Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

311–320 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#311

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

It's a shame that Mikrotik doesn't have a easy to use global GUI. It's the right hardware, and great firmware and wonderful flexibility - but it needs an easy to use GUI controller to make the simple stuff easy to take over from Ubiquiti.

Winbox is a really nice remote controller for Mikrotik & vulnerabilities of a shared global controller have just been clearly demonstrated, so I don't see an issue.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#312

Earlier quoted context omitted.

Yeah that doesn’t make sense to me. Sales would do something like that. Legal should be erring in the opposite direction.

No. They don't care if customers get pwnd. They care if customers become aware of exactly how they got pwnd and launch a class action. It's shitty but entirely predictable behavior common in these situations.

Well you’re right that it’s not their job to represent customers. Their client is the company.

But telling your client to sweep something like this under the rug isn’t exactly great advice.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#313

Earlier quoted context omitted.

I use OpenWRT now and would really rather avoid it. I want a central controller, not having every AP have its own UI. Plus firmware updates area always an adventure.

I'll let you in on a little secret, Ubiquity runs openwrt as can be seen by sshing into any uaps

That’s fine. I think it’s a great project. But I want someone else to worry about what happens during each firmware update. It’s not trivial.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#314

Earlier quoted context omitted.

I use OpenWRT now and would really rather avoid it. I want a central controller, not having every AP have its own UI. Plus firmware updates area always an adventure.

> Plus firmware updates area always an adventure. To somewhat eliminate the chances of adventure, I’ve profiled the setup for each of my many OpenWRT devices and created unique profiles for them in a (reasonably) simple Git repo[1]. All I need to do to get device-specific firmware is to update the OpenWRT version-number in a single makefile and the rest happens automatically. I’ve even setup Github Actions to build t…

About 5 years ago I would do the same thing. I want to set it up such that if I with the lotto and move away, the rest of my household can continue using the system without having to learn a CLI.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#315
post #92

It really doesn't get worse than this. But isn't Ubiquiti more of a prosumer company, like MikroTik? MikroTik does get a lot of heat when they have a security vulnerability and get downranked for it as if it were far, far away from Ubiquiti's security profile (something like "US vs. some east EU country"), but this event tells a lot about Ubiquiti's upper management and their internal security practices.

Fun fact - a lot of Ubiquiti's engineering is located in that same "east EU country". In fact, if you look at the open positions - https://careers.ui.com/positions - it appears most of the development appears to happen in Central/Eastern/Northern Europe.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#316

Earlier quoted context omitted.

Only been using it for a few months but it's been good. I moved the config I mentioned above (the three APs) to my parents' house and they haven't had any problems. Throughput in their case is a little limited but that's expected with the installation (no ethernet and a lotta walls). Hasn't needed a reboot or anything. I just started using an EAP660 HD[1] at home a week ago, so far so good. Haven't topped out the spe…

SOLD! Thank you.

Good luck! If you think of it, post a reply back here letting me know how it goes.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#317

> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed” Perversely, this is exactly the logging that you want to have in place in case of a breach. You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”

Why, they also have no evidence now!

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#318

Earlier quoted context omitted.

No, TP-Link's Omada controller can be run locally, I do that at home and at my parents' house. It is not cloud-connected unless you turn that on. Runs surprisingly well on a Raspberry Pi 2, actually. I've got a setup similar to what you're asking for. The TP-Link APs (AC1750, AC1350 and AC1200) support PoE, they're in a wireless mesh, support roaming, and all configuration is handled with one interface, no cloud invo…

How is the experience otherwise? Roaming? Throughput? Reliability? I generally like their hardware.

For what it's worth, we've been running about 15 TP-Link EAP225 in a warehouse without any hiccups so far. Most importantly they don't randomly die or lose the controller pairing like some low end Ubiquiti units tried in the past. The only quirk is that on Windows Server you have to configure the service manually, but it's no big deal. [0]

[0] https://www.tp-link.com/us/support/faq/2915/

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#319
post #189

Earlier quoted context omitted.

Now rewrite your entire comment with s/ubiquiti/sonos/g. So much wasted potential ... so much customer goodwill wasted because (apparently) no company is worth running unless it is a publicly traded unicorn.

Just curious (I agree with you), but what are the s/ and /g for? Samsung and Google?

I think the OP is using the sed syntax [0] to say:

> Now rewrite your entire comment with sonos instead of ubiquiti.

[0] https://www.grymoire.com/Unix/Sed.html#uh-6

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#320

Don’t have time to dig into this right now, but I have a Ubiquiti WiFi AP at my home behind a NAT; does this breach mean my home network is vulnerable/effectively exposed to the Internet? Do I need to log off HN and deal with this now, or can it wait?

It depends. How do you manage said AP? The leaked credentials issue here is specifically in SSO Cloud authentication to Controllers, which are used to administer all the actual hardware devices. However, the devices themselves aren't affected. So depending on how, or for that matter if, you manage them you may be unaffected as well which has always been a major touted advantage of UniFi and has indeed proved true right with this very incident.

Your post seems to imply you have just that AP and that's it? If you set it up initially (putting the controller on one of your own computers temporarily maybe), and then just left it standalone from there on out you're fine. There is no need to have an active Controller for all the hardware to work as configured, a Controller is just needed to change configuration, collect real time statistics/send notifications, and do necessarily active things like run a guest portal.

If you are running a Controller, but you're doing entirely standalone on your own hardware (or your own cloud service for that matter), and haven't enabled Ubiquiti SSO cloud access, you're unaffected. That's how I've always run since I don't trust 3rd party cloud stuff for something like this, ever.

It's """only""" an issue for their cloud service, and apparently their "Cloud Keys" and "Dream Machines" as well since they pushed it on people some recent firmware. Which granted covers a lot of surface area, and Ubiquiti has pushed very, very hard (see advertising outrage from just a few days ago). But it's thankfully still not everything.

Post reply on HN