Whistleblower: Ubiquiti Breach “Catastrophic”
krebsonsecurity.com
krebsonsecurity.com
> “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,”
Maybe putting your network control plane in 'the cloud' isn't such a good idea after all...
Edit: Just re-read the article, this part stood out:
> the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies.
> Adam says Ubiquiti’s security team picked up signals in late December 2020 that someone with administrative access had set up several Linux virtual machines that weren’t accounted for.
If this is true, and whoever breached them had full access to their AWS account, can we really trust them to clean up all their tokens and fully eradicate all forms of persistence the hackers may have gotten?
“Help yourself to a free year of identify theft insurance” and all that jazz.
If you discover, you have to report. If you don’t, odds are nobody will notice/will blame someone else.
Me and my colleagues always pushed for more secure setups and configs but the common rebuttal was "no need there's a keycloak running several layers above and you need to use a VPN and need access to AWS first, go implement features instead."
I hope for them that no rogue employee decides to play around a bit or that no one stores their credentials in some cloud LastPass account with a '123456qwerty' master password.
WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is that too much to ask?
The pervasiveness of adtech doesn't cease to impress me.
Scummy? Sure ... especially if you don't have a Ubiquiti gateway but only AP's so the top part of the page is blocked out, but it's not exactly "pushing ads at me!" in the traditional sense - e.g. they're not targetting ads, they're not collecting data.
New UI: Settings > System Settings > Administration > Enable Remote Access
"Classic" UI: Settings > Remote Access > Enable Remote Access
I used to have remote access turned off and accessed the video streams via the iOS app when my phone was on VPN to the local network. That no longer works. Remote access (cloud) needs to be activated in order for the iOS app to work, no matter if you are on the local network or not.
My controller is only on 6.0.43 but i can access it via iOS app on VPN.
My contoller only does Wireless/AP management though. nothing more.
I'm still on version 5.14 and all of the cloud features are optional. I just ignore them. I guess now I know not to upgrade!
It's the right hardware, and great firmware and wonderful flexibility - but it needs an easy to use GUI controller to make the simple stuff easy to take over from Ubiquiti.
I think it's specific to Access Points, so not a general purpose centralized controller for MikroTik equipment, but... centralizing access point management seems to be the main thing under discussion here.
No, you don't? I mean you can but you don't need to.
There are cases when that is useful, true - for example, the automatic channel selection makes some curious choices sometimes.
Even before now there are some limitations with UniFi that have annoyed me. Setting up more complex DNS and firewall rules requires editing the JSON config. IPv6 tunnelling isn’t well supported. The stats in the controller, whilst neat, aren’t very useful because they have to be manually reset to zero.
CLI for Port Forward: /ip firewall nat add chain=dstnat dst-port=1234 in-interface=ether1-gateway action=dst-nat protocol=tcp to-address=192.168.1.1 to-port=1234
VS having to document the same task in the GUI:
IP->Firewall->Nat-> Add New
General Tab Chain: dstnat Protocol: TPC Dst. Port: Port In. Interface: ether1-gateway
Action Tab Action: dst-nat To Address: IP address of Server To Port: Port # of Service
Highly worth getting one to try out.
With the CLI you either need to document it yourself, or you need to know to query if there are any port forwards. That can be a problem if there is more than one person responsible for the network, or if someone else needs to inherit your setup.
Documentation of configuration sometimes isn’t an issue on your own home system because you generally have a high level memory of what changes you made and their purpose. Conversely I still struggle sometimes with Ubuntu because I customise my configuration using command line tools, and I find keeping track of those changes or the implications of those changes is difficult.
This news (covering up, legal overriding good security practices) is super concerning though, and I'm definitely going to start looking around as well.
I would start with a hAP ac², a wireless router that is approximately the equivalent of their hEX Ethernet router plus a dual-band AP (cAP/wAP ac). It's a great standalone device and less than $70, or you could get the individual devices for a bit more flexibility.
Avoid the models labeled "lite", those are low-cost versions with lower routing speeds and 2.4GHz WLAN only.
For management you can obviously configure each device separately, or you can use CAPsMAN where one device acts as the controller and handles all configuration. It's not as slick as Ubiquiti, but it works.
I've got a setup similar to what you're asking for. The TP-Link APs (AC1750, AC1350 and AC1200) support PoE, they're in a wireless mesh, support roaming, and all configuration is handled with one interface, no cloud involved.
Just make sure that what you're ordering says it supports Omada. They still ship a lot of SMB gear that doesn't, but all the basics are there now.
Without those, it takes a little longer for the device to switch APs at the borders of their coverage. Mostly imperceptible, but the longer handoff times can be enough to kill a phone call over iPhone WiFi calling
I've been very happy with roaming/throughput/reliability generally. The EAP-225 is 2x2, which they don't readily announce. Their newer and more expensive units are available as 4x4. That being said they're so cheap, I've been happy just to throw more onto the network.
For the software to manage them it uses some kind of multicast identification scheme to find new APs. If you're on a different subnet then it won't be able to automatically see them. They have a tool to connect to the AP and give it the management server IP, but that's Windows only.
