Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

721–730 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#721
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Check out Mikrotik. Quite similar range of products to Ubiquiti, very configureable, maybe it fits your needs...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#722
post #329

Earlier quoted context omitted.

Just curious (I agree with you), but what are the s/ and /g for? Samsung and Google?

It's how you do a text replacement in VIM, I believe it's s for substitute, /../ for the regular expression, and g for global, to substitute multiple instances.

Don't forget the % if you are using vim, to make sure you replace on all lines :)

:%s/ubiquity/sonos/g

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#723

Earlier quoted context omitted.

The early days at Ubiquiti were good. I worked with a lot of good engineers and we shipped good work. The decline is a recent problem. > How the brand hasn't become toxic already is a mystery to me, yet look at the stock price tracker. It's been trending up for years and it has well over doubled in the past six months alone. This is your answer. No incentive to change. All of the bad engineering decisions have been r…

>I heard rumors that the CEO was making two separate teams work [. . .] separately, competing against each other. I don't work in tech, so maybe I'm dumb to this, but why would you ever do this?

I can see why the idea is tempting, ie testing multiple strategies and survival of the fittest. But in reality there are extreme downsides. Teams will lie and fudge data to get ahead. People dont trust their coworkers.

I think this is where strong technical leadership is needed. At some point someone needs to make a decision on the technical direction and have the conviction to stick with it.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#724

Earlier quoted context omitted.

Do people _really_ need wifi roaming in their homes? I have multiple cheap APs setup in my house using the same SSID and it's fine. As long as I'm not holding a realtime conversation and moving around between APs I never have any problems. And since I almost never hold a Skype call while walking through my house I almost never have any issues.

If you've ever lived in a country where the houses are made primarily of stone, you'd definitely understand the need for it.

Or earthquake-proof reinforced concrete.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#725

Earlier quoted context omitted.

> constant scrutiny for not being secure enough. Do you have a source for this? I follow OpenBSD quite closely and this is news to me..

I haven't got much sources for you but what I've picked up over the years: a lot of OpenBSD's security is just old fashioned manual code review and audits, and there are not enough eyeballs. Someone like Ilja van Sprundel can go in the source code and find a bunch of issues without too much trouble [1]. I don't see any concentrated efforts to improve the status quo (where's formal methods, where's automated fuzzing,…

> if OpenBSD suddenly got enough attention from the wider security community, including people who actively look for holes that can be exploited, there'd be plenty of important stuff found.

This seems like a structural advantage to less popular software. If your software is less common, attackers will have put less time into exploiting it, and therefore you will be more secure. My impression is that MacOS and Linux both benefited from this relative to Windows for a long time.

In general this should be true if usage grows faster than security resources for popular system. It might be still be true even with significant, commensurate investments in security while you grow, because if a small percentage of users mis-configure the software and create vulnerabilities, that population will hit a critical mass with growth regardless of your security efforts.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#726

Earlier quoted context omitted.

Is pfSense, vyos, stuff like that out of fashion? Or too hard to maintain? Automating that stuff with ansible should solve the central management bit...

Can you run pfsense on an AP or switch or does it only handle gateway/firewall/routing tasks?

Yeah, of course you can. It's just a freebsd with some configuration stuff on top, it can run hostap, switch, it can do lagg and span ports and all the other stuff you'd expect... not sure how common it is though

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#727

Earlier quoted context omitted.

Disclaimer: worked for Meraki (now Cisco Meraki) for several years. Generally, halfway decent wireless APs are all targeted at the enterprise market. Consumer hardware is a brutal race to the bottom, as lay consumers aren't qualified to compare options based on anything but price and UI. Ubiquiti was an outlier in trying to bring enterprise features to the consumer market The problem for enthusiasts and small busines…

> having a trustworthy and secured backend. Ubiquiti had a secured backend - their screw-up was not doing MFA on their admin accounts. I would still like if there was an option for a local-only control panel.

> their screw-up was not doing MFA on their admin accounts

MFA is not a silver bullet. You can still login with stolen cookies and 'replay' the session without signing in.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#728
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Mikrotik CAPsMAN

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#729

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Ruckus with the Unleashed firmware. I bought an R610 AP on eBay a few months back, flashed it with the Ruckus firmware (legally available to all from their site), and it does exactly what you want. On-prem only, no cloud, one of the APs will act as a controller/manager for the others, and they can all communicate via wired or meshing off of each other. One of them can even be a NAT thing if you want. I think I paid a…

Same here, I ditched my Ubiquiti and went with Ruckus and I could not be happier. I'm just so sorry that I ever bought into Ubiquiti's marketing when I purchased their AP. The Ruckus performs so much better and the mgmt software is light years better than Ubiquiti. I also run a Protectli but on OpenBSD (from pfsense originally).

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#730

Earlier quoted context omitted.

I just ordered a mikrotik 10gb https://mikrotik.com/product/crs305_1g_4s_in . The guys at work recommended it so hoping for the best!

i've got one of those, and another mikrotik 10gb switch. whatever the 16 port one is. they've been working nicely. i have good luck with fiber SFP+ modules, but it seems picky about 1G copper SFP modules, fwiw.

really i ordered cisco ones do those work?
Post reply on HN