Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

261–270 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#261

Earlier quoted context omitted.

The UDM, UDM Pro, and I think _all_ newer controller software require cloud login at some point in the process.

It's definitely not all the new controllers, although with the UDM line you might be right. I think there's a huge intersection between people who would buy those specific devices and people who are perfectly happy to have remote access to their control plane in the cloud.

It looks like what I was referring to is that they recently made the initial controller setup on the cloudkey require a cloud account [1], but you can migrate to local only after the initial setup.

So the only remaining 'local only' from start to finish is for self-hosted I guess.

[1] - https://www.youtube.com/watch?v=gNkXAe0aOAg

Re: Ubiquiti all but confirms breach response iniquity

#262
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

> I'm just a guy who worked at Ubiquiti for a year Would you be able to point to unofficial compatible operating systems for Ubiquiti devices? I want to remove Ubiquiti software from the devices I bought and paid for.

The gear is locked down to UniFi firmware. Some of us wanted to open it up to alternatives like OpenWRT but that wasn't an option for us.

Re: Ubiquiti all but confirms breach response iniquity

#263
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

That would be the reverse of the usual strategy, wouldn't it? Most companies seem to try to pin breaches on sophisticated hacker groups backed by nation states. But then, they benefit from the perception of a threat that's impossible to defend from (so there wasn't anything they could do) - whereas Ubiquiti benefits from people thinking the attack was just a small actor that couldn't possibly threaten Ubiquiti's cust…

There was a lot of infighting and turf wars when I finally quit. I'm not even surprised that this latest turf war spilled into the news.

Re: Ubiquiti all but confirms breach response iniquity

#264
post #208

Earlier quoted context omitted.

> they’re definitely moving in a little bit of a different direction then where many of us would hope it pains me to say this because I was there for the UniFi glory days: The old Ubiquiti is dead and gone. Almost everyone I know quit. I hope they can land on their feet and return to the glory days but I don't have much hope. The company got toxic fast at the end

Based on username/comment, let me ask, what is next? Because the platform integration and ease of administration, no one else has and it’s great for simple networks.

Several of us from the UniFi team went to competitors but we're focused more on enterprise.

We always thought MikroTik was one of the biggest competitors for low cost equipment. Our main advantage was the UBNT community and having famous supporters like Troy Hunt which MikroTik didn't have. The community fell apart after the redesign killed it and I don't think people like Troy Hunt will endorse Ubiquiti now so it should be interesting to watch what comes next

Re: Ubiquiti all but confirms breach response iniquity

#265

Ubiquiti should really stop making cloud logins mandatory. The latest stuff (UDM/UDM Pro, Cloud Key G2) must be connected to their cloud at installation time. Remote access can be turned off but an admin account connected to their cloud remains. Without those ties to their infrastructure, this breach would not be as severe. It would just cause an attacker to see what I've bought from them, nothing else. I'm glad I ca…

I worked there and I didn't even understand why we had to force cloud logins on Dream Machine. In the early days we were all about letting people run their own controller hardware and not requiring cloud logins. No one could ever tell us why we had to force everyone to the cloud. It was a mandate from above

Re: Ubiquiti all but confirms breach response iniquity

#266
post #172

Earlier quoted context omitted.

Mine's only slightly larger than that (mostly by virtue of having 3.5 levels, not by X-Y size), but the original plaster walls attenuate the hell out of 5GHz signals. I have two APs, one in the basement and one on the second floor and even with that, I'm considering adding two more inside and a dedicated one outside to serve the patio/BBQ area as I can readily tell the speed difference to internal file and backup ser…

> the original plaster walls Ah, the ones that have wire mesh underneath? That would do it.

No. My house predates the widespread use of expanded metal mesh style of lath. Just the old wood strip lath and thick, horsehair plaster.

Re: Ubiquiti all but confirms breach response iniquity

#267
post #150

Earlier quoted context omitted.

eBay. The secondary market for high-end network switches is excellent if you’re a buyer.

Ya I did some research and it's not bad at all. And ruckus is pretty good with their firmware options. In fact I'm buying two new R710s to replace my very old UAC AP Pros. Was going to get the new AP 6 LR but after UIs current woes (and them dropping support for my APs way too early) I'm done with them.

I ran into issues with firmware on a ZoneDirector 1200 and some R610's that were out of support contract. Totally functional and all, but couldn't bring them current.

Though, After using Ruckus in Corp/Enterprise they've sold me on how capable their APs are, it's real deal high density stuff.

Re: Ubiquiti all but confirms breach response iniquity

#268
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

When I'm bored, I sometimes intentionally take comments out of context, just to see where they go, I know this isn't what you ment, but I like to pretend:

>Form your own opinion, I'm just a guy who worked at Ubiquiti for a year, raising all kinds of hell about the security, architectural, and operational problems that I saw while I was there.

You are a lawn man/woman.

Security problems: I have to show my badge EACH TIME I go to the bathroom

Architectural problems: these bricks are the WRONG COLOR!

Operational problems: The painters used the WRONG COLOR OF OFF WHITE!

Again, I know this isn't what you ment, but I enjoyed transposing a well written critique of their software from (presumably) a knowledgeable software guy into a lawn person in a jumpsuit.

Thank you, amd have a good day.

Re: Ubiquiti all but confirms breach response iniquity

#269

Earlier quoted context omitted.

It's definitely not all the new controllers, although with the UDM line you might be right. I think there's a huge intersection between people who would buy those specific devices and people who are perfectly happy to have remote access to their control plane in the cloud.

It looks like what I was referring to is that they recently made the initial controller setup on the cloudkey require a cloud account [1], but you can migrate to local only after the initial setup. So the only remaining 'local only' from start to finish is for self-hosted I guess. [1] - https://www.youtube.com/watch?v=gNkXAe0aOAg

I have a cloud key gen2 plus and do not have a UI.com account. I would classify getting the network controller setup without having one initially "mildly annoying but worth it".

I'm also floored at the number of people who are spinning the existence of a self-hosted controller as somehow a bad thing...?

Re: Ubiquiti all but confirms breach response iniquity

#270

Earlier quoted context omitted.

Depending on your viewpoint. Compared to an enterprise setup with similar features? Basically free. Compared to your average all-in-one home router, however, these are very expensive.

> Compared to your average all-in-one home router, however, these are very expensive. Compared to your average all-in-one home router, however, these are also markedly less shitty.

Right. Which feels like it meets the criteria of "far from cheap" pretty well.
Post reply on HN