The other option (that I went for) is just to create a management VLAN (good practice anyway) that the controller and APs live on. This is specifically supported by the APs.
I just started using an EAP660 HD[1] at home a week ago, so far so good. Haven't topped out the speeds yet because nothing in my house can take advantage, but I have some AX200 cards coming. I understand there's a throughput bug at the moment that's going to be solved in a future firmware fix[0], but my clients don't go fast enough to hit that yet. TP-Link seems to very actively update their firmware for the pieces I've been using, FWIW.
So I've been pretty happy with it so far. Roaming has been fine, though in one case I think I had non-optimally located a couple of APs because my Linux laptop kept rapid-fire flapping between two of them. I believe that's a client-side problem, though.
I did try a Cisco 240AC and its wifi performance was rock solid. The management interface is non-cloud, and I believe covers the whole network, but it lives inside the AP itself, which I don't love. The management UI is buggy and they seem slow to push bugfixes, and when I added a 142ACM to extend my network it started going flaky -- I had to do a factory reset/reconfigure of the 240AC to resolve it, then it happened again a few weeks later -- so I'm gonna flip my Cisco stuff on eBay. :-(
[0] https://hwp.media/articles/review_and_test_of_the_tp_link_ea...
[1] Tip if you adopt one of these in Omada: You need to give Omada the EAP660's password (default "admin"/"admin") for it to successfully adopt. The other APs never required a password to adopt, so it was a little confusing until the internet came to the rescue.
The layer-3 stuff however is still early days and I can't recommend getting the secure gateway at this time. No IPv6 support. Depends strictly on an internet uplink configuration for default route to which all traffic is then NATted. Can't change that. No real security features, no packet inspection etc. The routing features really feel like an alpha version. They are working on it and have a roadmap to a more workable layer-3 solution. So maybe in the future the will be as nice as the Ubiquity solution.
Cloud is not needed but possible. You can get an OC-200 controller for not much money that fills the role of single pane configuration webinterface. The software for that controller can also be downloaded for Linux on PC or ARM if you want to use your own hardware. Also the network keeps running if the controller is down.
There are PoE devices with OpenWRT support[1] and should be possible to enable 802.11r if they have the support. They can be managed locally even with self-signed certificate.
To somewhat eliminate the chances of adventure, I’ve profiled the setup for each of my many OpenWRT devices and created unique profiles for them in a (reasonably) simple Git repo[1].
All I need to do to get device-specific firmware is to update the OpenWRT version-number in a single makefile and the rest happens automatically.
I’ve even setup Github Actions to build the firmware for me (basically, run make), so I can even get/build new firmware from my phone.
I’ve yet to have any issues when flashing these builds. It used to be much worse when flashing the regular “official” OpenWRT image and restoring packages afterwards.
Couldn’t be simpler! (With the regular Linuxy you-have-to-build-it-yourself-first clause)
I need to get back to trying to build a custom build for my KanKun smart plugs.
Not as comprehensive as Ubiquiti’s management interface but the CAPsMAN feature on Mikrotik routers and APs does cover this use case.
With my 5 year old Mikrotik hAP AC I am able to get up to 500 Mbit/s on lan.
And my old phone now shows 250 Mbit/s on speedtest.net both directions.
How much more are we talking about? Have I missed some big hardware upgrade recently?
I remember that when I had hAP AC using firewall rules inside lan, it also did not go much faster. Good indication was CPU usage. If it used 100% CPU at ~200Mbit/s then it was firewall slowing things down.
I've got some Ubiquiti gear I bought a couple years ago. Like you, I want good quality gear that I can manage myself. I don't need a bunch of fancy corporate garbage, like link aggregation or cloud management. Give me solid, hardware accelerated routing and switching, flexibility over my local DNS, and maybe some VLANing.
I was running Linux on a small x86 box as my last network router. Maybe it's time to get back to that. That or go back to banging rocks together. Haven't decided which, yet.
My plan: OPNsense on a PC Engines board for router + firewall, an unmanaged PoE-providing switch for switching, and something from 2-8 WAPs for indoor/outdoor Wi-Fi.
It's pretty hard to recommend Unifi based on how they handled this breach, but the hardware itself has performed very well. Hopefully the new PC Engines boards can accommodate your needs.
https://teklager.se/en/knowledge-base/apu2-1-gigabit-through...
> APU2, APU3 and APU4 motherboards have four 1Ghz CPU cores, pfSense by default uses only 1 core per connection. This limitation still exists, however, a single-core performance has considerably improved.
I can saturate 1GB/s with no problem OoB on Debian/OpenWRT on APU2/3/4, ymmv
No. They just don't want to serve the low end. I'm from SK, Canada and the vast majority of all businesses are small businesses. This site [1] says 98%. The problem is they only account for about 25% of the GDP, so vendors don't consider them worth serving. Everyone wants to sell to the 2% of the businesses that make up 75% of the GDP.
