Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

131–140 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#131

Can companies be held responsible for damages from data breaches? If they could, it seems like it would incentivize more caution about what data is collected, and more investment in the security of that data. I also imagine an insurance industry, where the insurers then have expectations about what kinds of security must be in place to get reasonable premiums.

Yup, this is more or less how “cyber security” policies work.

Re: Ubiquiti all but confirms breach response iniquity

#132

Earlier quoted context omitted.

> Most of the value proposition of the Unifi lineup is I can look at a single website ... > The single pane of glass to view everything when I am many miles from the networks I support is essential It's also why we're talking about this.

Only because they made it cloud based. If they never forced people to create a cloud account - and instead allowed people to choose - this would be wildly different.

Did I miss something here? I run a Unifi network with a local account and don‘t recall being forced to create a cloud account.

Re: Ubiquiti all but confirms breach response iniquity

#134
post #60

Earlier quoted context omitted.

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.

My house had a problem since the cable came in on one corner of my house, and my office was on the other side. Browsing was ok but things like video calls suffered, at least until I went with a Unifi BeaconHD.

Re: Ubiquiti all but confirms breach response iniquity

#135

Earlier quoted context omitted.

Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.

Depends a lot on the house. My house is It wasn’t a problem until covid when multiple meeting or other streams just performed poorly on a marginal network. The Ubiquiti gear made it easier to run antennas for optimal signal. The hot thing to do is to shit on them, but I’ll be sticking with it. They’ll emerge better from this crisis and if you think that any competitor in this price point is better, you’re delusional.

Also, foil-backed insulation [0]. I finally figured out they insulated the hell out of my house with this stuff.

Works amazingly on heating and cooling bills, but it's a pretty solid wall to radio waves.

[0] https://www.ibhs.co.uk/foil-backed-mineral-wool-50mm-thick-x...

Re: Ubiquiti all but confirms breach response iniquity

#136
post #18
post #11

Earlier quoted context omitted.

These blanket statements don’t apply to everyone. It depends which Ubiquiti hardware you own and how you’ve configured it. For example, I run the UniFi controller on my FreeNAS server. There are no forced updates to it. It doesn’t update unless I update it. The firmware on my APs doesn’t update unless I update them from my controller.

Unless you're manually verifying the content of your AP firmware updates (which is a bit hard since they're closedsource), I don't understand what you're trying to say. The firmware could be compromised at the source so your FreeNAS doesn't help at all when you download and apply a compromised firmware update. Unless you're not updating your APs and keeping them vulnerable in that way :)

I was addressing "attackers might have gained control of the update infrastructure allowing them to push out malicious firmware to your devices."

In my case, no, they cannot push anything to my devices. Obviously, I could pull down compromised firmware. But that's always a risk with software that I don't personally verify, which is like 99.9% of software.

As a side note: obviously this security incident doesn't give me a whole lot of confidence in how they run their systems, but at no point has it been alleged that Ubquiti's firmware updates have been tampered with.

Re: Ubiquiti all but confirms breach response iniquity

#137
post #48

Earlier quoted context omitted.

Damn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.

During this week I've been playing around with replacing my USG with my existing home server - it already has two NICs - my first thought was to run OPNSense in a VM but nftables on NixOS seems to work well enough - there are a few examples floating online [0,1]. OpenBSD even supports the USG [2] but I couldn't think of much reason to keep the extra hardware. The next thing I want to do is reflash my Unifi APs with O…

> The next thing I want to do is reflash my Unifi APs with OpenWRT

My understanding is that this doesn't work anymore because Ubiquiti started signing firmware. Your link also goes to a blank page.

Re: Ubiquiti all but confirms breach response iniquity

#138
post #60

Earlier quoted context omitted.

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.

Mine's only slightly larger than that (mostly by virtue of having 3.5 levels, not by X-Y size), but the original plaster walls attenuate the hell out of 5GHz signals. I have two APs, one in the basement and one on the second floor and even with that, I'm considering adding two more inside and a dedicated one outside to serve the patio/BBQ area as I can readily tell the speed difference to internal file and backup servers if I'm in the same room as an AP vs on another floor or outside.

Make no mistake, it still "works" with just one, only slower.

Re: Ubiquiti all but confirms breach response iniquity

#139
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

So, why & how did you do this?
Post reply on HN