Live data from Hacker News

Ubiquiti developer charged with extortion, causing 2020 “breach”

krebsonsecurity.com

191–200 of 239 posts

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#191
post #115

Earlier quoted context omitted.

Those are good points, but Ubiquiti lost me at centralized, private management of my network devices. Someone might, you know, abuse that; plus, I'm not in control of what's on my device.

It's mostly meant for enterprise use cases. Think something like hotel WiFi. Which is easier to secure? The cloud accounts, or physical access to the several hundred devices in the hotel? Even in private buildings, if you're deploying thousands of access points, you may not trust the minimum wage third party contractors doing all the installations and don't want on-device configuration to be possible.

That's a good point.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#192
post #14

> Investigators say they were able to tie the downloads to Sharp and his work-issued laptop because his Internet connection briefly failed on several occasions while he was downloading the Ubiquiti data. Those outages were enough to prevent Sharp’s Surfshark VPN connection from functioning properly — thus exposing his Internet address as the source of the downloads. Not the first time I’ve read about a VPN unable to…

Or he didn't screw it up and that's the FBI's standard excuse.

My first thought. They could have used some undisclosed (illegal) tools and methods to find him, and then cooked up this story to explain it.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#193

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

Yes and all the things. But Nick was the guy responsible for all these things.

You really cannot have good security if the goal of your “cloud lead” is to ransomware you.

So yes - they did not have good security so they hired him to fix it :)

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#194
post #188

If anyone is looking for the alternative to Ubiquiti since their fall from grace in recent years, I've found it to be HP Aruba. I always use more open source stuff for personal projects, but Aruba Instant On is what I commonly recommend/integrate for other people, whereas it used to be Ubiquiti. Solid design across hardware and software. It finds that unique balance in quality/usability between cheap/unreliable, and…

Does Aruba Instant On have anything comparable to the UniFi Dream Machine Pro?

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#195
post #188

If anyone is looking for the alternative to Ubiquiti since their fall from grace in recent years, I've found it to be HP Aruba. I always use more open source stuff for personal projects, but Aruba Instant On is what I commonly recommend/integrate for other people, whereas it used to be Ubiquiti. Solid design across hardware and software. It finds that unique balance in quality/usability between cheap/unreliable, and…

Does Aruba Instant On have anything comparable to the UniFi Dream Machine Pro?

Most pro's I watch (like: Lawrence Systems) don't like the UDM all that much due to lack of features. While you get a single pane-of-glass for managing the Wifi and Router, having some other product for a router tends to be better (PFSense or OpnSense). I've been running both for for 6+ years now and like it.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#196

Earlier quoted context omitted.

Mikrotik?

If the top result for "Mikrotik configuration" is accurate: https://help.mikrotik.com/docs/display/ROS/First+Time+Config... Then no thanks. I have a finite number of hours on this planet and I have no interest in spending more of them trying to configure network equipment with commands like ``` /ip firewall filter add chain=forward action=fasttrack-connection connection-state=established,related \ comment="fast-track…

I was mostly trolling to see if anyone would jump in with an actual alternative because I also wanted to know. I used to buy ubiquity pcie radios to use in mikrotik boards before ubiquity came out with their own complete devices.

Although There is a web ui for mikrotik too, ubiquity’s was definitely slicker.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#197
post #195

Earlier quoted context omitted.

Does Aruba Instant On have anything comparable to the UniFi Dream Machine Pro?

Most pro's I watch (like: Lawrence Systems) don't like the UDM all that much due to lack of features. While you get a single pane-of-glass for managing the Wifi and Router, having some other product for a router tends to be better (PFSense or OpnSense). I've been running both for for 6+ years now and like it.

The only thing I've ever wished the UDM could do was change it's WAN MAC address, because I wanted to keep the same IP I'd had for years when I got it. No particular reason other than sheer nerdiness, but I got over it.

Other than that, I've never wanted it to do something that it can't do.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#198

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

> Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified?

Oh my sweet summer child. You haven't worked in large organizations with thousands of employees before, have you? Surely not if you think this is "Security 101".

