So the laptop probably had some malware/keylogger on it that was able to pick up some data in the lastpass browser extension or something?
Whistleblower: Ubiquiti Breach “Catastrophic”
41–50 of 815 posts
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#42This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.
If i were you I’d take heart in the knowledge that the others aren’t any better, it’s just a matter of “when” they’ll get cracked in the same way
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#43> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is that too much to ask?
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#44Was days away from refitting my home out with £2,000 of gear. Any other recommendations for routers, wifi and security cameras?
There were some other suggestions in yesterday's Ubiquiti discussion.[1]
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#45> Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies. A root user user breach, seemingly on the organiza…
Hardware keys?
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#46Shit, I had plans to refresh the network infrastructure in my parent's place with a full ubiquiti setup to replace the years of added on junk.
Parent’s place? Go Eero Pro. Your future time management self will thank you.
Router, Wifi AP (probably two to get full coverage), Powerline extender, Point-to-point extender with a switch on the other end.
Stupid outbuildings. Anyway, thanks for the tip!
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#47Was days away from refitting my home out with £2,000 of gear. Any other recommendations for routers, wifi and security cameras?
Is there any (good) brand with pricing between Mikrotik and a Ruckus that doesn't need a cloud connection?
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#48Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#49> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#50>Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee. So the laptop probably had some malware/keylogger on it that was able to pick up some data in the lastpass browser extension or something?