Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

201–210 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#202
Well this absolutely sucks :(. I've been a huge supporter of Ubiquiti ever since I was buying mini their PCI cards and sticking them into soekris engineering boards (ubiquiti started out as a hardware company).

The magic thing that absolutely sold me on their equipment was the ease with with you could provision and mesh new gear. Does anybody have anything that compares with that ease of use?

To explain what I mean: I recently had a buddy move into our guest house/apartment. While we waited for the ISP to come out and hook up his internet, I just put an AP on his counter, powered it up, and meshed it into our home network. The whole process took less than a minute and didn't require any running of ethernet.

(Maybe that's a common feature nowadays and I've just been out of the industry for so long?)

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#203
post #51

This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.

I always thought that the main selling point of their devices was that you can run your own Ubiquiti server at home and keep everything local? They are always portrayed as the not-so-shitty IoT company.

I can't speak to the newer UniFi garbage, but the selling point for their Edge network products was that you could have Cisco-ish managed switches and routers without paying the absurd prices for ASICs, licenses, ios upgrades, parasitic middleman distributors, etc.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#204

> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed” Perversely, this is exactly the logging that you want to have in place in case of a breach. You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”

Ironically they can factually make that statement now as well.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#205

Earlier quoted context omitted.

Technically, Ubiquiti does have a local option. You can run the controller locally and disable cloud login.

I have been suspicious of their cloud config and run a docker image of the controller locally. I'm still on version 5.14 and all of the cloud features are optional. I just ignore them. I guess now I know not to upgrade!

When they introduced callhomes/telemetry sometime in the 5.x code i blocked their known DNS entries and then setup firewall rules to block all internet access outside of the Ubuntu Repos..

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#206
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

[deleted]

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#208
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

[deleted]

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#209

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Omada EAP245. You can use appliance and/or software controller that you can run locally, to manage your APs no cloud needed. https://www.tp-link.com/us/business-networking/ceiling-mount...

And if you only have one, no need to run Omada. Completely controlled from the AP web interface.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#210

Earlier quoted context omitted.

If you don't have remote access enabled and aren't running their surveillance camera software, it is not clear to me that there is any risk to the customer from this event (outside of the source code being used to generate new exploits). It doesn't sound like the attackers were able to abuse automated firmware update functions, and losing credentials to a UI account has no impact on users running cloud key locally wi…

Right. I would never have any device like a camera be directly connected to the internet and instead cut off that device from the internet in my router software and only access it from outside via a VPN. Not that this whole screw-up should be excused in any way or downplayed.

I bought one of their security cameras to act as a nursery cam last year, which I could later convert into a home security camera.

The 'in house' software, unifi-video, was discontinued 3 months after I got it set up. All of the apps I use to connect to the system have been pulled from the app store, and you now have to use their camera controller for the one camera, vs the software Im running on my linux box.

Their controller is much more limited, and many, many security camera installers were caught off guard with no path forward for their customers. It's a nightmare of a shitshow and I would never in a million years recommend Ubiquiti as a company at this point.

Post reply on HN