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#199
post #80

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

Hoo boy, this is gonna be a fun one. For reference, I spent a year (mid-2018 to mid-2019) running the UniFi Network team and worked with Nick during that time. > * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for when an AWS root IAM account is logged in or used, this account should be under lock and key and when…

> Ubiquiti kept all the hardware signing keys in a private GitHub repo that every employee had read access to

This right here is why I'll never use Ubiquiti gear. These devices are so obviously backdoored and like swiss cheese, they offer the complete opposite of security. Thanks for sharing the true facts.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#200
post #80

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

Hoo boy, this is gonna be a fun one. For reference, I spent a year (mid-2018 to mid-2019) running the UniFi Network team and worked with Nick during that time. > * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for when an AWS root IAM account is logged in or used, this account should be under lock and key and when…

> For reference, I spent a year (mid-2018 to mid-2019) running the UniFi Network team and worked with Nick during that time.

Nick's whole strategy was to find a problem, exaggerate it as much as he could get away with, and then offer himself as the hero who would fix it all.

He exaggerated or lied about everything he wanted to use for political advantage, right up to the end where he fabricated a hack and used Krebs to exaggerate it as much as possible for his own personal profit.

You have to realize he did the same thing during his time at Ubiquiti: Found problems he could use for political advantage, exaggerated them as much as he could get away with, and then amplified his lies until they were gospel. A lot of what you're saying has some roots in truth, but I can tell you have the exaggerated Nick Sharp version of events.

> There was Robert.... and then nobody knows. I asked repeatedly why we didn't have a CTO, or a COO, or a CFO, or CMO or ANYTHING and I got nothing but shrugs and "idunno" as a response for the whole year I was there.

This wasn't some big mystery. Everyone knew that Robert ran everything as CEO and the legal, marketing, and other teams operated out of the New York office.

> Nick came in and started putting "proper" AWS structure and security in place, primarily by scaring Robert (the CEO) into giving him the keys to the castle

Nick was hired specifically to run AWS. That was his job from the beginning. The old cloud team quit and Nick was recruited from his job at Amazon because supposedly he was an AWS expert.

The incident where he scared the CEO was the first of his political games to exaggerate or fabricate security incidents for political gain.

> So why wasn't anybody else notified? Simple. Because he was basically "god". If anybody was gonna be notified, it would've been Nick. He was the top of the totem pole company-wide when it came to AWS.

Yes, this. All of these news stories are missing the point that Nick was the cloud lead. You don't have to believe anonymous commenters. His LinkedIn profile will confirm it. He was recruited out of Amazon to lead the cloud efforts, but he was in over his head and had severe personal issues.

> at that time Ubiquiti kept all the hardware signing keys in a private GitHub repo that every employee had read access to.

This is another Nick exaggeration. It's true that older devices had hardware signing keys stored in a Git repo before the system was updated and keys rotated. However, those old keys were only accessible by a few people until Nick and his team took over GitHub and restructured permissions with the web portal they built themselves. In the process they made too many repos accessible to too many people.

> To keep with the metaphor, Ubiquiti couldn't even get Pre-school level security in place, much less 101. I have no idea how something even more massive hasn't happened yet. Must be dumb luck.

Ubiquiti's overall structure is far from perfect, but you were only there during the Nick Sharp era. Ubiquiti had a lot of people who took security and proper practices very seriously before Nick Sharp took over everything, but it was also a distributed company with a lot of isolated divisions. Nick Sharp got into power by taking the worst and oldest parts of the company and convincing people that everything was equally bad and that only he could fix it. If you got your security information from Nick Sharp, you'd think that Nick is the only person who can do anything properly at the company.

> Speaking of, by the time I left the company, the team that was handling the door entry-way systems (UniFi "Access" I guess) had been caught with numerous security issues, not the least of which was logging user credentials in plain text (not just storing, but logging, in response to authentication events). They were also based in China and subject to Chinese laws around government access, so take that how you will.

I also heard that, but I think it was just incompetence on their part. Nick was pushing the conspiracy that they were doing something with the Chinese government, but it doesn't follow that they'd do it by sending the data to AWS servers under his control. I think they just made a sloppy prototype to impress the CEO and got caught doing dumb stuff. I do blame the company for not cutting that team off, though. They had no idea what they were doing other than their ability to put together quick prototypes to impress the CEO.

Post reply on HN