Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

1–10 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#5
I’m still on board with Uniquiti, tons of equipment and it wouldn’t make sense to switch everything over for small operations. But this is extremely disappointing, they’re definitely moving in a little bit of a different direction then where many of us would hope.

More shiny products that increase bottom line is great but many IT officials rely on UniFi as well, I wonder how they’re responding to enterprise customers.

I just hope this incident will at least get them to put some emphasis on security again as well.

Re: Ubiquiti all but confirms breach response iniquity

#6
What I’m curious about is, if I run my own controller on my own hardware, do I need to be concerned about this? I could understand supply chain concerns... I’ve held off updating anything while this plays out. But all these “breach! breach!” stories fail to spell out who is affected and what they need to do.

Re: Ubiquiti all but confirms breach response iniquity

#7

So, what happens now? Will Ubiquiti be held to task, by anyone?

They’ve lost my business.

Plaintiff lawyers will come into effect if there were actual damages as a result of this. Has anyone heard of actual breaches of their own networks as a result? If not, probably no actual damages = class action plaintiffs don’t care because no $ for them. Of course this is generalizing but this is usually the calculus. I know this because I am a cyber attorney.

Re: Ubiquiti all but confirms breach response iniquity

#8
post #6

What I’m curious about is, if I run my own controller on my own hardware, do I need to be concerned about this? I could understand supply chain concerns... I’ve held off updating anything while this plays out. But all these “breach! breach!” stories fail to spell out who is affected and what they need to do.

Force pushed updates overnight turned local controllers into requiring ui.com single sign on, iirc.

Re: Ubiquiti all but confirms breach response iniquity

#9
post #6

What I’m curious about is, if I run my own controller on my own hardware, do I need to be concerned about this? I could understand supply chain concerns... I’ve held off updating anything while this plays out. But all these “breach! breach!” stories fail to spell out who is affected and what they need to do.

If the compromise is widespread enough then the attackers might have gained control of the update infrastructure allowing them to push out malicious firmware to your devices.
Post reply on HN