Live data from Hacker News

Ubiquiti developer charged with extortion, causing 2020 “breach”

krebsonsecurity.com

91–100 of 239 posts

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#91
post #22

Earlier quoted context omitted.

Most come with a killswitch, so if it wonks out you can't access the net.

Are killswitches actually fast enough? Serious question, I don’t know much/anything about networking internals. I never trust killswitches and when I want to ensure I don’t leak anything, I bind to the VPN interface instead, but I don’t know if that actually gives better security?

I've never used surfshark myself but they advertise as having a killswitch inlcluded in their VPN [0] so it sounds like in this case, it definitely failed.

[0] https://surfshark.com/vpn#vpn-page-essentials

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#92

Also 25 btc ransom. That's like 50k usd for such a big risk. Sort of like how they show a person trying to make enough to pay some medical bills or something.

>Also 25 btc ransom. That's like 50k usd Uh, you might want to take another look at the current price of bitcoin. Even at the time, that was around 750k to 1mm USD.

the total amount he was asking for was actually 50 BTC, so around 2m USD.

25 for the data not be release and 25 for him to tell them about the "backdoor" he used to access their system.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#93
post #67
post #58

Earlier quoted context omitted.

Yeah and I don’t trust that a vpn would really care for my $5 a month or whatever when faced with state actions that if it came to that.

At least one VPN provider did just that https://torrentfreak.com/private-internet-access-no-logging-...

This was before they got a new owner.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#94

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

> * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for when an AWS root IAM account is logged in or used, this account should be under lock and key and when used, confirmed and audited by relevant persons or teams.

I had never heard of GuardDuty so I got curious. It doesn't seem like there's a free tier available for it: https://aws.amazon.com/guardduty/pricing/ In fact at larger scales it seems pretty expensive even.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#95
post #45

Earlier quoted context omitted.

Accounts and actions like this are easily managed in AWS GuardDuty since they were so foreign from the user benchmarks. Outside of the normal security standards you'd expect of next level monitoring from companies such as CrowdStrike. It took Ubiquiti weeks to notice these issues and he used the AWS root account, this account should be actively secured and alerted for abuse using AWS GuardDuty or similar. I've made m…

But who configures AWS GuardDuty and who does it report to? Presumably the root account owner? In that case, wouldn't that be the cloud lead?

It reports to anyone you want, typically though you would point it to an SNS topic which is ingested by any other service, group or end point you wish.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#96

Earlier quoted context omitted.

> it somewhat repairs my view of Ubiquiti's brand It shouldn't. Everything I read still speaks to their toxic culture and their inability to focus on a product before releasing 10 new ones. I buy their switches and APs, but their routers are still garbage.

What's the better set-it-and-forget-it alternative? The Dream Machine Pro has been truly wonderful for me. I'm not interested in the equivalent of "a totally customizable Linux box running pfSense".

Mikrotik?

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#97

> Investigators say they were able to [subvert the attacker’s VPN] because his Internet connection briefly failed on several occasions while he was downloading the Ubiquiti data. Those outages were enough to expose his real address. Ahem, how convenient! Call me a paranoid Internet-forum dwelling cyber-loon, but that smells an awful lot like parallel construction. When the authorities log the start and end times of e…

That doesn't sound paranoid to me, especially as the US government has relied on the old "he made a mistake with his VPN" explanation before (against a target that is much better funded):

https://www.wired.com/story/guccifer-elite-hackers-mistakes/

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#98
post #79

Earlier quoted context omitted.

Wait. So his big "whistleblower" source for this article in April was actually the hacker? https://krebsonsecurity.com/2021/04/ubiquiti-all-but-confirm... Bad on Krebs for not at least mentioning this.

He obv didnt know

He can still post a retraction/update on the original article.

I mean, he added an update already from later in the month, and he clearly knows now.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#99
post #72
post #69

Earlier quoted context omitted.

Is there a good reason for that to not be the default when using a VPN? At the very least it should be easy to configure. I remember when I tried using a VPN on Ubuntu a bunch of years ago, I had to set up iptables rules even though the VPN connection could be configured through the network manager GUI.

With wireguard since there is no "connection" to be maintained, you could argue this is a non-issue.

But Wireguard itself relies on an active internet connection, which needs to still be set up to not fall back on in case the wg connection deactivates.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#100
post #80

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

Hoo boy, this is gonna be a fun one. For reference, I spent a year (mid-2018 to mid-2019) running the UniFi Network team and worked with Nick during that time. > * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for when an AWS root IAM account is logged in or used, this account should be under lock and key and when…

This is all pretty damning. What would you use at home instead?
Post reply on HN