Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

281–290 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#281

Earlier quoted context omitted.

Depending on your viewpoint. Compared to an enterprise setup with similar features? Basically free. Compared to your average all-in-one home router, however, these are very expensive.

> Compared to your average all-in-one home router, however, these are very expensive. Compared to your average all-in-one home router, however, these are also markedly less shitty.

The nano with WIFI-6 is $99, the decent all-on-one routers with wifi-6 I've seen are around $200.

Re: Ubiquiti all but confirms breach response iniquity

#282

Mentioned it before, but since a few days ago my unifi devices (2 wifi APs, a small switch, plus one Debian VM with the controller, all on it's on VLAN) are not allowed to do outbound traffic anymore, with the exception of NTP, DNS and one trusted apt mirror. Looking at the firewall logs it seems the devices try to ping (ICMP type 8) a bunch of AWS IPs every few hours. The controller tries to connect 80/443 on differ…

Is that going to the trace service? There was a falling out between teams while I was there because the cloud team wanted to collect stats from APs even when users disabled analytics in the UI. It was so bad that some of the developers and one of the leads quit because they didn't want to be a part of it. Someone on Reddit started reverse engineering it https://www.reddit.com/r/Ubiquiti/comments/lwr4ud/update_ubi...…

Yep, analytics is disabled. Thanks for the link, didn't look into the data being sent. But I can't confirm my devices trying to send out data if I SSH into them (just tried it for the 1st time).

Re: Ubiquiti all but confirms breach response iniquity

#283
post #148

Earlier quoted context omitted.

I can at least verify a portion of the second claim of this reviewer's post. A section of the EULA does dictate that Synology grants itself the right to conduct an audit to protect their intellectual property. "Section 7. Audit.Synology will have the right to audit your compliance with the terms of this EULA. You agree to grant Synology a right to access to your facilities, equipment, books, records and documents and…

Microsoft can and does the same thing for Windows licensing compliance..

I'm only aware of similar terms in their volume license agreements. Do you have a pointer to such terms in their standard, off-the-shelf Windows versions? Cannot find anything here: https://www.microsoft.com/en-us/Useterms/Retail/Windows/10/U...

Re: Ubiquiti all but confirms breach response iniquity

#284

Earlier quoted context omitted.

The UDM and UDM Pro are the controller, and you can disable all of the cloud nonsense after initial setup.

You can disable on the UDM but I don't believe the UDM pro allows you to. Thats just what I've heard though, so might not be accurate.

The UDM Pro does allow it. I've got one, and all of the cloud stuff is disabled.

Re: Ubiquiti all but confirms breach response iniquity

#285
post #251

Earlier quoted context omitted.

HPE seems to be aiming squarely at Ubiquiti with their Aruba Instant On line (which is distinct from the Aruba Instant line because what's life without some confusing branding?). I installed some of their APs and switches in my home a few weeks ago and it's working well. It ended up a little less expensive than comparable UBNT gear would have been and there's actual availability on their Wifi6 APs. The APs are cloud…

> The APs are cloud managed only, but, personally, I trust HPE not to make a complete clown show That is unwise on the long-term, though. The technology is there so you don't have to trust anyone, so why do you choose to trust them when they're not offering cloudfree solutions?

Because it was the best available option in my price range in all other aspects and I honestly don't care all that much where the AP controller for my home network is located. The APs will continue to work while offline and I'm unlikely to even look at the controller interface more than a handful of times a year provided the vendor doesn't do anything that will outright break things. I honestly don't care if it's hosted inside my network or not.

Ubiquiti has a history of poor software releases that break things and now of trying to gloss over a serious security breach. I'm less worried about HPE in that regard.

Re: Ubiquiti all but confirms breach response iniquity

#286
post #48

Earlier quoted context omitted.

During this week I've been playing around with replacing my USG with my existing home server - it already has two NICs - my first thought was to run OPNSense in a VM but nftables on NixOS seems to work well enough - there are a few examples floating online [0,1]. OpenBSD even supports the USG [2] but I couldn't think of much reason to keep the extra hardware. The next thing I want to do is reflash my Unifi APs with O…

> replacing my USG with my existing home server I like this idea too, but would prefer that the router was physically separated and before any hardware that was in the network. Is this a pointless concern?

If you have your router in a separate box then you won't have to take down your whole network if you have to restart your VM host.

Re: Ubiquiti all but confirms breach response iniquity

#287
post #205

Earlier quoted context omitted.

Most of the US leadership and many of the US employees quit in recent years. The CEO wanted to focus on international offices where employees were cheaper. It was backfiring while I was there and I heard it only got worse after I left. Sad situation. I knew a lot of good people there who cared about making good products during the UniFi glory days. Everything collapsed fast. I knew we were in trouble when the CEO's e…

Really sad to see. I still see no realistic alternative for the "distributed decent wifi at a reasonably SMB scale" wireless product though. Miraki I guess is as close as it gets, but then you are locked in 100% cloud and it's certainly not remotely the same price point. I am relegating Unify to manage my APs and (some) switches for ease of use - while I enjoy CLI fun, it gets old doing routine stuff the for the 100t…

OpenWISP has been mentioned elsewhere on this page.

Re: Ubiquiti all but confirms breach response iniquity

#288
post #78
post #51

Earlier quoted context omitted.

It's an interesting idea to have a single pane of glass management experience for OpenWRT - given that all config is under UCI [0] it seems very possible. One of the things on my todo list is to try and get Nix to push config to my Unifi APs when I flash them with OpenWRT. [0] - https://openwrt.org/docs/guide-user/base-system/uci

Take a look at https://openwisp.io/docs/ as it can accomplish this today.

That’s very neat - though I think orthogonal to my Nix plan. Certainly suits anyone that wants to manage multiple APs from the same interface however.

Re: Ubiquiti all but confirms breach response iniquity

#289
post #17
post #6

What I’m curious about is, if I run my own controller on my own hardware, do I need to be concerned about this? I could understand supply chain concerns... I’ve held off updating anything while this plays out. But all these “breach! breach!” stories fail to spell out who is affected and what they need to do.

If you read the original post, the they noticed a breach when someone put an "unknown" VM on their server infrastructure. The attackers also got signing keys for firmware. So even if you run a local controller, I see two very serious vectors: 1. The "Ubiquiti account signin" functionality - you probably had it off, but I'd like a confirmation that it doesn't keep a backdoor open anyway. 2. Having a malicious firmware…

The self-hosted controller UI uses your browser to fetch crap from UI.com. Mine just launched a request to net-fe-static-assets.network-controller.svc.ui.com/videos/empty, which I'm sure is perfectly reasonable...I can think of a thousand legit reasons why my network controller would need to load, erhm, an empty video. sigh I wish I could trust them.

Re: Ubiquiti all but confirms breach response iniquity

#290

Earlier quoted context omitted.

That would be the reverse of the usual strategy, wouldn't it? Most companies seem to try to pin breaches on sophisticated hacker groups backed by nation states. But then, they benefit from the perception of a threat that's impossible to defend from (so there wasn't anything they could do) - whereas Ubiquiti benefits from people thinking the attack was just a small actor that couldn't possibly threaten Ubiquiti's cust…

> nation states Nation state is not a fancy infosec way of saying country

Why don't they say "country"? Or just "nation"?

(Can it really be because "nation state" is more fancy?)

I can understand, though, why they don't say "state" -- maybe that'd sound as if a single state in the US had attacked

Post reply on HN