Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

191–200 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#191
post #102
post #55

You get great insight into the character of the leaders of a company watching how breaches are handled. Companies that put the customer first are transparent, and quickly take action (even if painful to customers) to ensure that customers’ data and systems stay intact and confidential. Companies that try to gloss over, hide or downplay things indicate that the leadership does not respect their customers and is only i…

If I can vent for a second, this company has no leadership . None. Things may have changed in 2 years, but I doubt it. I was messaged almost daily by random employees asking wtf was going on with the company. They were afraid for their jobs. Practically no one respected the CEO, and he was the only C-suite exec. There. Was. No. Leadership. There was no company wide communication, and all communication channels were m…

If you had the power, what you would do?

From the outside it seems like accepting fault and product returns would smooth waters. Acknowledge faults on their own forums and Reddit subs and also provide times lines for fixes (then stick to them and update threads!)

The hardware is mostly good. The weird bugs and company management are turning a strong community of users against Ubiquiti.

Re: Ubiquiti all but confirms breach response iniquity

#192
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

For LastPass, did they enforce the policy to mandate 2fa for everyone’s vault? Where I work they mandate 2fa be enabled. Some orgs overlook this.

Re: Ubiquiti all but confirms breach response iniquity

#193

It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response. At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewh…

I dumped their gateway/security appliance in favor of Opnsense box. Never looked back or regretted it. Their security appliance is not as granular as I would want and the Opnsense was a learning opportunity for me.

Re: Ubiquiti all but confirms breach response iniquity

#194
post #146

Mentioned it before, but since a few days ago my unifi devices (2 wifi APs, a small switch, plus one Debian VM with the controller, all on it's on VLAN) are not allowed to do outbound traffic anymore, with the exception of NTP, DNS and one trusted apt mirror. Looking at the firewall logs it seems the devices try to ping (ICMP type 8) a bunch of AWS IPs every few hours. The controller tries to connect 80/443 on differ…

I have said this before, but would like to reiterate that I am never touching or buying anything branded as Ubiquiti or owned by Robert Pera. This hardware is far from cheap and consumers are literally paying for adware/spyware. I really hope Ubiquiti stock takes a nosedive over the next year.

Fwiw, Ubiquiti hardware is actually quite cheap.

Re: Ubiquiti all but confirms breach response iniquity

#195

Anyone know if Apple will be putting out a wifi mesh system, maybe integrated into Homepod Minis? Apple already 'owns' me, I might as well have them run my Wifi too and ditch my unifi gear. At least Apple seems to care about privacy and security, even if it is a self-serving marketing scheme.

Their wifi line used to be excellent.

Having APs that could be hardwired would be a requirement for me. The less wifi the better.

Re: Ubiquiti all but confirms breach response iniquity

#196
post #30

Earlier quoted context omitted.

Ditto and they have also lost my recommendations. If I hear any friends thinking of Ubiquiti, I will be pointing them towards articles like the one we are discussing. I had been a bit wary of then since their push for cloud SSO etc, but these recent events have put the final nail in the coffin for me. Personally I am migrating my family's network to MicroTik gear.

A friend of my boss recommended Ubiquity semi-recently. We're a small IT company, plenty of theoretical expertise but no dedicated network admins, so it made sense to go on a recommendation. The fact that doing anything , for example assigning a VLAN to a switch port, requires you to first setup a mongodb server on your machine before you can install the controller software tipped me off to the quality of what we had…

> The device also gets like 80°C while idle.

This sounds like a 8 port poe switch. They get hot. However they also don’t seem to mind it.

Re: Ubiquiti all but confirms breach response iniquity

#197

It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response. At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewh…

Unifi's router isn't all that great. I would go with other software (like opnsense), which is the recommendation of some others out there.

Their switches and APs are still really good. For alternatives, it depends on your goals. How many configuration options do you need? Is cloud management bad? Any more.

For consumer: Google, Eero, Orbi and some of the others are good. If you want more control, you need to venture into the SMB and Enterprise space.

Unifi, Engenius, Aruba Instant On, Tp-link Omada, Mikrotik, Ruckus and maybe some others. It really depends on your desired feature set.

Re: Ubiquiti all but confirms breach response iniquity

#198
post #166
post #60

Earlier quoted context omitted.

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

Similar to the other responses, it's the fact that I can manage my network remotely from a simple app or UI. This helps me answer phone calls from my family asking why Netflix doesn't work on TV #2, when I'm not at home. Won't solve all problems, but at least I can narrow it down and troubleshoot. And I like the fact that I can an overview of the state of my network; one of my wired links to an AP would degrade to 10…

> it was a bad ethernet cable in the end

Checking the cable is like checking if the power is on, it is NEVER the cable - except in networking for some reason. Half the time it's the cable.

Re: Ubiquiti all but confirms breach response iniquity

#199
post #189

Earlier quoted context omitted.

I don’t deny any of that. But where is most of the hardware for just about any network and computing equipment manufactured? Questioning if tplink is made in China is pretty low effort and pointless. A thoughtful analysis would ask why an onshore supplier would fundamentally be any less vulnerable to political adversaries.

being made in china and being a Chinese company are very different things and the risks are different.

Much like Cisco being exposed to US supply chains leaves them vulnerable to tampering by US intelligence through physical interception, merely being made in China is a security risk.

Re: Ubiquiti all but confirms breach response iniquity

#200
post #128
post #71

Earlier quoted context omitted.

That may have worn thin, nowadays. The average response here would have been described as cynical in the past. The Russia/China scapegoat had been way overused to the point where I'm cynical every time it comes up probably even where it's actually true, one time in a hundred or whatever. Nobody blames the NSA in these circumstances, ever.

Google did it with an allied op recently. Not NSA, but as close as we're likely to hear about. https://www.technologyreview.com/2021/03/26/1021318/google-s...

Do we know for sure it was an allied operation? Everything I saw mentioned a “Western government operation” which doesn’t necessarily exclude the NSA.
Post reply on HN