There's a lot of money to be made in the small business sector. It's just not *enough* money for huge tech companies.
1. https://www.bizadv.ca/by-the-numbers-saskatchewan-business-s...
For example with pfSense going closed source we’d be willing to pay around $100 total lifetime cost to put it on PCEngines hardware. We can build that in to the upfront cost of the device. I wouldn’t be shocked if they try for $50-$100 / year which won’t be economically viable for our market, so instead of getting $100 / device and never interacting with us, we’ll end up moving to a different product. I really hope they come up with an offering that’s appealing to the small business sector, but I’m not holding my breath and I’ll be learning opnsense as a contingency.
[Hi from Regina!]
my experience as a professional "network nerd" is that most other people in the networking field run cheap/second hand enterprise gear fetched from their employer at a major discount and simply seem to care less about wifi in general.
I picked up a pair of Aruba 3200 controllers and a bucket full of APs on a local auction site for a song years back, still does me fine. Then again, not caring about the fastest latest standards is key, if you’re chasing current gen the enterprise stuff is unaffordable. You do need the appetite for a bigger power bill, mind.
EDIT: it's when you get into supply contracts in the thousands .. then it gets tricky
Still, it’s nice to have a hobby, and if you’re looking for one, run your own, sure! No shame in that. But it’s no longer necessary, and that’s pretty swell to me.
^ I agree with why they don’t make that accessible to end users: because people will uselessly fiddle with settings knobs to feel empowered, knobs like “separate 2.4 and 5 networks” (which breaks roaming and makes users incorrectly blame their WiFi routers when PEBCAK is at fault) that semi-expert users feel qualified to mess with, and lazy technicians will use to create “guest” networks that don’t offer protection and perform miserably due to being locked to 5GHz.
I do have requirements beyond what the typical consumer does of their network, like PoE to run a couple of access points, PPPoE so that I can put my modem in bridge mode, the desire to configure extra DNS records, dynamic DNS since my home IP changes. Oh, and let's not forget some filtering/rewriting capabilities so that I can force modern smart TVs to respect the DNS server I provide them.
My network is much more usable having put the time into it. Yes, you could buy some off the shelf thing and get an OK experience, but that wasn't good enough for me.
All of these features are available out of the box and have a GUI intelligent enough to offer a text area for adding filtering/rewriting commands that exceed the GUI’s remit. I used to have to hand-build this. Now I can plug and play it, and end up with the same experience as someone who built their own server and OS, using the same open source components as they would.
Total time invested, 8 hours over 5 years. I’m content with that exchange, and it has come with the only drawback being “it cost money to purchase the router itself”. I could DIY for less expensive in dollars and more expensive in hours. That’s the hobby-or-not choice, as I see it.
I do not decry those who invest time instead. Good, do so! I invested thousands of hours of my life into DIY of this stuff. It was invaluable experience, but it’s no longer mandatory to DIY to get a great experience indistinguishable from DIY.
It would seem the market is RIPE for them to come back into the wifi market with a mesh product.
They do sell mesh wifi products from Eero, Linksys and Netgear on their shop, but I don't think there's going to be any Apple-branded network gear anytime soon.
All my switches are bonded to one another, and it was handy when something snapped one of the fiber runs. That side of the house kept connectivity until the weekend when I could crawl around and run a new cable. (Never did figure out why it broke, though. Guessing the house shifted in just the right way.)
It would have hardly been the end of the world if I had to wait, but if your kit can do it, why would you not?
I would not detract from your network going the extra mile. I suspect that for most people, the value-to-effort ratio of link aggregation just isn't there in a residential setting.
The latest incarnation on linksys ea8500 is slightly bumpy (seems like a kernel crash), but didn’t get annoying enough yet to hook up the serial console and get into kernel bug hunting, yet.
I have about a dozen VLANS that are distributed between different SSIDs and a few L2 switches for wired; bonjour gateway/filtering for the stuff like AirPrint.
It's got a quad-core i5. I run Proxmox and virtualize VyOS as a router, Home assistant, and a couple of other small things like an https reverse proxy for various services that I like to access remotely.
Went this route after my old OpenWRT router couldn't keep up with gigabit WAN. This box has no problems doing so, and even does WireGuard at near wire speed.
There are a bunch of similar units available on Aliexpress, as well as 1U units with x86 CPUs and SFP ports for 10GbE, etc.
I have an ER4 which works for now but plan to go down the custom route once the ER4 is unable to push packets quickly enough. My hope is that VyOS/DANOS is sufficiently stable by then to run as a VM on say a Odroid H2+ replacement (or something similar)
I know quite a few companies that use it in production.
They’re small passively cooled embedded x86 machines. They haven’t made the jump to 10GBit, and their newest model (the apu2) is getting pretty old. However, they have very long production timeframes (many years) for each board config, which leads to stability over time.
Generic Linux or BSD boxes are ok as routers, but they're not the best switches since they start taking up a lot of space if you need a bunch of NICs.
It Just Works.
Apple style. Plug it in. Never fuck with it. Rock solid.
