Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

561–570 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#561
post #275

Earlier quoted context omitted.

The early days at Ubiquiti were good. I worked with a lot of good engineers and we shipped good work. The decline is a recent problem. > How the brand hasn't become toxic already is a mystery to me, yet look at the stock price tracker. It's been trending up for years and it has well over doubled in the past six months alone. This is your answer. No incentive to change. All of the bad engineering decisions have been r…

What do you suggest for someone leaning on an EdgeRouter Lite (with EdgeOS v1.10.11, staying far away from v2.x) and a Unifi UAP-AC-PRO access point? The router will probably reliably carry me until saturating 1Gbps becomes a daily occurrence and the access point will be retired when WiFi 6E comes around (assuming Ubiquiti's WiFi 6E access points aren't required to connect to the cloud.)

Also in answer to sibling comments - you don't need to connect the UI software to the cloud. I have an Edgerouter SFP-X and a few AP lites. I recently added an 8 port Unifi switch for more PoE ports.

Following is to the best of my knowledge! Any ex-Unifi folks or other pros are welcome to correct me:

- The Edgerouter absolutely does not talk to ui.com (except check-for-updates). There's no remote control ability etc etc.

- The Unifi range can be controlled from the cloud, but via your Unifi Cloud Key. You can run this software yourself, without buying extra hardware. When it is not running there is no comms to the cloud. Run the software, configure things, stop the software - I run it in docker on an rpi4.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#562

By the way, reporting to krebsonsecurity is a giant waste of potential income. This is what the SEC whistleblower program is for. You get paid for submissions there that lead to successful enforcement actions, and the payouts can be very substantial. Furthermore because payouts exist, there's an industry of competent lawyers that will happily take cases with compensation coming exclusively from your payout. Also, how…

> how is this a securities case?

Everything is securities fraud.[0]

[0] https://www.bloomberg.com/opinion/articles/2019-06-26/everyt...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#563
post #438

Earlier quoted context omitted.

You never can be... but you should already know that being a manager. But if you're the target of an advanced persistent threat. It doesn't matter how good your guys is, they'll win eventually when the next 0day no one knew about shows up. But then your cloud provider will have been broken into dozens of times already. Hundreds of companies have to do a security audit of all of their networks now* because Ubnt got, g…

So what, you are suggesting a strategy of staying away from large services and hoping that you won't be targeted? I posit that it doesn't take burning a zero day, or a coordinated effort by the CIA, the FSB, and Randy Waterhouse to break the typical DIY self-hosted security implementation. (And that the manager paying someone to build it has no ability to tell between a great , a good and a bad DIY job.)

A network controller for local WiFi shouldn’t be reachable from the Internet at all. I’ll take a vulnerability ridden controller on an isolated management VLAN over cloud shit any day.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#564

Earlier quoted context omitted.

1. Putting the management UI on a local system requires some custom networking setup, and is full of security footguns. 2. Most customers who want this have multi-site setups; in that case, you need paths across the public internet too. Again security footguns, and also reliability ones. 3. Remote work is very very common for IT people. 4. Recovery from configuration mess-ups is harder if your control plane has to ru…

> 4. Recovery from configuration mess-ups is harder if your control plane has to run on the same network that you've messed up. That’s a senseless statement in the context of a cloud solution that requires Internet to work.

In actual deployments and support situations I saw at Meraki, connectivity from individual hosts to the internet was usually the most reliable part of the network.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#565
post #246

It is interesting to do a search of HN for past references to "Ubiquiti". Whenever the topic of routers came up, many comments followed that recommended them above any alternatives. Commenters seemed proud to tell the world they were using Ubiquiti, as if the "HN concensus" for home routers was to choose Ubiquiti. It seemed to me Ubiquiti would never allow customers the option to install their own OS (e.g., BSD) or b…

"It is even worse: Ubiquiti forced all users to use cloud-based authentification even for accessing your controller software on a local network with a local client. This was not even properly communicated but deployed by one of the regular maintenance updates." Uh? that is demonstrably not true. Any more details?

No opinion myself, but someone did mention something to this effect in a different thread: https://news.ycombinator.com/item?id=26638671

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#566

By the way, reporting to krebsonsecurity is a giant waste of potential income. This is what the SEC whistleblower program is for. You get paid for submissions there that lead to successful enforcement actions, and the payouts can be very substantial. Furthermore because payouts exist, there's an industry of competent lawyers that will happily take cases with compensation coming exclusively from your payout. Also, how…

[deleted]

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#567

Is it just me or are you no longer able to avoid the cloud with the latest software updates for unifi?

Only if you have the newer Cloud Key or Dream Machine. The older Cloud Key isn't fast enough to handle the new OS (which ended up being good in this case, since it's still getting security updates).

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#568

It seems naive to want to talk to the press under a pseudonym — Adam , in this case. When looking for leakers internal security auditors don’t need proof you are Adam in order to fire you. They just put enough pressure on the most likely Adams such that they quit. You will be one of them. If another Adam does so, so be it. Your actions likely flushed the other leaker when you thought you were the only one. You won’t…

I wouldn’t be surprised if Adam has already left the building.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#569

Earlier quoted context omitted.

> having a trustworthy and secured backend. Ubiquiti had a secured backend - their screw-up was not doing MFA on their admin accounts. I would still like if there was an option for a local-only control panel.

For their UniFi line, at least, you don't have to use their cloud controller. You can self-host.

Yes. I run the controller on a raspberry pi 4. Local only.

I too am disappointed in UniFi’s direction.

I used to recommend them. I don’t now.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#570

Earlier quoted context omitted.

Why is it so easy to snatch defeat from the jaws of victory in tech?

It's not enough to be good, or great, every tech company wants to be a world-spanning juggernaut. and it's just not possible, let alone desirable.

No - not every company ...
Post reply on HN