Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

761–770 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#761

Earlier quoted context omitted.

Yeah, but one cannot upgrade them without purchasing annual support contract from Ruckus.

No, you do not need one for unleashed.

Good to know, thanks. I had bunch of Ruckus Zoneflex APs that I could not upgrade w/o contract.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#762

Earlier quoted context omitted.

Can you share info? Because currently for a single site there is no license fee. I've only got one AP at home, but could put a bunch more of wanted. It works so well I wouldn't mind paying some fee, but it'll depend on how much.

@c0nsumer My earlier comment was based on a change of policy which happened around 1st March, and any Unleashed quotes as of 1st March (and the two-weeks prior) need to be re-quoted for the new "license per AP" Unleashed model. I've been a bit busy with other work since that bombshell dropped, but if I get a moment I'll try to dig up some pricing. The other thing to note is feature discrepancy between Unleashed and s…

Thanks! I completely glossed over the IPv6 thing... At home I don't get native IPv6 from my ISP, so I just tend to forget about that. Although it would be neat.

For me I bought my AP on eBay and just plopped the standalone Unleashed firmware on it and that's all seemed fine. In what I see there's nothing changing? But it sounds like you're running a /much/ larger install.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#763

Earlier quoted context omitted.

I just ordered a mikrotik 10gb https://mikrotik.com/product/crs305_1g_4s_in . The guys at work recommended it so hoping for the best!

HN community is in an endless loop of switching vendors: https://news.ycombinator.com/item?id=18200119 IMO using what we have intelligently is easier. Uniquiti hardware has the Edge line of routers and switches that are not cloud-controlled, not listen on any ports, and not establish any connections on your behalf.

True, I bought it because of the 10gb ethernet and youtubers recommending it. I didn't realize it was also a router with a 45 dollar license key. https://mikrotik.com/software

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#764
post #757
post #499

Earlier quoted context omitted.

Google certainly seems to do this when it comes to chat applications. Ironically though, they've actually (arguably) lost marketshare - they went from gtalk being pretty widely used (in the late 2000s, early 2010s, as Android took off), to having a confused and fragmented ecosystem (Allo, Duo, Hangouts, Chat, Messaging), and it seems none of those have the same market penetration as the original did. Perhaps internal…

They essentially destroyed all competition (AIM, YIM, ICQ, MSN etc), the open source solution that would standardize chat (XMPP) and themselves. Making people just go and use proprietary solution like WhatsUp. XMPP was so promising.

Psst, hey, XMPP isn't quite dead yet! Some of us never stopped working on it. Come help bring it back into the hype!

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#765
post #569

Earlier quoted context omitted.

Yes. I run the controller on a raspberry pi 4. Local only. I too am disappointed in UniFi’s direction. I used to recommend them. I don’t now.

What do you use/recommend now?

Gosh. I wish I knew. This thread is rife with alternatives, so other's guess is as good as mine. The unifi wifis I have running are still good and work extremely well. So my suggestion is to keep using them, but only if you host the controller software on your own hardware (I'm using RPi 4 as stated) and only if you avoid their cloud solution(s). (This IMO).

I am still looking for alternatives when the time comes to replace mine. Which I'll be forced to replace once/if they completely nerf the self hosted on self hardware options.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#766

Earlier quoted context omitted.

I'm not sure what you're calling conspiracy theories since it looks like the GP edited his content, but if you think China is not exfiltrating data from hardware, let me know. I'll provide you with copious references from the recent past. Sure, the US is doing it, too.

Please do provide the references.

Here are just a few. There are more if you dig deeper:

https://cybernews.com/security/walmart-exclusive-routers-oth...

https://arstechnica.com/information-technology/2014/04/easte...

https://www.zdnet.com/article/multiple-backdoors-and-vulnera...

Even Cisco was doing it: https://www.zdnet.com/article/cisco-removed-its-seventh-back...

And the NSA was known to be intercepting router shipments to international customers, injecting their backdoors, then re-shipping the modified hardware:

https://www.infoworld.com/article/2608141/snowden--the-nsa-p... (this is documented all of the place; infoworld may not be the best source but it is just one)

For every example that is exposed, it is safe to assume there are others that have not been found.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#767
post #352

Earlier quoted context omitted.

> BigRespectableCompanies Ubiquiti really aren't in the same ballpark as AWS or Microsoft, which are the companies people use that argument for, and you can bet your ass their security is better than in most places.

This is a fallacy. Just because these companies have great security teams doesn’t mean that things don’t fall through the cracks. Shit slips past the security team in product meetings all the time.

This is user error though and not any fault of AWS.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#768

Earlier quoted context omitted.

> Note, however, that roaming between APs is a feature of the 802.11 standard; In theory yes, but man do a lot of devices have terrible roaming heuristics. "I can still see beacons so id better stay here even though i havent received a packet in the last minute. Wouldnt want to pay the time cost of associating with that other BSS that has 5X the signal"

Do people _really_ need wifi roaming in their homes? I have multiple cheap APs setup in my house using the same SSID and it's fine. As long as I'm not holding a realtime conversation and moving around between APs I never have any problems. And since I almost never hold a Skype call while walking through my house I almost never have any issues.

4 floors, 150-year-old brick, random steel girders in annoying places, and a broadband line that comes into the building at almost the least convenient place possible. Yeah, I need roaming.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#769

Earlier quoted context omitted.

If you've ever lived in a country where the houses are made primarily of stone, you'd definitely understand the need for it.

Or earthquake-proof reinforced concrete.

Just brick that's old enough will do it. Mine's something like 150 years old, and it's absolute murder to drill into, just incredibly hard, and it's either dense enough to act like stone, or it's absorbed enough moisture over the years to look like a faraday cage to wifi.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#770
post #501

Earlier quoted context omitted.

Never, ever happened. Ever. You're conflating "NSA secretly rerouting shipping company deliveries to end-users, installing their firmware, then senting it on" with "Cisco willingly did that". Cisco was unaware, and once aware (thanks to Snowden), Cisco took steps to try to prevent it, by altering shipping destinations, at the last minute, on route.

I’m not conflating anything. Check your facts. “ Way back in 2004, Cisco wrote an IETF proposal for a “lawful intercept” backdoor for routers, which law enforcement could use to remotely log in to routers. Years later, in 2010, an IBM security researcher showed how this protocol could be abused by malicious attackers to take over Cisco IOS routers, which are typically sold to ISPs and other large enterprises.” https:…

[flagged]
Post reply on HN