Live data from Hacker News

Final thoughts on Ubiquiti

krebsonsecurity.com

101–110 of 238 posts

Re: Final thoughts on Ubiquiti

#101

You guys are thinking about this in a very cloudy kind of way. Assuming that Ubiquiti was being blackmailed, they have a security problem in who they hire (Who held user data for ransom). Assuming they were not being blackmailed, but had a security hole in their software, Ubiquiti has a security problem. Krebs reporting comes from a potential conflict of interest in that the person who might have been trying to black…

Kreb's article specifically alleged malfeasance on Ubiquiti's part - that they were deliberately covering up a huge data breach.

This turned out to be untrue on three levels: 1) There was no cover-up. Ubiquiti disclosed the attack, and was working with the FBI, working to identify what had happened, and in fact where already onto Sharp as a insider attack. 2) There was no large scale data breach. 3) The claim that there was a huge cover up was part of a extortion scheme, that Krebs was (unwittingly) assisting in.

Yes, this is a standard insider attack - and Ubiquti's security needed to be significantly better - but it doesn't change the fact that Brian Krebs reported false information - including information that he should have been in a position to know was untrue at the very least in the second article, if not the first.

Ironically enough, the person at Ubiquiti that introduced the wider GITHUB access to production secrets and new policies that allowed Nick Sharp to get production access was - according to former Ubiquiti employees - Nick Sharp.

Who watches the watchers?

Re: Final thoughts on Ubiquiti

#102
post #32

Before people jump on this with super negativity... mistakes happen. What is Krebs' false positive rate? I think low enough that a simple, clear explanation of why it happened is sufficient. There's no weasel words or evasion here - he owns up to the error, apologizes to affected parties, and retracts all original posts. It's true that his reporting probably caused stress for Ubiquity. I'm curious what people think i…

He has a history of doxxing people who have nothing to do with his pieces so yeah excuse my negativity.

IIRC, he never even apologised for it - just straight up said nothing, like he was pretending it never happened. I haven't followed Krebs' articles since then, he totally lost my trust.

Re: Final thoughts on Ubiquiti

#103

You guys are thinking about this in a very cloudy kind of way. Assuming that Ubiquiti was being blackmailed, they have a security problem in who they hire (Who held user data for ransom). Assuming they were not being blackmailed, but had a security hole in their software, Ubiquiti has a security problem. Krebs reporting comes from a potential conflict of interest in that the person who might have been trying to black…

Kreb's article specifically alleged malfeasance on Ubiquiti's part - that they were deliberately covering up a huge data breach. This turned out to be untrue on three levels: 1) There was no cover-up. Ubiquiti disclosed the attack, and was working with the FBI, working to identify what had happened, and in fact where already onto Sharp as a insider attack. 2) There was no large scale data breach. 3) The claim that th…

>> 2) There was no large scale data breach

Says who? The FBI? Says Ubiquiti? I bet BOTH of those places have a reason to say that, and it is green and smells of dead presidents.

Re: Final thoughts on Ubiquiti

#104
post #69

Earlier quoted context omitted.

What should he do going forward?

He should become immune to social engineering and manipulation... /s Now seriously, there is not much he can do going forward other than be even more careful with vetting his sources. Which I am sure he already internalized.

(Questions about the current state of journalism aside...)

There is already standard journalistic practice for avoiding this: get a second, more reliable source. It can often be much easier to get a reliable source to verify information initially provided by a sketchy source than to get that reliable source to provide information in the first place.

If you post unverified information that one person on the internet tells you, your work is indistinguishable from gossip, and should be taken as such.

Re: Final thoughts on Ubiquiti

#105

Earlier quoted context omitted.

What should he do going forward?

Not be a shock jock revealing things based on untrustworthy sources.

His entire beat is based on untrustworthy sources. What makes him special is that he is hanging out on Russian language carder forums and the like, monitoring the gossip and identifying new threats and patterns of behavior. That is the value that he adds, and it's a reasonably big value.