Case studies, focus groups, surveys and interviews are great ways to find the unknown unknowns. Of course, you need to pay people to participate in them, and then you need to pay expensive employees to conduct, collect and analyze the results.
It's often just cheaper to spy on customers, though, and pretend that there is no other possible way to conduct business.
No they're not, because the vast majority of people simply won't be bothered, and most people probably aren't as reliable as concrete data.
Telemetry that tells you which features are popular is useful but does need filtering to avoid identifying individual users. But sending back errors and crashes is what's really important.
You can do things like have feedback forms but typically users don't like sending that in because they feel like they're doing work for free.
You're conflating "NSA secretly rerouting shipping company deliveries to end-users, installing their firmware, then senting it on" with "Cisco willingly did that".
Cisco was unaware, and once aware (thanks to Snowden), Cisco took steps to try to prevent it, by altering shipping destinations, at the last minute, on route.
Don't know if this is the same case still or not, but they did this for FCC compliance around the time 802.11ac was launching. That might have changed that though I'm not sure, I stopped considering them at that time.
Also a good company to look at would be Microtek, I have heard good things, but haven't looked into them directly.
Edit: I got upvoted by somebody, but as an UI user I'm genuinely looking for an answer. If it's still possible to get inside if devices aren't connected to UIs cloud.
1. They are now pushing ads to their local controllers. That is a shady tactic. It also means the controller is phoning home. It means they might have an XSS in that code now or in the future.
2. They just deprecated a bunch of relatively new hardware. If I’m going to invest a non-trivial amount into their hardware I want to know it’ll keep working for a long time.
3. They lost trust due to this breach. How can I trust their code to secure my locks network if they can’t secure their own?
Both will run from locally hosted controllers if desired.
I've been seeing more Cisco "Meraki Go" kit around as well, which looks to target the same use cases as Ubiquiti (very very similar gear, WAPs, low end switches & gateways), albeit without a local controller option, but at least without the usual steep Meraki subscription charges.
Can't see anything on their website for a transition plan in the event of shutdown (and of course, why would they post that and potentially signal lack of confidence in their longevity).
https://www.tp-link.com/us/business-networking/ceiling-mount...
https://news.ycombinator.com/item?id=26628198
Or if you just want Wave1 Hardware...R700/R500
You can get these as overstock on the cheap on amazon etc. The unleashed version means it can run the controller on the AP.
1. https://support.ruckuswireless.com/product_families/4-eol-ru...
I do find myself rarely looking for firmware upgrades unless there’s a specific issue I can’t workaround.
Even on my ubnt equipment. I find it best to just leave it segmented/network isolated and humming.
All these cloud features just increase exposure and grant the vendor leverage to hold you hostage.
I have it on very good authority that Ruckus have started rolling out a change in their pricing model to require a Unleashed license per AP to operate, a move which obviously increases costs to the end-user.
Some people might say its a deliberate move prevent cannibalisation of their main business model by nudging people away from Unleashed. I couldn't possibly comment.
What are you describing here? I have a Ruckus Unleashed that I bought without a credit card and it works fine.
It works so well I wouldn't mind paying some fee, but it'll depend on how much.
My earlier comment was based on a change of policy which happened around 1st March, and any Unleashed quotes as of 1st March (and the two-weeks prior) need to be re-quoted for the new "license per AP" Unleashed model.
I've been a bit busy with other work since that bombshell dropped, but if I get a moment I'll try to dig up some pricing.
The other thing to note is feature discrepancy between Unleashed and standard. Perhaps of most interest to your average HN contributor was (the last time I checked) IPv6 was not supported on Unleashed firmware, and not much sense of urgency (if any !) to rectify that.
For me I bought my AP on eBay and just plopped the standalone Unleashed firmware on it and that's all seemed fine. In what I see there's nothing changing? But it sounds like you're running a /much/ larger install.
As you may or may not be aware, Ruckus have an "all quoted" policy, there is no price list per-se.
At the time I was working on the project (late 2020) Ruckus did have a promotional activity going on where you could buy Unleashed kits at fixed prices without quoting.
However due to various technical questions that were coming up (e.g. IPv6 support) we missed the window and it was uncertain if Ruckus were going to extend the promotion.
Ruckus did extend the promotion, at least initially (Jan-Feb 21') but then they switched to the "license per AP for Unleashed" and the promotion was killed off.
It was at at that point that my friend took the hint and dumped the idea of Ruckus and I went back to my normal work.
If I get a chance I'll try to find out what happens about second-hand kit. My guess would be that if you stay on old firmware there's not much they can do about it. Although whether its desirable or advisable to stay on old firmware is another question, obviously.
Without going into detail because, well, you never know who's reading ....
TL;DR "WatchDog End User Support" is now mandatory for Unleashed and is sold and priced on a per AP per year basis.
The pricing is not too scary (two digit figure per AP per year). But I'm told the requirement is (will be ?) enforced so its unlikely to be a case of being sneaky and paying the first year and "forgetting" to pay the renewal.
I've clearly only just scratched the surface of Ruckus stuff.
