Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

241–250 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#241
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Try Mikrotik. It can do all of the things you listed and more.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#242

Earlier quoted context omitted.

Eero is amazing. It Just Works. Apple style. Plug it in. Never fuck with it. Rock solid.

They are amazon-owned. I'd be shocked if they weren't collecting and reporting telemetry.

Telemetry is an extremely important part of making things just work. There's no other way to find the unknown unknowns.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#243

The plot Thickens: "SHAREHOLDER ALERT: Ubiquiti, Inc. Investigated for Possible Securities Laws Violations by Block & Leviton LLP; Investors Should Contact the Firm" https://finance.yahoo.com/news/shareholder-alert-ubiquiti-in...

This type of solicitation is a dime a dozen, but I do find the name of the firm hilarious. Anyone who's had to make patch cables would recognize the name...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#244

It is interesting to do a search of HN for past references to "Ubiquiti". Whenever the topic of routers came up, many comments followed that recommended them above any alternatives. Commenters seemed proud to tell the world they were using Ubiquiti, as if the "HN concensus" for home routers was to choose Ubiquiti. It seemed to me Ubiquiti would never allow customers the option to install their own OS (e.g., BSD) or b…

I do not understand this comment.

Ubiquiti sells turn key HW and there never was any hint that this was HW you could roll you own on.

I could buy APs that I could install OpenWRT. I could setup an OpenBSD firewall. I could run my own DNS. I have done all this in the past. The point is I do not want to anymore. I have better things to do with my time. So as a turn key solution that is "prosumer" their kit works and I think you will find that is why most people here have recommend it.

You can disable the Cloud connection and I posted how in this thread. People on HN are tech savvy enough I sort that part.

The fact of the matter is they had a bad security breach and they have a cloud connected platform. Ops. That sucks. But the reality is that market forces have pretty much tied evaluations to cloud connections and telemetry gathered from it. That is the part that REALLY sucks. I do not blame them for trying to make money. I am angry if they were less then truthful in the details of the breach and I am sure both the SEC and the court of public option with punish them.

For my part, I have no plans to replace the 4 switches in my house with boxes running SONiC nor the 4 APs with OpenWRT or my firewall with OpenBSD because I just really do not care to have to maintain it, and if I drop dead tomorrow my wife can likely sort the UniFi stuff (as I have documentation on the setup) but there is no way could she sort the roll you own.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#245
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Synology. Isn’t cheap, decent performance though. However it doesn’t seem to be the brands focus

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#246

It is interesting to do a search of HN for past references to "Ubiquiti". Whenever the topic of routers came up, many comments followed that recommended them above any alternatives. Commenters seemed proud to tell the world they were using Ubiquiti, as if the "HN concensus" for home routers was to choose Ubiquiti. It seemed to me Ubiquiti would never allow customers the option to install their own OS (e.g., BSD) or b…

"It is even worse: Ubiquiti forced all users to use cloud-based authentification even for accessing your controller software on a local network with a local client. This was not even properly communicated but deployed by one of the regular maintenance updates."

Uh? that is demonstrably not true. Any more details?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#247
At least for home networking, I'll always pick something I can throw OpenWRT on over a managed service, subscription or closed-source option.

In the 15 years I've been using OpenWRT, I have never been disappointed with it, and I don't have to worry about some company's "secure" backdoor into my network being exploited.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#248
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Also add that all of the SOHO equipment is garbage that drops connections randomly, crashes, or simply can't deal with some WiFi chips.

This is the reason I went with the Ubiquity UniFi 6 years ago. It was the only one I tried that didn't constantly drop connections or cost a fortune. But it's only G and I've been considering an upgrade, but there are no good options on the market that don't have stupid cloud management bullshit, are built on garbage hardware, or cost an arm and a leg.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#249
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

have you checked out eero? https://eero.com/

I know someone that works there and they seem pretty happy with the place and product. just saw the amazon link now though so that may be a detriment depending on your view of them. (I have never used their systems or anything so it's not really an endorsement but something to consider)

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#250
post #192

Earlier quoted context omitted.

TP-Link is a Chinese company. Doesn't inspire much confidence..

And Cisco does? With it’s known back doors from the NSA?

Whataboutism aside, Cisco inspires even less confidence. Source: Used to work for Cisco.
Post reply on HN