In this case, he got played, but if he stops trying to work with untrustworthy sources he stops doing his job.

Re: Final thoughts on Ubiquiti

#106
post #32

Before people jump on this with super negativity... mistakes happen. What is Krebs' false positive rate? I think low enough that a simple, clear explanation of why it happened is sufficient. There's no weasel words or evasion here - he owns up to the error, apologizes to affected parties, and retracts all original posts. It's true that his reporting probably caused stress for Ubiquity. I'm curious what people think i…

Yeah, but publishing information as quickly as possible to surf on the first big clicks-wave can cost people their jobs. Because it can result in someone deciding to go with an other company.

A friend who is looking for a easier to manage network for his wife's doctors office let me know that there's reports about security issues after I recommended to him to evaluate if Ubiquity could be a good option. Not sure what exactly he was referring to. Nevertheless, I sent him now the link to this article.

Re: Final thoughts on Ubiquiti

#107
post #32

Before people jump on this with super negativity... mistakes happen. What is Krebs' false positive rate? I think low enough that a simple, clear explanation of why it happened is sufficient. There's no weasel words or evasion here - he owns up to the error, apologizes to affected parties, and retracts all original posts. It's true that his reporting probably caused stress for Ubiquity. I'm curious what people think i…

> What is Krebs' false positive rate? What's more important is how those false positives are handled. In this case, it feels like it was swept under the rug and he avoided addressing for as long as possible. If he had simply addressed the problem head-on as the news came out and the FBI information became public, it would have been a different story. The way he rushed to report accusations from an anonymous source (w…

> What's more important is how those false positives are handled.

Is it really though? If there's a company that has to defend / apologize often (Facebook/Meta maybe) I'd be way more critical of their apology than if one guy who didn't have a case like that before apologying a bit too late for some people or not in the way they wish he would. There's also a lot of information we don't know yet, we don't know what happend behind the scenes and when he was provided with the final verdict and facts.

Re: Final thoughts on Ubiquiti

#108

Earlier quoted context omitted.

Kreb's article specifically alleged malfeasance on Ubiquiti's part - that they were deliberately covering up a huge data breach. This turned out to be untrue on three levels: 1) There was no cover-up. Ubiquiti disclosed the attack, and was working with the FBI, working to identify what had happened, and in fact where already onto Sharp as a insider attack. 2) There was no large scale data breach. 3) The claim that th…

>> 2) There was no large scale data breach Says who? The FBI? Says Ubiquiti? I bet BOTH of those places have a reason to say that, and it is green and smells of dead presidents.

Get caught in a lie in front of a jury for a white-collar criminal prosecution with any sort of competent lawyer, and you never regain credibility. Regardless, the other points still stand.

It's incredibly hard to defend yourself if your head of security decides to extort you. They are the ones that design the protections to keep insider attacks from working. Luckily for Ubiquiti - the attacker screwed up his network configuration (VPN leak failure) which is also somewhat ironic.

Re: Final thoughts on Ubiquiti

#110
post #89
post #33

Earlier quoted context omitted.

The problem from my end though is, who really competes with them? No one else offers the same level of control at the same (or even close) price point.

Nobody competes with them as 'Apple for networking', but MikroTik is if anything a bit cheaper and better on the actual specs etc. - just without the snazzy UI and easy GUI (highly-G) config. There's probably a lot of people who'd love Ubiquiti gear ('gadget nerds', Linus Tech Tips viewers, gamers, etc.) to whom I wouldn't recommend MikroTik, but to anyone who's.. idk, heard of iptables, I would. All the gamer-market…

If you have heard of IPTables, go grab OPNSense.

Mikrotek makes sense when you really really really care about having the cheapest possible 10g switch.

AFAIK, there is nothing that competes apples to apples with the UDM in terms of a entry level managed switch / router / WAP offering (or the UDR, which does UDM + Telephony or distributed global management)

Post reply on HN