This is the reason I went with the Ubiquity UniFi 6 years ago. It was the only one I tried that didn't constantly drop connections or cost a fortune. But it's only G and I've been considering an upgrade, but there are no good options on the market that don't have stupid cloud management bullshit, are built on garbage hardware, or cost an arm and a leg.
I know someone that works there and they seem pretty happy with the place and product. just saw the amazon link now though so that may be a detriment depending on your view of them. (I have never used their systems or anything so it's not really an endorsement but something to consider)
they've been working nicely. i have good luck with fiber SFP+ modules, but it seems picky about 1G copper SFP modules, fwiw.
i checked my order history, it looks like ipolex and 10gtk 1000bT copper modules have had troubles in my mikrotik switches. the mikrotik brand works fine. and every 10G fiber module i've tried has worked (lots of fs.com, and i think 10gtek, and probably some other brand off amazon)
IMO using what we have intelligently is easier. Uniquiti hardware has the Edge line of routers and switches that are not cloud-controlled, not listen on any ports, and not establish any connections on your behalf.
Less dopamine, though.
many people switch not simply for the security/security-theatre, but because they no longer want to support a company with such poor security strategy after it is revealed that they have internal issues.
That's something entirely different from what happened with Ubiquiti.
WAPs have been absolute crap for years.
I'm so sorry. I'll go now.
i recall some features being locked behind a UBNT account, but that was only reporting-type stuff IIRC
https://help.ui.com/hc/en-us/articles/360012282453-UniFi-Set...
It works with their small 16 port (8 PoE switch).
Generally, halfway decent wireless APs are all targeted at the enterprise market. Consumer hardware is a brutal race to the bottom, as lay consumers aren't qualified to compare options based on anything but price and UI. Ubiquiti was an outlier in trying to bring enterprise features to the consumer market
The problem for enthusiasts and small business/home office setups like yours are that both the enterprise market (e.g. Meraki) and the premium consumer market (e.g. Google WiFi) focus heavily on ease of management - cloud controllers are table stakes these days, not a controversial feature. Part of that premium that Meraki, Aruba, and that class of enterprise supplier charge is about having a trustworthy and secured backend.
Note, however, that roaming between APs is a feature of the 802.11 standard; you just need to have all your APs on the same layer 2 (802.x) network, and using the same SSID and credentials. No fancy hardware required, and you can even mix and match vendors.
My kids have to go into settings, reconnect, and move on.
i think it did support roaming in the past and they disabled it in an OS update.
With standard 802.11 roaming, you have to reassociate and reauthenticate to the new AP. While this process is underway, you can't pass any traffic. For open networks or simple auth schemes like WPA2 single-password, this isn't very noticeable; however, for heavier-weight auth schemes like 802.1x this pause is substantial and is especially noticeable on voice/video calls. 802.11r is a scheme for caching the authentication info, letting you avoid the 802.1x round-trip to a central auth server.
For a 5-AP network, usually with shared-password WPA2, it's not necessary.
The security appliance was relatively cheap, then we saw the fine print that the total bandwidth was artificially limited and increased only adaquetly two product levels up. Sorry Mr BubbleTime, you need to buy a new applicance and a new license. Your old one is worth nothing and non-transferable, watch it rot.
The switches seem absurdly expensive when you consider the 5-7 year licensing costs. And the quality is poor at best considering Meraki went and pushed a firmware update that bricked every fan in every 48 port switch we had. But you have the security appliance so it “only makes sense” to pay for these switches.
We had an IPSEC incompatibility between a vendor with an ASA and our Meraki gear. The solution was to buy a Cisco device just for that one connection.
All in all, it’s passable, but because of the lock-in it’s not like I have a cost effective choice to get away from it. I wouldn’t chose it again.
That said, it does offer a mediocre IT tech a single pane of glass they have to try to mess up.
Of all the Meraki factors I’ve learned and considered, that it is cloud-based is the least important towards my recommendation or lack of. There are lots of people that would be happy to explain all the ways my experience is wrong, but whatever.
Short version, I wouldn’t do it again.
It fits well with being able to rapidly bring bodies into a project and implement change X across hundreds of stores, while having a standing IT team of 5.
If you have onsite (fulltime) IT, its likely not the best option.
I'd be particularly interested in comparisons of Meraki/Mist/etc. for small enterprise and campus.
Last I worked at Meraki was 2015; I don't remember any artificial limiting of bandwidth at that time.
Hard in what way? As long as the control traffic has paths between all relevant devices over the management LAN, why does the cloud need to be used at all?
2. Most customers who want this have multi-site setups; in that case, you need paths across the public internet too. Again security footguns, and also reliability ones.
3. Remote work is very very common for IT people.
4. Recovery from configuration mess-ups is harder if your control plane has to run on the same network that you've messed up.
There are on-site controllers available. They've just lost out in the market because of the amount of in-house IT expertise they require. No one wants to deal with that shit, and outsourcing the security and reliability problems to a specialized third party is usually a good idea.
