Live data from Hacker News

Ubiquiti developer charged with extortion, causing 2020 “breach”

krebsonsecurity.com

71–80 of 239 posts

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#71

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

> Most of these settings can be set and managed from AWS Organisations for free, and backed up with alarming and alerts for Guard Duty trivially.

Makes me wonder, why are they even settings? Why aren't they just always on?

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#72
post #69
post #46

Earlier quoted context omitted.

Proper opsec is you blackhole all traffic when the vpn isn’t active.

Is there a good reason for that to not be the default when using a VPN? At the very least it should be easy to configure. I remember when I tried using a VPN on Ubuntu a bunch of years ago, I had to set up iptables rules even though the VPN connection could be configured through the network manager GUI.

With wireguard since there is no "connection" to be maintained, you could argue this is a non-issue.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#75

Also 25 btc ransom. That's like 50k usd for such a big risk. Sort of like how they show a person trying to make enough to pay some medical bills or something.

>Also 25 btc ransom. That's like 50k usd

Uh, you might want to take another look at the current price of bitcoin. Even at the time, that was around 750k to 1mm USD.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#76

Hopefully this gets upvoted more but it somewhat repairs my view of Ubiquiti's brand now that more details have come out about what actually happened. I hope the courts will determine the full extent of the truth

> it somewhat repairs my view of Ubiquiti's brand It shouldn't. Everything I read still speaks to their toxic culture and their inability to focus on a product before releasing 10 new ones. I buy their switches and APs, but their routers are still garbage.

What's the better set-it-and-forget-it alternative? The Dream Machine Pro has been truly wonderful for me. I'm not interested in the equivalent of "a totally customizable Linux box running pfSense".

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#77
post #68
post #3

Earlier quoted context omitted.

Aren't they still serial and uncaring GPL violators?

Source for this?

Latest I can find is this thread: https://news.ycombinator.com/item?id=21450944

I’m not sure if it’s still ongoing, that’s why I asked if it was.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#78

The funny thing is that krebsonsecurity.com are the ones that published the false information in the first place. Good summary of the whole saga by Crosstalk youtube channel which covers mostly Ubiquiti: https://www.youtube.com/watch?v=paLm0tP5GbI

Wait. So his big "whistleblower" source for this article in April was actually the hacker? https://krebsonsecurity.com/2021/04/ubiquiti-all-but-confirm... Bad on Krebs for not at least mentioning this.

They should have definitely acknowledged they covered this before. But also to be fair, quoting the article the reputation damage was done: “Following the publication of these articles, between Tuesday, March 30, 2021 and Wednesday March 31”.

And the Krebs article was on April 4th. It seems BleepingComputer broke the story and Krebs just re-reported the news.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#79

The funny thing is that krebsonsecurity.com are the ones that published the false information in the first place. Good summary of the whole saga by Crosstalk youtube channel which covers mostly Ubiquiti: https://www.youtube.com/watch?v=paLm0tP5GbI

Wait. So his big "whistleblower" source for this article in April was actually the hacker? https://krebsonsecurity.com/2021/04/ubiquiti-all-but-confirm... Bad on Krebs for not at least mentioning this.

He obv didnt know

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#80

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

Hoo boy, this is gonna be a fun one. For reference, I spent a year (mid-2018 to mid-2019) running the UniFi Network team and worked with Nick during that time.

> * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for when an AWS root IAM account is logged in or used, this account should be under lock and key and when used, confirmed and audited by relevant persons or teams.

The "Cloud Lead" that Nick took over from gave zero fucks. He ran all the AWS stuff for Ubiquiti under his personal AWS account. Nick came in and started putting "proper" AWS structure and security in place, primarily by scaring Robert (the CEO) into giving him the keys to the castle (my own personal opinion of Robert is... not the greatest).

One thing to understand about Ubiquiti (at least during those times) is that the company had zero C-level execs. There was Robert.... and then nobody knows. I asked repeatedly why we didn't have a CTO, or a COO, or a CFO, or CMO or ANYTHING and I got nothing but shrugs and "idunno" as a response for the whole year I was there.

So when Nick came in, a very... let's just say "forceful" personality, he immediately won over Robert and ended up with carte blanche over pretty much all of Ubiquiti's cloud accounts. Which were basically... everything. All the UniFi Network services, UniFi Protect services, you name it. If it was connected to the cloud in any way, Nick had access to it.

So why wasn't anybody else notified? Simple. Because he was basically "god". If anybody was gonna be notified, it would've been Nick. He was the top of the totem pole company-wide when it came to AWS.

Also, for some perspective, at that time Ubiquiti kept all the hardware signing keys in a private GitHub repo that every employee had read access to. And they were in plain-text. So... yeah.

> * Furthermore on the root account being easily accessed, the root account in the companies I've worked at had MFA enabled, and the QR code is locked in a safe only accessible by two people agreeing it needs to be accessed in a break glass situation, where warranted.

See above for the quality of security processes and practices this company had in place.

> * Why was he also able to delete critical CloudTrail logs and reduce their retention to 1 day? I.e. These logs should be in a S3 bucket or other environment where such changes cannot be made. Alternatively, they should be shipped to a redundant service that manages this risk to prevent data deletion

See above. (re: "god") Nick answered only to Robert. And he'd already successfully hoodwinked him. He could do whatever he wanted. Eventually he fell from Robert's good graces, but seeing as Ubiquiti as a company didn't really have a ton of checks and balances, he kept his god-level access far longer than he should've.

> * Why did Ubiquti not announce they were compromised sooner? The hack started in early December, Ubiquiti noticed the compromise on Dec. 28. Ubiquiti told the market on January 11th. Is that a satisfactory turn around? Giving them some credit for the XMas break I'll say this partially understandable.

Simple. Fear of share price falling. I was constantly given this as a reason we couldn't be transparent. Not by Robert, nor where he could hear. But it was pretty much well known that the company kept shit quiet for fear of the share price dipping.

> All the AWS configuration I'm speaking of above, I would describe as Security 101.

To keep with the metaphor, Ubiquiti couldn't even get Pre-school level security in place, much less 101. I have no idea how something even more massive hasn't happened yet. Must be dumb luck.

Speaking of, by the time I left the company, the team that was handling the door entry-way systems (UniFi "Access" I guess) had been caught with numerous security issues, not the least of which was logging user credentials in plain text (not just storing, but logging, in response to authentication events). They were also based in China and subject to Chinese laws around government access, so take that how you will.

And that doesn't really even cover most of it. That year took a toll on my physical, mental, and emotional health, not to mention put a crazy strain on my marriage. I'd rather honestly forget it, but the schadenfreude of what's going on is too delicious to ignore.

Post reply on HN