Live data from Hacker News

Ubiquiti developer charged with extortion, causing 2020 “breach”

krebsonsecurity.com

141–150 of 239 posts

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#141

The funny thing is that krebsonsecurity.com are the ones that published the false information in the first place. Good summary of the whole saga by Crosstalk youtube channel which covers mostly Ubiquiti: https://www.youtube.com/watch?v=paLm0tP5GbI

Wait. So his big "whistleblower" source for this article in April was actually the hacker? https://krebsonsecurity.com/2021/04/ubiquiti-all-but-confirm... Bad on Krebs for not at least mentioning this.

Not surprised TBH. Brian Krebs has a history of questionable ethical behavior, like doxxing people who leave negative reviews on his book[0].

[0]: https://itwire.com/security/infosec-researchers-slam-ex-wapo...

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#142

Earlier quoted context omitted.

Mikrotik?

If the top result for "Mikrotik configuration" is accurate: https://help.mikrotik.com/docs/display/ROS/First+Time+Config... Then no thanks. I have a finite number of hours on this planet and I have no interest in spending more of them trying to configure network equipment with commands like ``` /ip firewall filter add chain=forward action=fasttrack-connection connection-state=established,related \ comment="fast-track…

> Ubiquiti does a great job of having good defaults out of the box, a straightforward UI, and remote management.

Which UI? The UDM has two. Mobile devices have another. Some features are only available on one of the UIs, and when the feature is available on both, it often behaves differently. Sounds pretty straightforward to me.

I ended up buying a Protectli box (FW6E) with OPNsense preinstalled. It's been fantastic, and blows Unifi out of the water.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#143
post #109

Earlier quoted context omitted.

I’d be willing to bet that for most of the VPNs that are getting advertised by YouTubers (NordVPN, SurfShark, ExpressVPN, PIA, et al) it’s 100% marketing and they don’t actually care whether their “kill switch” works 100% of the time. After all, they are not as trivial to implement as it sounds.

Something I don't understand is that he executed it fairly well... With the exception of using a weak, evidently broken, vpn instead of something like mullvad + tor. If you are going to do something like that (which is already a big "why???"), why put such little effort into your own security?

The suspect allegedly stole gigabytes of data, need bandwidth for that.

Last time I tried to use tor, I was getting like 32 kbit/sec, on top of a symmetric 100 mbit/second internet connection.

That was many years ago but I doubt they fixed the speed, very hard to do without centralized servers.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#144
The indictment:

https://www.justice.gov/usao-sdny/press-release/file/1452706...

Side note: Free suggestion for a new startup. Make indictments pretty! What is it with all these fonts? Looks they really type this on a typewriter. Are all court clerks just frustrated novelists?

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#145
post #115

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

Those are good points, but Ubiquiti lost me at centralized, private management of my network devices. Someone might, you know, abuse that; plus, I'm not in control of what's on my device.

It's mostly meant for enterprise use cases. Think something like hotel WiFi. Which is easier to secure? The cloud accounts, or physical access to the several hundred devices in the hotel? Even in private buildings, if you're deploying thousands of access points, you may not trust the minimum wage third party contractors doing all the installations and don't want on-device configuration to be possible.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#146
post #65
post #61

Earlier quoted context omitted.

So few people are actually using Tor that correlation-based traffic analysis has very good odds of revealing identities: get the list of employees, pick out those whose connections have accessed Tor at the time of attacks, and you'll have a very short list of suspects.

where do you get tor usage data? The only time I heard of it being used was when someone used tor on some university's wifi network to send a bomb threat. In that case it would be fairly easy to get the data, but if it's just a random guy using his home internet connection, can you get their ISP to cooperate? do they even keep such data around?

Getting the metadata is not a problem if you're the FBI (like in the article). You can get it directly from ISPs, or collect it yourself 24/7/365 in bulk and search it when needed.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#147
post #144

The indictment: https://www.justice.gov/usao-sdny/press-release/file/1452706... Side note: Free suggestion for a new startup. Make indictments pretty! What is it with all these fonts? Looks they really type this on a typewriter. Are all court clerks just frustrated novelists?

I'm waiting for them to follow the footsteps of recipe writers. "It was a frosty December morning, much like the ones I spent with my grandfather up north in my childhood" Just show me the deposition!

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#148
post #115

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

Those are good points, but Ubiquiti lost me at centralized, private management of my network devices. Someone might, you know, abuse that; plus, I'm not in control of what's on my device.

The problem is that they set a bar there. There is a gulf between consumer and enterprise APs that is full of only Unifi-esque gear. “Cloud management” is an OOB requirement and primary use case for SOHO gear these days. It’s a fleet management issue, just wish it could be done with proper config management and not phoning home. But they’re selling to small shops doing IT for 10s of law firms or doctor’s offices.

I’d never use Ubiquiti’s switches, routers, etc. There are great alternatives there. But when I went to replace my APs earlier this year I still could not find anything less shady that still did what I needed.

Is there an alternative that does PoE w/ multiple APs that hand-off well? And decent hardware…

TP-Link has a similar offering but with similar problems.

OpenWRT on [consumer gear] is not an answer here. More effort goes into the plastic than the hardware. Never dealing with cheap NICs, bad SoCs, inadequate memory, garbage drivers, etc. again.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#149
post #144

The indictment: https://www.justice.gov/usao-sdny/press-release/file/1452706... Side note: Free suggestion for a new startup. Make indictments pretty! What is it with all these fonts? Looks they really type this on a typewriter. Are all court clerks just frustrated novelists?

>Free suggestion for a new startup.

Not sure anything more than a browser extension would be needed.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#150
post #115

Earlier quoted context omitted.

Those are good points, but Ubiquiti lost me at centralized, private management of my network devices. Someone might, you know, abuse that; plus, I'm not in control of what's on my device.

You don't have to use their cloud services, everything can be managed 100% locally. With that said I'm moving away from Ubiquity after years of broken pointless updates, years long outstanding bugs, and after this thread obvious massive lacking security.

They’ve pretty much broken that in practice since the last major firmware update.

I just only turn my controller on when I’m working now and occasionally have to re-adopt.

And alternatives likely have similar issues. It’s what naturally occurs when small businesses get large, and especially when companies go from embedded to SaaS development.

Post reply on HN