Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

51–60 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#51

This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.

I always thought that the main selling point of their devices was that you can run your own Ubiquiti server at home and keep everything local? They are always portrayed as the not-so-shitty IoT company.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#52

Earlier quoted context omitted.

What a shockingly large breech. Wow.

The breaches are common, the reporting/discovery of them is not. Security just isn’t a priority for a lot of Orgs, as the consequences are minimal (see: Equifax) due to a lack of regulatory or financial penalty pain when a breach occurs. “Help yourself to a free year of identify theft insurance” and all that jazz.

Discovery of breaches seems to be undesirable in the current environment, if many go undetected.

If you discover, you have to report. If you don’t, odds are nobody will notice/will blame someone else.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#53

> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed” Perversely, this is exactly the logging that you want to have in place in case of a breach. You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”

[deleted]

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#54
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Technically, Ubiquiti does have a local option. You can run the controller locally and disable cloud login.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#55
post #29

Earlier quoted context omitted.

Successfully sweeping it under the carpet means you don't get sued for the mistakes you made. Legal isn't there to make sure the company complies with the laws. Legal is there to advise on and minimize legal risk.

> Legal isn't there to make sure the company complies with the laws. Legal is there to advise on and minimize legal risk. Breaking laws is one sure way to increase legal liability.

Only if you get caught.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#56
Ubiquiti is another one of these companies where if you did nothing but read about them on HN, Reddit, et al, you would think they're filing for bankruptcy tomorrow, set orphanages on fire, kill puppies, etc. The negative hyperbole around this company is something else, hack or not. And yet, all they do is thrive...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#57
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

It's a shame that Mikrotik doesn't have a easy to use global GUI.

It's the right hardware, and great firmware and wonderful flexibility - but it needs an easy to use GUI controller to make the simple stuff easy to take over from Ubiquiti.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#58
post #29

Earlier quoted context omitted.

Successfully sweeping it under the carpet means you don't get sued for the mistakes you made. Legal isn't there to make sure the company complies with the laws. Legal is there to advise on and minimize legal risk.

> Legal isn't there to make sure the company complies with the laws. Legal is there to advise on and minimize legal risk. Breaking laws is one sure way to increase legal liability.

but if you get away with it 90% of the time....

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#59
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Man I really wonder why the lack of proper 2FA is so wide spread?

Is it rally cost and complexity?

Or just missing awareness?

Or the lack of consequences when you get hacked in a way which could easily have been prevented (through then they might have attacked in a different way, tbh.).

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#60

> Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies. A root user user breach, seemingly on the organiza…

What is the right way store credentials to something like this? Hardware keys?

I use a Yubikey, personally.
Post reply on HN