Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

611–620 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#611

Earlier quoted context omitted.

Man I really wonder why the lack of proper 2FA is so wide spread? Is it rally cost and complexity? Or just missing awareness? Or the lack of consequences when you get hacked in a way which could easily have been prevented (through then they might have attacked in a different way, tbh.).

It's people not getting it and being plain annoyed by the second factor. YubiKey or Authenticator app on a different device... it's too inconvenient and people often only do it if forced (e.g. banks do this afaik).

Every day I sit at the same desk, at the same computer, logging into the same websites, using 2FA over and over and over and over while sites time out "for my protection". It's a plague. Write a damn desktop app I can run locally, I didn't ask for people from Turkmenistan to be able to login as me, so you could sell me a halfassed web version of something.

Joseph Heller predicted 2FA in Catch 22 when he wrote:

"Almost overnight the Glorious Loyalty Oath Crusade was in full flower, and Captain Black was enraptured to discover himself spearheading it. He had really hit on something. All the enlisted men and officers on combat duty had to sign a loyalty oath to get their map cases from the intelligence tent, a second loyalty oath to receive their flak suits and parachutes from the parachute tent, a third loyalty oath for Lieutenant Balkington, the motor vehicle officer, to be allowed to ride from the squadron to the airfield in one of the trucks.

Every time they turned around there was another loyalty oath to be signed. They signed a loyalty oath to get their pay from the finance officer, to obtain their PX supplies, to have their hair cut by the Italian barbers. To Captain Black, every officer who supported his Glorious Loyalty Oath Crusade was a competitor, and he planned and plotted twentyfour hours a day to keep one step ahead. He would stand second to none in his devotion to country. When other officers had followed his urging and introduced loyalty oaths of their own, he went them one better by making every son of a bitch who came to his intelligence tent sign two loyalty oaths, then three, then four;"

Notice how 2FA turns into MFA? Keep adding FA until you're as secure as the security theater demands.

"To anyone who questioned the effectiveness of the loyalty oaths, he replied that people who really did owe allegiance to their country would be proud to pledge it as often as he forced them to. The more 2factor logins a person went through in a working day, the more secure he was; to Captain Black it was as simple as that"

"Captain Piltchard and Captain Wren were both too timid to raise any outcry against Captain Black, who scrupulously enforced each day the doctrine of 'Continual Reaffirmation' that he had originated, a doctrine designed to trap all those men who had become insecure since the last time they passed a 2factor authentication prompt a few minutes earlier."

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#612
post #401

Earlier quoted context omitted.

> What more do you want? The hard part for me is figuring out how to disable access without breaking everything. I know it’ll be useful once I understand and I’ll take the time I need to learn it, but most people won’t. I prefer the opposite learning direction. Start closed and open the 1 or 2 things I need instead of having to understand 1000 things immediately to configure permissions reasonably.

Have you tried Access Advisor in AWS IAM? It’s been out for a few years now and is specifically targeted at using “... last accessed information to refine your policies and allow access to only the services and actions that your entities use.” Can you explain how IAM doesn’t work well with the “starting closed” approach? IAM authorization is “default deny” and every principal needs an explicit allow statement with th…

I’ll give it a try. Thanks!

> Can you explain how IAM doesn’t work well with the “starting closed” approach?

It works ok once you do a lot of learning and read the best practices. I think a lot of people will skip that and use their root account for everything.

The biggest mistake I made was creating an admin user, but giving it too many permissions and using it like a normal user.

After learning more I use the root account to make an admin account, but I think the admin account should only use IAM to create other fine grained users.

So it works fine, but I think it would be better to force people into creating those first couple of accounts with permissions chosen by experts. It’s too easy to jump right in and start using an over privileged account.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#613
post #110

Earlier quoted context omitted.

So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…

I can't imagine that there isn't a market for this. Look at the number of people recommending Ubiquiti stuff to each other. There are entire YouTube channels dedicated to it. If your whole living space or small office can be covered with a single access point, get a 3-in-1 combo that has a WAP, a router, and a small switch. But if you don't, you are left with, what exactly? There is also some demand for mesh stuff, f…

There were/are some performance implication of pfSense/OPNSense on these boards specifically. It seems like this has improved significantly in FreeBSD 12+.

https://teklager.se/en/knowledge-base/apu2-1-gigabit-through...

> APU2, APU3 and APU4 motherboards have four 1Ghz CPU cores, pfSense by default uses only 1 core per connection. This limitation still exists, however, a single-core performance has considerably improved.

I can saturate 1GB/s with no problem OoB on Debian/OpenWRT on APU2/3/4, ymmv

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#614
post #477
post #463

Earlier quoted context omitted.

This is what I do. I host a controller in AWS on an EC2 instance in my account. It works great.

Out of interest, why wouldn't you host it on something like a raspberry pi? Having your local network depend on an external network makes my old school sysadmin bones tingle for some reason.

Laziness? I can just set it up with a couple of clicks and pay almost nothing (it runs on a t2).

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#615

Earlier quoted context omitted.

I use OpenWRT now and would really rather avoid it. I want a central controller, not having every AP have its own UI. Plus firmware updates area always an adventure.

> Plus firmware updates area always an adventure. To somewhat eliminate the chances of adventure, I’ve profiled the setup for each of my many OpenWRT devices and created unique profiles for them in a (reasonably) simple Git repo[1]. All I need to do to get device-specific firmware is to update the OpenWRT version-number in a single makefile and the rest happens automatically. I’ve even setup Github Actions to build t…

This is cool! Forking.

