Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

61–70 of 486 posts

Re: Ubiquiti Networks Breach

#61
post #24

Earlier quoted context omitted.

Sounds like their cloud provider environment was breached. If that's the case then access to databases with salted and hashed passwords is to be expected, is it not? Would be good to know which provider this is and whether it was the fault of the provider itself.

As some of the IPv4 addresses for ui.com seem to be assigned to AWS I'm not sure what to make of it.

Improperly secured S3 bucket? That's hit more companies than I can count.

Re: Ubiquiti Networks Breach

#62
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Did you happen to write up the results of your router tests? I'd be really interested in reading up on them! I recently picked up an old Apple Airport Extreme so I could easily set up Time Machine backups on my network, but obviously Airports have their own host of issues so I'd be really interested in upgrading soon.

Re: Ubiquiti Networks Breach

#64
post #56

Earlier quoted context omitted.

It's impossible to secure yourself against a devoted persistent threat group over the long term. The asymmetry of effort is not tractable to overcome. So they can take your security seriously, but they will be hacked, or they have already.

I don't think my post argues, or even attempts to argue, against your point. It was a light-hearted jest at the fact that this exact line is in every single breach notification I have read for the past few years. The more serious point I was alluding at was not "just don't get breached", it was that the "we care" line rings hollow after the 250th time reading it.

My misread, apologies. I think the "we care" is a dodge around the reality that most are uncomfortable with, which is, "we make your data safe as possible but we will likely be hacked and you should compartmentalize your personal data accordingly with that expectation". But I am no good with marketing.

Re: Ubiquiti Networks Breach

#66
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I turned off cloud login a while back. There’s a toggle in the settings for this.

Re: Ubiquiti Networks Breach

#67
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I run a Netgate SG-5100 (PF-Sense) as the main router, the Unifi controller and Access points are al behind the Firewall. The AP and switches are really good, not the DPI/IPS/IDS solution (those suck)

Re: Ubiquiti Networks Breach

#68
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

They opted to TELL people about it which is a good indicator. I’m sure there’s many companies who choose not to (which may be against the law). It’s also HR spin on the topic, but iirc ubiquity offer bug bounties on a range of devices they sell so there’s at least some truth to the spin. ‘We know they breached but don’t know what they did’ is an interesting statement. One POV is that they didn’t have sufficient loggi…

I'm unsure how your statement is meant as a response to mine. I obviously agree that it is a good indicator that they notified customers of a breach.

Re: Ubiquiti Networks Breach

#70
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Did you happen to write up the results of your router tests? I'd be really interested in reading up on them! I recently picked up an old Apple Airport Extreme so I could easily set up Time Machine backups on my network, but obviously Airports have their own host of issues so I'd be really interested in upgrading soon.

A second-hand Mac mini is an alternative that I've used for network Time Machine backup targets. Can also turn on caching iCloud/App Store/system updates for your home, if bandwidth is metered and/or slower than your local speeds.
Post reply on HN