In the prosumer to small business segment, I would argue that there is still enormous potential value in being able to configure all of the network gear from a single GUI, not least because it doesn't then require a lot of in-house networking expertise to get something going that works and is reasonably secure.
But with a cloud-managed system you have a professional, single-purpose organization dealing with those challenges. Which you are getting for the rock-bottom price of your licensing/support plan. Building a good internal IT organization is hard and expensive, and most businesses have other things to do.
> plus you have all the usual concerns about any critical system that depends on Internet connectivity to work properly.
Generally these systems only need internet connectivity to change the configuration and for some monitoring features. In practice, customers are okay with these being unavailable during internet outages as long as both the management platform and the ISP are on a pretty strict SLA.
(Compare, for example, the usual downtime from your 1-4-person IT team not having someone with the right skills on call.)
> and nothing is more flexible for disaster recovery than having someone physically on-site.
Who has the cash for that?
> In the prosumer to small business segment, I would argue that there is still enormous potential value in being able to configure all of the network gear from a single GUI, not least because it doesn't then require a lot of in-house networking expertise to get something going that works and is reasonably secure.
That was my original point: "Generally, halfway decent wireless APs are all targeted at the enterprise market. Consumer hardware is a brutal race to the bottom, as lay consumers aren't qualified to compare options based on anything but price and UI. Ubiquiti was an outlier in trying to bring enterprise features to the consumer market"
I don't know what your standard for a 10-to-50-employee small business is, but "point your browser at this IP address" is usually beyond their in-house technical skills [1]. Small businesses whose core competence is software/networking, or who by coincidence have that expertise in-house, are a tiny niche market. No one [2] cares.
[1] See for example the rise of the Managed Service Provider, which was a large and growing subsegment for Meraki back in 2015 or so. Showing up, installing the hardware, setting up the wireless, and then managing it from your office a few miles away is a big business opportunity, and is a much more efficient use of limited skilled IT labor.
[2] No one with substantial resources and a profit motive.
But with a cloud-managed system you have a professional, single-purpose organization dealing with those challenges.
Just to be clear, are you thinking of the professional, single-purpose organization we've been discussing today in the context of a catastrophic data breach, the one we've been discussing in the context of incompatibilities with other vendors, lock-in effects and expensive licensing, or a different one?
Generally these systems only need internet connectivity to change the configuration and for some monitoring features
So as long as the equipment is set up exactly how we need it and never needs to change or be checked for any reason, everything is good. It's hard to imagine why these devices need a UI at all, when the engineer who installs the equipment could just set it up once and then you're done.
In practice, customers are okay with these being unavailable during internet outages as long as both the management platform and the ISP are on a pretty strict SLA.
John: Bob, the Internet is out again. Who do I call at the ISP?
Bob: We don't have a dedicated contact, it's just the business support number on their website.
John: I'm in the queue, at number 17. What's our maximum time for someone from the ISP to contact us about an outage? That might be faster.
Bob: No-one will call, but if it's not back by next business day we do get £50 off next month's bill.
(This is roughly how that conversation probably goes when you're a 20-person organisation with two floor of an office building on a business park outside a small town.)
(Compare, for example, the usual downtime from your 1-4-person IT team not having someone with the right skills on call.)
What's an IT team?
Who has the cash for that?
What cash? When we have a new starter, John or Bob sets up the WiFi on their laptop and company phone and adds those MAC addresses to the whitelist for the network. Normally John works in development and Bob works in sales, but they do know a bit about networks so this is fine. Well, as long as they can get to the GUI, anyway.
Small businesses whose core competence is software/networking, or who by coincidence have that expertise in-house, are a tiny niche market. No one [2] cares.
And yet as someone who has worked for software development businesses for an entire career and whose customers/clients have mostly been other relatively small organisations of one type or another, I have never met one that didn't. Of course that could be because I've tended to work with other technically-inclined businesses, but the same is true even for schools or my own business's accountants. I'm not claiming this is some sort of universal truth, but I don't think the market is nearly as tiny as you're suggesting, at least not in this part of the world (the UK).
Remember, we're probably not talking about setting up encrypted WAN tunnels across continents and multiple layers of switches in a data centre here. We're more likely to be talking about getting an Internet connection with suitable firewall set up, connecting a handful of switches and APs and making sure everyone knows the WiFi password, and installing everyday software on the staff PCs and mobile devices with maybe some basic configuration and enabling updates.
[1] See for example the rise of the Managed Service Provider, which was a large and growing subsegment for Meraki back in 2015 or so. Showing up, installing the hardware, setting up the wireless, and then managing it from your office a few miles away is a big business opportunity, and is a much more efficient use of limited skilled IT labor.
They're not unheard-of here, but again, in my experience such arrangements are far less common in smaller organisations than just having a couple of people on the staff who also "set up the IT" and know enough for the kinds of everyday admin tasks you're talking about.
"Small businesses whose core competence is software/networking, or who by coincidence have that expertise in-house, are a tiny niche market."
