Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

731–740 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#731

Earlier quoted context omitted.

For those people here saying "go Ruckus unleashed" ... caveat emptor my friends ! I have it on very good authority that Ruckus have started rolling out a change in their pricing model to require a Unleashed license per AP to operate, a move which obviously increases costs to the end-user. Some people might say its a deliberate move prevent cannibalisation of their main business model by nudging people away from Unlea…

Can you share info? Because currently for a single site there is no license fee. I've only got one AP at home, but could put a bunch more of wanted. It works so well I wouldn't mind paying some fee, but it'll depend on how much.

@c0nsumer

My earlier comment was based on a change of policy which happened around 1st March, and any Unleashed quotes as of 1st March (and the two-weeks prior) need to be re-quoted for the new "license per AP" Unleashed model.

I've been a bit busy with other work since that bombshell dropped, but if I get a moment I'll try to dig up some pricing.

The other thing to note is feature discrepancy between Unleashed and standard. Perhaps of most interest to your average HN contributor was (the last time I checked) IPv6 was not supported on Unleashed firmware, and not much sense of urgency (if any !) to rectify that.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#732
post #292

Earlier quoted context omitted.

This is not surprising to me at all. IMO, the CEO had a bit of a Steve Jobs hero-worship complex, but only all the bad parts. I can absolutely see him putting two teams on the same project, and "may the best product win". The team that "lost" would get canned, obviously (I saw it happen to two separate offices while I was there).

> IMO, the CEO had a bit of a Steve Jobs hero-worship complex, but only all the bad parts. Part of me wishes Steve Jobs had never been brought back to Apple and died in obscurity. He's such a bad example. People idolize him, but his good parts can't be imitated, his bad parts can, and a lot of people can't seem to tell the difference.

> his good parts can't be imitated

Without dropping acid at work at least, but that seems to be frowned upon these days.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#733

Earlier quoted context omitted.

Do people _really_ need wifi roaming in their homes? I have multiple cheap APs setup in my house using the same SSID and it's fine. As long as I'm not holding a realtime conversation and moving around between APs I never have any problems. And since I almost never hold a Skype call while walking through my house I almost never have any issues.

If you've ever lived in a country where the houses are made primarily of stone, you'd definitely understand the need for it.

A 1920's stucco bungalow with chicken-wire in the walls pretty much acts like a faraday cage in every single room.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#734

Earlier quoted context omitted.

The problem is that on-prem isn't much better in many cases. Only the largest organizations have the capability to operate deep defenses against these threats whether it's the cloud, or the on-prem. If you and your team have the skills you can operate fairly effectively on a small scale, but that's a pretty luxurious situation. Most home users can't tell the difference between a router and cable modem hence it's in t…

The problem isn't Ubiquiti using AWS. It's Ubquiti forcing customers to use cloud authentication.

I didn't make the claim that there is a problem with Ubiquiti using AWS. The problem is that the conditions exist for Ubiquiti to fail with cloud authentication.

If hadn't failed with that it'd have failed in another way. Perhaps that failing wouldn't have been as bad in other cases, but we already see how their products have declined for the same reasons.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#735

Interesting to see what Troy Hunt does next considering they send him free stuff[1] and he speaks highly of them. He's so far only said it's "obviously a really bad look"[2] 1. https://www.troyhunt.com/friends-dont-let-friends-use-dodgy-... 2. https://twitter.com/troyhunt/status/1376998711318863880

I’m not holding my breath. Troy is a consultant. If they sent him that much free gear, what, he’s gonna backpedal and say “I’m removing everything UBNT out of my network”? Definitely not. “That’s a bad look” is a understatement for the giant cluster that this is.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#736
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Would you be willing to qualify your statements wrt Engenius? I've had good experience with them in the past, has something changed?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#737

Earlier quoted context omitted.

The problem isn't Ubiquiti using AWS. It's Ubquiti forcing customers to use cloud authentication.

I didn't make the claim that there is a problem with Ubiquiti using AWS. The problem is that the conditions exist for Ubiquiti to fail with cloud authentication. If hadn't failed with that it'd have failed in another way. Perhaps that failing wouldn't have been as bad in other cases, but we already see how their products have declined for the same reasons.

Without cloud authentication the only way to mass compromise Ubiquiti devices would be to compromise software updates. Which companies do a better job securing usually.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#738

> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed” Perversely, this is exactly the logging that you want to have in place in case of a breach. You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”

Most places I've worked say - do not read other people's patents.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#739

This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.

Are you me? Just finished setting up my Ubiquiti-based home network that includes a dream machine, 6 access-points, and a wireless bridge to an outbuilding. All told about a $1,500 investment I made because I thought I was investing in "best-in-class" hardware and software. Sigh.

As long as you change your UI.com password (and enable 2fa there) and disable the remote administration option, you should be all good.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#740

> Adam wrote in his letter. “Legal overrode the repeated requests to force rotation of all customer credentials, and to revert any device access permission changes within the relevant period.” tsk.

So hackers breached the network and still might have been present. Having everyone reset their passwords at that time is the LAST thing you want to do, as the hackers could have just collected all the fresh credentials, a significant percentage of which are also used for other services because users are users.

Legal made the right decision. You clean up the internals, close the backdoors, and then you notify/refresh user credentials.

Post reply on HN