Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

571–580 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#571
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

you can build one but PoE might not be in the cards unless you want to convert the injected power back to a 5v barrel.

Alix makes a decent router board that can host Linux and dual PCI cards means 5 and 2.4 ghz AP's. the total would be ~200 for each "AP" but they would be pretty massively powerful.

https://www.pcengines.ch/alix.htm

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#572
post #284

Earlier quoted context omitted.

I don't think that it is a solvable problem if the economics stay the same. SolarWinds is actually trading almost $2/share more than it did 1 year ago today ($15.67 v $17.23). Sure, it is down from its 52 week high ($24.34). I would argue that SolarWinds should not be allowed to be in business in its current form, considering what a threat they have been to themselves and others in their mis-handling their software p…

I feel like we have to regulate this at a governmental level to get anywhere. We keep automating more and more of our society and its clear we're unable to protect it but the casuals don't get that and keep charging ahead and we enable them. The amount of power we gift to a given attacker seems to just grow and grow. But how do we achieve political intervention when technologists and politics appear to be completely…

You don't need to be technical to pass laws for this stuff. Technology doesn't change the fact that underneath it's always greed/negligence/etc. These are things that have existed forever.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#573
post #352

Earlier quoted context omitted.

> BigRespectableCompanies Ubiquiti really aren't in the same ballpark as AWS or Microsoft, which are the companies people use that argument for, and you can bet your ass their security is better than in most places.

This is a fallacy. Just because these companies have great security teams doesn’t mean that things don’t fall through the cracks. Shit slips past the security team in product meetings all the time.

Still better than the security competence of most individuals.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#574

Earlier quoted context omitted.

Yep, I have my controller running on a Synology 720+ NAS that has zero ‘wide area network’ access. Everything is local to my home. I am deeply saddened by Ubiquiti’s fall from grace... they were so good.

Can you go into more detail about your setup? I have 920+ and am in the market for a new router (controller? Still learning the terminology).

The cloud controller is a (surprisingly heavyweight) service that manages a network of unifi devices. It can run on a raspberry pi, or an x86 container / vm.

If I wanted to run it all the time, I’d try putting it in a docker container on my synology.

Instead, I have an sd card for my raspberry pi that has nothing but the controller installed. The main downsides to this are that it is easy to lose the sd card, and that the controller gathers bandwidth/usage/wifi connection reliability stats, but only when it is running. I don’t get those unless I boot up the RPi to diagnose some network issue (this has never been an issue in practice).

One advantage of the RPi setup over a synology container is that it has both a ethernet jack and a wifi adaptor. This is surprisingly helpful when bootstrapping complicated mesh topologies.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#575
post #433

Earlier quoted context omitted.

As a former enthusiast in this area, I need the time for other more pressing interests and have reverted my home network to Eeros pinned to an IQrouter. All of them require some central service to operate, and I rarely if ever have to pay any attention to them. They also provide better coverage and less radio interference than the prior gold standard, Apple Airport devices. The IQ runs some sort of ssh *nix variant a…

Maybe you and I have different opinions of "enthusiast" in this context. There is really only so much you're going to do on a home network. You set it up and once it's going, it requires very little maintenance. I would not consider running my own network gear a "hobby" any more than I would consider restaining my deck a "hobby". It's largely a one-time project. I do have requirements beyond what the typical consumer…

I used to do all of those things on homebuilt FreeBSD routers for a commercial ISP we built and ran for a few years back in the day, and now I do them on my off-the-shelf router so that I don’t have to maintain the OS or link-shaping, I just click Update Now once in a while and it autoadapts to local congestion.

All of these features are available out of the box and have a GUI intelligent enough to offer a text area for adding filtering/rewriting commands that exceed the GUI’s remit. I used to have to hand-build this. Now I can plug and play it, and end up with the same experience as someone who built their own server and OS, using the same open source components as they would.

Total time invested, 8 hours over 5 years. I’m content with that exchange, and it has come with the only drawback being “it cost money to purchase the router itself”. I could DIY for less expensive in dollars and more expensive in hours. That’s the hobby-or-not choice, as I see it.

I do not decry those who invest time instead. Good, do so! I invested thousands of hours of my life into DIY of this stuff. It was invaluable experience, but it’s no longer mandatory to DIY to get a great experience indistinguishable from DIY.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#576
post #379

Earlier quoted context omitted.

Do they make an Eero yet with more than two Ethernet ports? I love the product, I just want to plug 4-5 devices in as well as use the WiFi.

You can buy a 5-port unmanaged switch for roughly $30, just FYI.

To add the unstated testimony: I have two Eeros connected to an 8-port switch and they handle it just fine.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#577
post #222

Earlier quoted context omitted.

My point is partly, let's check in a year from now. I'd wager not one of your coworkers switched. Zero.

You'd have lost that bet already. One of them switched to Aruba last week. I've already replaced several pieces of ubnt gear as well and posted for sale on ebay. The APs I'm holding off until there are some solid WiFi 6E options. I know of at least two others that currently have hardware on order to replace existing ubnt routers with OPNsense so you can add them to the list by the end of April.

Count me in the Ubiquiti to OpnSense group too.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#578

Earlier quoted context omitted.

Why does it have to be a neighbor? It says "internet" on the tin. Do you have confidence that random people on the internet can't do the equivalent of a port-scan on you? The other way I think of it is, I don't use it right now. It likely has open doors, intentional or unintentional. If the open doors are widely discovered, reliably closing them seems difficult. The highest-leverage point in time to influence this st…

The question is what incentive a random person in the internet has into finding and targeting me. I’m a single dude who’s not rich, and I’m not gullible to scams (at least not easily). So unless they have a personal grudge against me, I would probably not be currently worried about installing a doorbell camera for example. The threat modeling will Change the moment I have a family of course. I see it no different fro…

Imagine someone taking control of your door and telling you you need to pay them $50 at a random bitcoin address before you can open it.

$50 isn't a reasonable payoff for most carjackings, but this isn't like a carjacking. They're doing the same thing at the same time to 1000 people using a script they wrote. That changes the payoff, and that means more people are likely to try to do something like this.

This is an extremely mild scenario. It's possible I'm wrong about IoT, and there's a case for using it in its current state. But one thing I'm _sure_ of is that analogies with cars don't work.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#580

Earlier quoted context omitted.

Yep, I have my controller running on a Synology 720+ NAS that has zero ‘wide area network’ access. Everything is local to my home. I am deeply saddened by Ubiquiti’s fall from grace... they were so good.

Can you go into more detail about your setup? I have 920+ and am in the market for a new router (controller? Still learning the terminology).

Yep, I put it in a Docker container on the Synology. Fairly straight forward. I followed a guide like this:

https://lazyadmin.nl/home-network/unifi-controller-on-a-syno...

Post reply on HN