Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

291–300 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#291

Ubiquiti should really stop making cloud logins mandatory. The latest stuff (UDM/UDM Pro, Cloud Key G2) must be connected to their cloud at installation time. Remote access can be turned off but an admin account connected to their cloud remains. Without those ties to their infrastructure, this breach would not be as severe. It would just cause an attacker to see what I've bought from them, nothing else. I'm glad I ca…

I worked there and I didn't even understand why we had to force cloud logins on Dream Machine. In the early days we were all about letting people run their own controller hardware and not requiring cloud logins. No one could ever tell us why we had to force everyone to the cloud. It was a mandate from above

Thanks for that insight!

I guess it's for the usual reasons. Telemetry / product improvement, and also more marketing data. Data is the new gold :)

Re: Ubiquiti all but confirms breach response iniquity

#292
post #12

So this week, I have gone from having a single little USG and a massive order planned for loads of kit to stopping them automatically updating the firmware and dropping that order. Extremely annoying, but not as annoying as if this had happened in a couple of weeks.

So what are vendor are you changing to now?

None! Going to keep my jerry-rigged-Heath-Robinson networks with the existing mesh and switches until things resolve to a satisfactory juncture.

Re: Ubiquiti all but confirms breach response iniquity

#293
post #235

Earlier quoted context omitted.

The key is “for each packet”, because it’s bucket based it will entirely skip evaluation for packets that do not match. This is due to how the rule set is compiled, but I can see how it could be confusing if you’re used to iptables and only think in those terms. I posted the architectural diagrams of both in another comment on this thread yesterday, I think you missed that.

>The key is “for each packet”, because it’s bucket based it will entirely skip evaluation for packets that do not match. That is how it works in nftables. >but I can see how it could be confusing if you’re used to iptables and only think in those terms. Considering you're misunderstanding some basics about nftables and iptables here, I think you need to look in the mirror. >I posted the architectural diagrams of both…

[deleted]

Re: Ubiquiti all but confirms breach response iniquity

#294
post #176

Earlier quoted context omitted.

I don't use a UI.com account to connect to the Unifi controller I host (as I don't need their inconsistently working NAT traversal to get to my controller), hopefully the networks I support are safe due to not being entangled with Ubiquiti's cloud infrastructure. Anyone who is forced to get a UI.com account (eg: UniFi Dream Machine and UDM-Pro owners) should change their credentials and do a factory reset on their ro…

> do a factory reset on their routers and Access Points ASAP This is a miserable user experience. If you do a reset and don’t know the SSH password on APs or cameras you get to spend a hellish few hours crawling though ceiling insulation, climbing ladders and physically resetting devices. It’s so shit. I’ve just done it, but not due to security concerns, but instead because of a UDM-P crapping out randomly.

This is why I like having the controller in a virtual machine offsite. Factory resetting the router and pairing it to the same site in the separate controller gets me back to the same exact place I expect to be.

With the UDM series, the integrated controller ensures you lose everything if you have to factory reset, site to site VPNs have to be manually configured, and numerous other minor annoyances crop up (like UI.com not always being able to connect to the controller).

Re: Ubiquiti all but confirms breach response iniquity

#295
post #211

I can believe that they do not keep logs of the database access. As brain dead as it sounds. I have been in the position of implementing a client on a API I do not control. The owners of the servers (colleagues but in a different country) do not seem to know what logs are. We get random failures from the server. I can pin down to the second when they occur (not closer because of network lag). I suspect that the serve…

Logs are typically off by default in most Enterprise software, or goes nowhere by default which is basically the same thing. Logs cost money to both collect and store. Not everyone is cheerfully burning through VC capital. Some people have budgets. Speaking of log collection, simply dumping the logs into a central repository is the same as taking the garbage to the landfill. Collecting trash just results in a big col…

It is untrue that logs are trash. I gag at the comparison.

If the would just look at logs they could answer so many questions that are costing a lot of money.

I am used to a Unix world, with logs as text files. They take up very little room, and it is easy to through out old ones (keeping logs for ever is foolish for a lot of reasons).

I am staggered that "I turned logging on extensively for a recent Azure project. Some logs cost more than the service they were monitoring." There is no way that this can be true unless there is some very very bad craziness going on. A real mindfuck

Even a hours worth of logs would of by now saved at least a week of developer time for the people I work with (my time, they pay for).

"Logs are typically off by default in most Enterprise software" That is probably true, I have no reason to doubt you and it fits with the other things I have witnessed, but there is a better way.

Re: Ubiquiti all but confirms breach response iniquity

#296

Earlier quoted context omitted.

> nation states Nation state is not a fancy infosec way of saying country

Why don't they say "country"? Or just "nation"? (Can it really be because "nation state" is more fancy?) I can understand, though, why they don't say "state" -- maybe that'd sound as if a single state in the US had attacked

I think this derives from “state-sponsored”. “The state” has a distinct meaning from country or nation which I think is important to capture too.

I think your point about confusion with constituent states is spot on though

Re: Ubiquiti all but confirms breach response iniquity

#297
post #248

Earlier quoted context omitted.

Mikrotik have not been able to keep up with the latest, or previous to latest wifi standards, seems like it's become too complex

Skipping wifi 6 seems like a smart move, with 6E on the horizon. It includes all the things that should have been part of the standard in the first place, so why get your hardware certified for 6, if you have to get it recertified for 6E anyway shortly after? 6 doesn't add very much over 5 in real world setups, very few devices even support 802.11ax yet, and the bleeding edge has never been Mikrotik's target segment.…

According to people in their forums they don't support all the ac features either. Something to research if you're thinking of switching anyway.

Re: Ubiquiti all but confirms breach response iniquity

#298
post #174

Earlier quoted context omitted.

The UDM and UDM-Pro force you to set up a UI.com account, and cannot be used with external Unifi controllers like one you might run on a server, PC or cloud key (Ubiquiti's management software on a Power over Ethernet powered dongle, does not require a UI.com account).

The UDM and UDM Pro are the controller, and you can disable all of the cloud nonsense after initial setup.

Wow, that sucks. So you HAVE to create a cloud account to be able to disable it later?

Re: Ubiquiti all but confirms breach response iniquity

#299
post #187
post #146

Earlier quoted context omitted.

I have said this before, but would like to reiterate that I am never touching or buying anything branded as Ubiquiti or owned by Robert Pera. This hardware is far from cheap and consumers are literally paying for adware/spyware. I really hope Ubiquiti stock takes a nosedive over the next year.

How is it "adware/spyware"?

Might be referring to this https://news.ycombinator.com/item?id=26628198

Re: Ubiquiti all but confirms breach response iniquity

#300
post #297

Earlier quoted context omitted.

Skipping wifi 6 seems like a smart move, with 6E on the horizon. It includes all the things that should have been part of the standard in the first place, so why get your hardware certified for 6, if you have to get it recertified for 6E anyway shortly after? 6 doesn't add very much over 5 in real world setups, very few devices even support 802.11ax yet, and the bleeding edge has never been Mikrotik's target segment.…

According to people in their forums they don't support all the ac features either. Something to research if you're thinking of switching anyway.

As far as I know, that concerns 802.11k/v/r, MU-MIMO and beam forming, which many other 802.11ac devices also don't support, so it doesn't bother me. Then again, I'm not running an enterprise setup and I've never been one to meticulously make sure I get every single feature in the world on a spec sheet.

The hAP AC² serves my home networking needs quite well, with an additional AP to better cover the whole apartment.

Post reply on HN