Live data from Hacker News

Ubiquiti developer charged with extortion, causing 2020 “breach”

krebsonsecurity.com

161–170 of 239 posts

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#161

So... do the ubiquity things work again without being tied to their 'cloud'? Fake vulnerability or not, this is the worst part about their devices these days. Speaking of which, are there any semi-pro APs that still work without going through the vendor's servers?

> So... do the ubiquity things work again without being tied to their 'cloud'?

Ubiquity works without their "cloud" if you install their management software on your computer (I use a VM on my server). In my experience, you don't even have to run their management software once you have the network configured. If you are paranoid, install their s/w on a VM, set up your network, and then shut down the VM. You should bring up the management VM periodically for software updates, but otherwise it runs fine.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#162

Earlier quoted context omitted.

Wait. So his big "whistleblower" source for this article in April was actually the hacker? https://krebsonsecurity.com/2021/04/ubiquiti-all-but-confirm... Bad on Krebs for not at least mentioning this.

Not surprised TBH. Brian Krebs has a history of questionable ethical behavior, like doxxing people who leave negative reviews on his book[0]. [0]: https://itwire.com/security/infosec-researchers-slam-ex-wapo...

ITWire is not a credible news source. The site, and especially Varghese, often writes tabloid pieces that are just character attacks.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#163
post #156

Earlier quoted context omitted.

Not surprised TBH. Brian Krebs has a history of questionable ethical behavior, like doxxing people who leave negative reviews on his book[0]. [0]: https://itwire.com/security/infosec-researchers-slam-ex-wapo...

Is identifying a real person by their internet pseudonym really doxxing?

Krebbs doxxed one of my friends who happens to be a gay hacker in a country where both being gay and being a hacker are illegal. Krebbs doesn’t take kindly to any sort of bad reviews or even the hint that he’s not perfect FYI.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#164
post #162

Earlier quoted context omitted.

Not surprised TBH. Brian Krebs has a history of questionable ethical behavior, like doxxing people who leave negative reviews on his book[0]. [0]: https://itwire.com/security/infosec-researchers-slam-ex-wapo...

ITWire is not a credible news source. The site, and especially Varghese, often writes tabloid pieces that are just character attacks.

I don’t know anything about the outlet but that story looks pretty fine? It links to its sources at least, which is better than most tabloid pieces

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#165
post #161

So... do the ubiquity things work again without being tied to their 'cloud'? Fake vulnerability or not, this is the worst part about their devices these days. Speaking of which, are there any semi-pro APs that still work without going through the vendor's servers?

> So... do the ubiquity things work again without being tied to their 'cloud'? Ubiquity works without their "cloud" if you install their management software on your computer (I use a VM on my server). In my experience, you don't even have to run their management software once you have the network configured. If you are paranoid, install their s/w on a VM, set up your network, and then shut down the VM. You should bri…

Note that this also has the chance to be a security issue, the management software can run nightly software updates on your AP's, possibly closing flaws before your "periodical" manual efforts.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#166
post #14

> Investigators say they were able to tie the downloads to Sharp and his work-issued laptop because his Internet connection briefly failed on several occasions while he was downloading the Ubiquiti data. Those outages were enough to prevent Sharp’s Surfshark VPN connection from functioning properly — thus exposing his Internet address as the source of the downloads. Not the first time I’ve read about a VPN unable to…

Wonder if tor browser would've been a better choice

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#168

Earlier quoted context omitted.

If the top result for "Mikrotik configuration" is accurate: https://help.mikrotik.com/docs/display/ROS/First+Time+Config... Then no thanks. I have a finite number of hours on this planet and I have no interest in spending more of them trying to configure network equipment with commands like ``` /ip firewall filter add chain=forward action=fasttrack-connection connection-state=established,related \ comment="fast-track…

> Ubiquiti does a great job of having good defaults out of the box, a straightforward UI, and remote management. Which UI? The UDM has two. Mobile devices have another. Some features are only available on one of the UIs, and when the feature is available on both, it often behaves differently. Sounds pretty straightforward to me. I ended up buying a Protectli box (FW6E) with OPNsense preinstalled. It's been fantastic,…

Thanks for the suggestion. Do you have any recommendations like Protectli, but for for the wireless AP?

The fragmentation about Ubiquiti devices drives me crazy - I have the "wrong" consumer wifi AP or the "wrong" (pro)consumer router (take your pick), so half of the wifi AP functionality is disabled - but for no reasonable reason - just they have two (more?) product lines that don't work together and it's hard to realize until you get the products. Overall I've been pretty disappointed by my Ubiquiti hardware - I feel like it was advertised as higher performance and better functionality than it ended up being.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#169

Earlier quoted context omitted.

From my cursory reading of Brian Krebs' blog, most posts seem written by a ghostwriter.

what makes you think that?

Krebs uses the word 'I' a lot, but the ghostwriter(s) do not.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#170

Earlier quoted context omitted.

Wait. So his big "whistleblower" source for this article in April was actually the hacker? https://krebsonsecurity.com/2021/04/ubiquiti-all-but-confirm... Bad on Krebs for not at least mentioning this.

Not surprised TBH. Brian Krebs has a history of questionable ethical behavior, like doxxing people who leave negative reviews on his book[0]. [0]: https://itwire.com/security/infosec-researchers-slam-ex-wapo...

Same happened with Crosstalk in a similar fashion. Commented on a video about a product similar to what he was describing and he removed the comment. It’s all about them and the products they want to sell. Not as open/transparent as one would think.
Post reply on HN