Live data from Hacker News

Ubiquiti developer charged with extortion, causing 2020 “breach”

krebsonsecurity.com

201–210 of 239 posts

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#201
post #121

Earlier quoted context omitted.

>Also, for some perspective, at that time Ubiquiti kept all the hardware signing keys in a private GitHub repo that every employee had read access to. And they were in plain-text. So... yeah. This is frankly worse than any of this other news. So there's essentially zero trust associated with the code signatures since any employee, past or present, can sign a payload. Wonderful.

I've since heard that the repo has been taken down and all the keys rotated, but just kinda makes you wonder how many APs and switches and cloud keys, etc are still out there using compromised keys. Also, even though they may have had read access, not many knew it existed. But it wasn't super hard to find (I stumbled across it basically). Oh and then there the whole metrics collection debacle, where the controller ba…

> Also, even though they may have had read access, not many knew it existed. But it wasn't super hard to find (I stumbled across it basically).

We didn't have read access until Nick Sharp and his team took over GitHub permissions and gave everyone access. Wonderful security work.

> Oh and then there the whole metrics collection debacle, where the controller basically phoned home about the topology of every network that it managed. Even if you opted out. Opting out just meant they fuzzed your ID so any given record couldn't be linked back to PII. Which may or may not be legal, IANAL.

Nick Sharp was at the core of this too! He built the 'trace' system to collect all of these metrics and had all of these ideas about how to secretly collect the data in ways that would be hard for people to detect.

He pretended to be a principled person who stood for security and privacy, but whenever he saw an opportunity for political gain he abandoned all principles. He was the only person I knew at the company who was enthusiastic about collecting all of that data.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#202

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

You assume anyone except the hacker knew anything about AWS. Our firm subcontracts to other firms. I am among other thing resident Sysadmin which means I get to do everything related to AWS. Out of 6 contracts we had, where firm had their project on aws I got root credentials in 4 cases. out of 4 i only managed to convince 2 to take their account security more seriously and lock things down. What I am trying to say i…

> You assume anyone except the hacker knew anything about AWS.

There were a lot of smart and experienced people at Ubiquiti when I worked there.

Nick Sharp manipulated his way into total control over everything and wouldn't let anyone outside of his isolated team touch it. Nick was hired out of his job at Amazon because he was supposed to be the AWS expert. He used that to lock out anyone but himself and a trusted team.

It didn't matter that others knew better. Nick controlled it.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#203
post #186

Earlier quoted context omitted.

[flagged]

That’s pretty shitty of him. I’m not saying anyone is a saint, only that krebs doxxes people who disagree with him, which can put their lives in direct harm. I’m not any more of a fan of wee ve than you. Also, fuck Nazis.

Weev is blind?

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#204

Earlier quoted context omitted.

You assume anyone except the hacker knew anything about AWS. Our firm subcontracts to other firms. I am among other thing resident Sysadmin which means I get to do everything related to AWS. Out of 6 contracts we had, where firm had their project on aws I got root credentials in 4 cases. out of 4 i only managed to convince 2 to take their account security more seriously and lock things down. What I am trying to say i…

> You assume anyone except the hacker knew anything about AWS. There were a lot of smart and experienced people at Ubiquiti when I worked there. Nick Sharp manipulated his way into total control over everything and wouldn't let anyone outside of his isolated team touch it. Nick was hired out of his job at Amazon because he was supposed to be the AWS expert. He used that to lock out anyone but himself and a trusted te…

> Nick was hired out of his job at Amazon because he was supposed to be the AWS expert.

This always cracked me up. From what I can tell, he was a mid level dev on the Alexa web api team. He knew AWS sure, but he did not have the cred at all to justify the position and responsibility he was given at Ubiquiti.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#205
post #121

Earlier quoted context omitted.

I've since heard that the repo has been taken down and all the keys rotated, but just kinda makes you wonder how many APs and switches and cloud keys, etc are still out there using compromised keys. Also, even though they may have had read access, not many knew it existed. But it wasn't super hard to find (I stumbled across it basically). Oh and then there the whole metrics collection debacle, where the controller ba…

> Also, even though they may have had read access, not many knew it existed. But it wasn't super hard to find (I stumbled across it basically). We didn't have read access until Nick Sharp and his team took over GitHub permissions and gave everyone access. Wonderful security work. > Oh and then there the whole metrics collection debacle, where the controller basically phoned home about the topology of every network th…

Oh god don't remind me about Trace. I had to deal with the Controller side of that and it was a damn nightmare.

