wide communication, and all communication channels were m…

> I hope this is the last one and they get their act together. But realistically I can't believe that'll happen.

The good thing about them being a public company is there is some accountability from outside the company. Looks like they're already being investigated for fraud for downplaying the breach and their stock price took a big hit. Hopefully this all leads to the CEO being replaced and things turning around.

Re: Ubiquiti all but confirms breach response iniquity

#276
post #131

Earlier quoted context omitted.

Yup, this is more or less how “cyber security” policies work.

Unless it’s changed in the last two or three years cyber security insurance policies seem only to cover the cost of notifying customers of the breach and paying for credit monitoring for whatever period of time is required in each customer’s specific jurisdiction. (When last I looked, in most states it’s none.) Every time I looked into cyber security insurance it wasn’t worthwhile at all because it didn’t provide any…

It may be worth reviewing cybersecurity insurance policies with your legal team!

At a former company, we had a nasty case of BEC with a vendor that ultimately cost us well over six figures - over 90% of the loss was recouped by filing a claim with our insurance.

Re: Ubiquiti all but confirms breach response iniquity

#277
post #248
post #60

Earlier quoted context omitted.

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

Mikrotik have not been able to keep up with the latest, or previous to latest wifi standards, seems like it's become too complex

Skipping wifi 6 seems like a smart move, with 6E on the horizon. It includes all the things that should have been part of the standard in the first place, so why get your hardware certified for 6, if you have to get it recertified for 6E anyway shortly after?

6 doesn't add very much over 5 in real world setups, very few devices even support 802.11ax yet, and the bleeding edge has never been Mikrotik's target segment.

6E gear is not really available anywhere yet, so it's really only an issue for people who just have to have the latest gear at all times. For the majority of people, 802.11ac/wifi 5 is what their hardware supports, so that's what they need.

Re: Ubiquiti all but confirms breach response iniquity

#278
post #174

Earlier quoted context omitted.

It's definitely not all the new controllers, although with the UDM line you might be right. I think there's a huge intersection between people who would buy those specific devices and people who are perfectly happy to have remote access to their control plane in the cloud.

The UDM and UDM-Pro force you to set up a UI.com account, and cannot be used with external Unifi controllers like one you might run on a server, PC or cloud key (Ubiquiti's management software on a Power over Ethernet powered dongle, does not require a UI.com account).

The UDM and UDM Pro are the controller, and you can disable all of the cloud nonsense after initial setup.

Re: Ubiquiti all but confirms breach response iniquity

#279
post #12

So this week, I have gone from having a single little USG and a massive order planned for loads of kit to stopping them automatically updating the firmware and dropping that order. Extremely annoying, but not as annoying as if this had happened in a couple of weeks.

So what are vendor are you changing to now?

Re: Ubiquiti all but confirms breach response iniquity

#280
post #174

Earlier quoted context omitted.

The UDM and UDM-Pro force you to set up a UI.com account, and cannot be used with external Unifi controllers like one you might run on a server, PC or cloud key (Ubiquiti's management software on a Power over Ethernet powered dongle, does not require a UI.com account).

The UDM and UDM Pro are the controller, and you can disable all of the cloud nonsense after initial setup.

You can disable on the UDM but I don't believe the UDM pro allows you to. Thats just what I've heard though, so might not be accurate.
Post reply on HN