You have that expertise in house. Having looked at sales numbers and market research for a company that sold internationally and cross-industry: yes, your experience is very unrepresentative.
> even for schools...
Tangent: schools are honestly pretty technically sophisticated! We sold to some of them at Meraki, but they were drawn to us more for labor savings than to compensate for limited expertise. Education customers typically had very few (especially in perpetually-underfunded US primary and secondary schools), but very competent, IT people. They were feature-hungry power users.
In part that's because, even with low employee headcount, they have to provide a surprising level of IT services per student as well. A school with 80 employees and 1000 students probably has the IT workload of a white-collar employer with 500+ headcount.
OK, let's assume that's true for the sake of discussion. According to your market research and sales numbers, what is the big market for these cloud-managed products among smaller organisations, and how do those organisations generally manage their IT facilities?
1. Use low-cost consumer hardware with zero centralized management, and set it up with the same expertise and judgment as your typical residential deployment.
2. Have one admin person with the wherewithal work with web UIs, and wants a simple setup-and-forget system. UI not much more complicated than a single-AP residential deployment, user management workflow no more complicated than adding a G-Suite user. If they can use the default password for the admin system, they will (which e.g. Meraki and Aruba don't have in any meaningful sense).
Your original contention was that it's hard to implement a single pane UI without putting a bunch of logic in the cloud. If our hypothetical one admin person with some idea of what they're doing, together with any automatic assistance the relevant devices provide, can set up enough local networking that all of those devices can reliably access the Internet and support cloud-based configuration, then a similar process can set up those devices to support single pane configuration using the LAN only.
At that point, looking back to the four "hard problems" you enumerated a few comments ago, I still don't see a strong argument for needing the cloud dependency.
The risks around network setup and reliability don't seem any worse for LAN-based configuration than cloud-based. In fact, LAN-based clearly has an advantage by not relying on any external infrastructure. It also has the advantage that if you want to get more serious for a larger deployment, you can run independent cabling and create a dedicated management network for control signalling, while most places aren't going to have an independent second Internet connection for management traffic if you accidentally break your configuration so your main data network loses Internet access.
Managing multiple sites is probably a non-issue at this level of the market.
Remote access for IT/support people is easily provided if necessary by having safe and easy VPN setup as part of your user-friendly interface. This has the added advantage that your tech people can also reach any other parts of the network they need, and so you might have required this functionality anyway. And if it's locally configured, you can always quickly shut that VPN access off again in case of any security worries, without needing anyone else's remote systems to be working properly before you can secure your own in an emergency.
That’s a senseless statement in the context of a cloud solution that requires Internet to work.
Ubiquiti had a secured backend - their screw-up was not doing MFA on their admin accounts. I would still like if there was an option for a local-only control panel.
Having your local network depend on an external network makes my old school sysadmin bones tingle for some reason.
They have a good UI, good hardware but the software seems half baked.
Originally with the switch to the "new settings", the schedules were switched between the AP's and the UDM, not sure about a dedicated cloud controller.
Great product, poor QA I think.
I couldn’t see an option on setup.
I might try block it from internet and see what happens.
I am deeply saddened by Ubiquiti’s fall from grace... they were so good.
If I wanted to run it all the time, I’d try putting it in a docker container on my synology.
Instead, I have an sd card for my raspberry pi that has nothing but the controller installed. The main downsides to this are that it is easy to lose the sd card, and that the controller gathers bandwidth/usage/wifi connection reliability stats, but only when it is running. I don’t get those unless I boot up the RPi to diagnose some network issue (this has never been an issue in practice).
One advantage of the RPi setup over a synology container is that it has both a ethernet jack and a wifi adaptor. This is surprisingly helpful when bootstrapping complicated mesh topologies.
https://lazyadmin.nl/home-network/unifi-controller-on-a-syno...
I too am disappointed in UniFi’s direction.
I used to recommend them. I don’t now.
I am still looking for alternatives when the time comes to replace mine. Which I'll be forced to replace once/if they completely nerf the self hosted on self hardware options.
The work flow we used was AWS Vault -> Okta -> short lived AWS creds.
It briefly pops you out to a browser to authenticate and caches a short lived token locally
There's tools like aws-okta that can advantage of that to supply short lived credentials which require 2FA
You could also write a service that requires whatever authentication you want and returns the results of STS AssumeRole
https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_p...
So you're saying it was both not trustworthy and not adequately secured?
MFA is not a silver bullet. You can still login with stolen cookies and 'replay' the session without signing in.
From a couple years back, https://arstechnica.com/information-technology/2016/04/how-h... (the hackers got remote access to a sysadmins desktop then waited til he mounted TrueCrypt and stole the entire contents)
Even with hardware tokens, if someone gets access to your machine while you're using it they can wait til you authenticate then use the creds proxying requests through your machine so they look legit
I will note that as of 2015, "L3 switching" (i.e. hardware-accelerated IP routing) hardware was expensive as hell. I believe that on the software side, dropping new hardware into the existing hardware-routing infrasturcture is fairly easy, but I don't actually know because I didn't work much on MS hardware.