He basically dictated that you couldn't use any kind or repo+deployment pipeline except for what his team was building. Which wasn't actually functional for like 8 months. So we never even got a dev or staging tier to test against for months.

And then when I ended up with access to push things along, the actual apps for the trace system we're... not well implemented.

Ugh... I could bitch about this stuff for literal days but I gotta drop my kids off.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#206
post #80

Earlier quoted context omitted.

Hoo boy, this is gonna be a fun one. For reference, I spent a year (mid-2018 to mid-2019) running the UniFi Network team and worked with Nick during that time. > * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for when an AWS root IAM account is logged in or used, this account should be under lock and key and when…

> For reference, I spent a year (mid-2018 to mid-2019) running the UniFi Network team and worked with Nick during that time. Nick's whole strategy was to find a problem, exaggerate it as much as he could get away with, and then offer himself as the hero who would fix it all. He exaggerated or lied about everything he wanted to use for political advantage, right up to the end where he fabricated a hack and used Krebs…

I appreciate the perspective.

If you're telling me I worked there at literally the worst possible time frame, I'd believe it. I may have my experience skewed through the perspective of Nick's influence, but tbh many of my issues were unrelated to him or his sphere of influence.

The C level thing may not have been a "big" mystery, but it was to me, and as somebody who was running the dev of a flagship software product (UniFi) it set off alarm bells that nobody I talked to could explain who was handling the roles of those execs. I'm not exaggerating when I say I effectively got "I dunno" as a response when I inquired, and I dug.

It is good to know, though, that what I experienced wasn't chronic for the entire company's existence.

To clarify on the China thing, I wasn't trying to imply that anything nefarious was actually happening. Just that it warranted some scrutiny when a security focused product was being developed on the Chinese mainland and by a team of Chinese citizens that are subject to CCP laws. Given some of the things that have happened around that country's involvement in tech in recent years, I don't think such scrutiny is unwarranted, especially when the team has a track record of security "goofs".

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#207
If convicted, I hope this guy spends a long time in prison - what an incredible ass.

As a long time user of ubiquiti devices, I’m glad this was the actual story. It actually makes me feel a lot better since this kind of risk is extremely hard to defend against and unrelated to their hardware.

Maybe a good time to buy some 2yr leaps.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#208
post #180

Earlier quoted context omitted.

It was notdan, and he’s quite open about both of the things I mentioned both on Twitter and his blog. He is mentioned in this article.

[flagged]

I don't know anything about the case or the current attitude of the blind neo-Nazi. Depending on the later, it could be very beneficial to see how someone could get sucked into a such mental state. Hearing how such a thing happends might be beneficial for those who are just starting that slide into exremism.

Even if the neo-nazi is still dyed in the wool, I certainly don't think that being curious about that person's perspective justifies being doxed.

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#209

For me a company of their size and, what I would expect, maturity, this new announcement does not satisfy me or provide me much assurance. Consequently I am still happy I have been recommending people against Ubiquiti since the original announcement from Krebs. * Why was it so easy for a lead engineer to get access to a root AWS user without anyone else being notified? I.e. AWS GuardDuty provides FREE alerting for wh…

I've written this before, but someone on HN posted a link on Ubiquiti Glassdoor reviews where multiple people mentioned that the company is hostile to automated testing. Have things changed? If not, why, just why?

Re: Ubiquiti developer charged with extortion, causing 2020 “breach”

#210
post #151

Earlier quoted context omitted.

What does that even mean? Let's say you have a Wireguard configuration, wg0 which runs off ens0. If your wg0 connection dies, for whatever reason (let's say the remote server goes down), your computer falls back to ens0. What does "not having a connection to be maintained" change about this?

Wireguard will keep contacting the remote server. You'd have to delete the wg0 interface or delete the default route for packets to go out via ens0. Wireguard only has "connection" in a sense that it caches some runtime information about the peer's endpoint, but endpoint configuration is static. I guess, too much magic automation on top of this is not the best thing for opsec, including having some daemon that can di…

> You'd have to delete the wg0 interface or delete the default route for packets to go out via ens0

So... You'd have to do work to properly blackhole traffic when wg0 goes down. However long it takes to reconnect, you still will automatically fall back down to ens0 while it's down unless you do something to stop that.

Post reply on HN