I need to get back to trying to build a custom build for my KanKun smart plugs.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#616
post #551

Earlier quoted context omitted.

Except if it is awscli creds, then of course there is no MFA.

Exactly, no workflow for terraform or CLI if you have U2F (Yubikey) 2FA.

I really want to like U2F, but it’s use cases seem so limited.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#617
post #492

Earlier quoted context omitted.

It’s very easy to say “greed” because we want to believe bad things are always the fault of someone’s personal moral failings. Hopefully the tech community will start to realize that when the same problems keep occurring for the same reasons, it points to a systemic failure.

Have you worked for ubiquiti too like GP or are you just sprinkling random whatever words?

They had a coherent point and it wasn't buried in word salad. If you disagree, maybe you could express that with a few less whatever-words yourself.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#618

Earlier quoted context omitted.

This looks like an enterprise perspective. For smaller organisations operating on a single site, some of these concerns won't apply. I also think you're being a little one-sided there because cloud-hosted configuration has its own risks in terms of security and accidentally cutting off your management access, many of them directly analogous to the ones you mentioned, plus you have all the usual concerns about any cri…

> also think you're being a little one-sided there because cloud-hosted configuration has its own risks in terms of security and accidentally cutting off your management access, many of them directly analogous to the ones you mentioned, But with a cloud-managed system you have a professional, single-purpose organization dealing with those challenges. Which you are getting for the rock-bottom price of your licensing/s…

OK, with tongue firmly in cheek, I will try to reply to your points from the perspective of the small organisations I was talking about.

But with a cloud-managed system you have a professional, single-purpose organization dealing with those challenges.

Just to be clear, are you thinking of the professional, single-purpose organization we've been discussing today in the context of a catastrophic data breach, the one we've been discussing in the context of incompatibilities with other vendors, lock-in effects and expensive licensing, or a different one?

Generally these systems only need internet connectivity to change the configuration and for some monitoring features

So as long as the equipment is set up exactly how we need it and never needs to change or be checked for any reason, everything is good. It's hard to imagine why these devices need a UI at all, when the engineer who installs the equipment could just set it up once and then you're done.

In practice, customers are okay with these being unavailable during internet outages as long as both the management platform and the ISP are on a pretty strict SLA.

John: Bob, the Internet is out again. Who do I call at the ISP?

Bob: We don't have a dedicated contact, it's just the business support number on their website.

John: I'm in the queue, at number 17. What's our maximum time for someone from the ISP to contact us about an outage? That might be faster.

Bob: No-one will call, but if it's not back by next business day we do get £50 off next month's bill.

(This is roughly how that conversation probably goes when you're a 20-person organisation with two floor of an office building on a business park outside a small town.)

(Compare, for example, the usual downtime from your 1-4-person IT team not having someone with the right skills on call.)

What's an IT team?

Who has the cash for that?

What cash? When we have a new starter, John or Bob sets up the WiFi on their laptop and company phone and adds those MAC addresses to the whitelist for the network. Normally John works in development and Bob works in sales, but they do know a bit about networks so this is fine. Well, as long as they can get to the GUI, anyway.

Small businesses whose core competence is software/networking, or who by coincidence have that expertise in-house, are a tiny niche market. No one [2] cares.

And yet as someone who has worked for software development businesses for an entire career and whose customers/clients have mostly been other relatively small organisations of one type or another, I have never met one that didn't. Of course that could be because I've tended to work with other technically-inclined businesses, but the same is true even for schools or my own business's accountants. I'm not claiming this is some sort of universal truth, but I don't think the market is nearly as tiny as you're suggesting, at least not in this part of the world (the UK).

Remember, we're probably not talking about setting up encrypted WAN tunnels across continents and multiple layers of switches in a data centre here. We're more likely to be talking about getting an Internet connection with suitable firewall set up, connecting a handful of switches and APs and making sure everyone knows the WiFi password, and installing everyday software on the staff PCs and mobile devices with maybe some basic configuration and enabling updates.

[1] See for example the rise of the Managed Service Provider, which was a large and growing subsegment for Meraki back in 2015 or so. Showing up, installing the hardware, setting up the wireless, and then managing it from your office a few miles away is a big business opportunity, and is a much more efficient use of limited skilled IT labor.

They're not unheard-of here, but again, in my experience such arrangements are far less common in smaller organisations than just having a couple of people on the staff who also "set up the IT" and know enough for the kinds of everyday admin tasks you're talking about.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#620

Earlier quoted context omitted.

The other stuff people recommend is often 2-3x the Unifi price and 2-3x more complicated to setup and configure. I don't know about 2-3x the price, at least not here in the UK. We looked into this when fitting out a new office with the networking essentials a couple of years ago, and Ubiquiti wasn't particularly attractive on headline prices compared to the other typical brands that get mentioned in that space (Mikro…

The prices we are comparing against are Meraki, Aruba, Ruckus, etc. I would be shocked if Ubiquiti was similar in price to those even in the UK.

Who is "we"? You're talking about brands aimed at enterprise customers. I have no idea how much penetration Ubiquiti has managed to make into that market, but certainly around these parts its products are better known in the tier below that. The kind of organisation that is considering Ubiquiti IME probably wants significantly more functionality and scalability than home or entry-level small office gear but isn't working at enterprise scale and doesn't want to pay for it either. That organisation is unlikely to be considering the kinds of brands you mentioned as alternatives, and I rarely see any of those brands mentioned in discussions about alternatives to Ubiquiti.
Post reply on HN