In theory yes, but man do a lot of devices have terrible roaming heuristics.
"I can still see beacons so id better stay here even though i havent received a packet in the last minute. Wouldnt want to pay the time cost of associating with that other BSS that has 5X the signal"
It's so nearly there. The power management stuff means that even with single a physical radio one can associate with multiple BSS's on different frequencies by telling one BSS to hold packets for you while tuning in to the other frequency.
All that's needed to make it reality is a way to tell a BSS "If I fail to ACK a link layer packet, please forward it via the wired network to this other BSS to send to me instead".
Then a client could be connected to multiple BSS's, send packets via either, receive packets via whichever one it is currently tuned into, and not lose any packets while switching.
I have multiple cheap APs setup in my house using the same SSID and it's fine. As long as I'm not holding a realtime conversation and moving around between APs I never have any problems. And since I almost never hold a Skype call while walking through my house I almost never have any issues.
Of course you could say: Does the house have to be designed that way? Do the APs have to be located where they are, is it really necessary to have that stone wall, is it necessary to put the study in the place where it is, is it necessary to have that noise insulation around the elevator? None of that is necessary, but some Mikrotik hardware was much cheaper than getting rid of a stone wall and more pleasant than having to hear it when the neighbours use the elevators.
If I'm in the living room and need to move to the other end of the house to get away from family-related noise, the device needs to roam between two APs.
Unifi handles this without any issues.
It should help high power bad signal (some devices use fixed thresholds) and equalize the beacon vs. data reception quality.
I don't think openwrt had data rate config in webui, but it does support the setting in the config files (that I normally scp onto a device). The following seems to work:
/etc/config/wireless:
config wifi-device 'radio0'
...
option txpower '1' << 1mW (more than enough for 1 room)
option legacy_rates '0'
list basic_rate '24000 36000 48000 54000'
list supported_rates '24000 36000 48000 54000'i hear this a lot but never experienced it myself, maybe related to outdated os?
been running multi-ap with same ssid/key no special sauce for years and it just works.
Not exactly. There are extensions to pre-authenticate with an AP (802.11r) for truly seamless roaming without packet drop or delay and for AP controlled roaming (802.11k) where the current AP tells you your options to roam to. This last one is important because the AP has generally better information about the network than the client and because the clients are not that great at managing this.
I am sure there are other extensions too, but afaik cheap APs don't implement these.
The base standard's behavior requires a reassociation to the new cell (i.e. AP i.e. BSSID). This introduces a gap in coverage, but for simple setups like the 5-AP one IgorPortola is talking - I assumed that this was using shared-password auth - the gap's length is functionally 0. 802.11r gets rid of that gap, which is important when using heavier-weight authentication protocols like 802.1x.
(Note that by 802.x in my original I meant not 802.1x, but rather the set of standards including 802.3 (ethernet) and 802.11 (wifi))
The other alternative is to go way up-market and buy industrial gear. Consumer gear is shit due to a race to the bottom mentality. 90% of consumers buy the cheapest. This is also what turned every TV and appliance into a feature-encrusted shitbox full of spyware.
The OS, TurrisOS, is based on OpenWRT and for a while they were having trouble keeping up-to-date but that's been sorted in recent releases.
There are great features like auto-updates and BTRFS snapshots and the ability to rollback to previous known good if you screw up a config. I also run LXC containers on it for things like PiHole (not on the internal flash but the main board takes an M.2 SSD).
The Turris MOX is a modular Turris system that you can assemble from the parts that you need.
I have a small Gl.iNet router upstairs flashed with upstream OpenWRT that I use as a WiFi access point and have setup 802.11r for BSSID roaming. Have been using this setup for months and handoff has been completely transparent.
They can be a little nasty to users on the forum as well but in general I really like the product.
Check out Ruckus. I've found their 'unleashed' stuff quite nice (no affiliation, just a customer).
(also sell campus controller local no cloud ... but this route is pricey)
Other than ubiquiti I assume you mean? Not that I know of. I want the old ubiquiti back where customers, not stock price and ad revenue, was the focus.
Enterprise solutions with your self-contained WLAN controller and APs (not including PoE switches) are typically pretty pricey (>$5k, can spend a lot more).
We had ubiquiti, but the power outage usually corrupts the controller, and requires constant resetting.
Support/Licensing costs are totally worth it for having trouble-free WiFi with no cloud dependencies (context: using and supported UniFi in various roles since the first UAP came out, and I think was free for UWC attendees, though I could be confusing that with their first camera), but am network nerd that's comfortable with enterprise wifi.
I'm a network nerd that would love enterprise wifi but that seems way out of my price range.
Alix makes a decent router board that can host Linux and dual PCI cards means 5 and 2.4 ghz AP's. the total would be ~200 for each "AP" but they would be pretty massively powerful.
I bought an R610 AP on eBay a few months back, flashed it with the Ruckus firmware (legally available to all from their site), and it does exactly what you want. On-prem only, no cloud, one of the APs will act as a controller/manager for the others, and they can all communicate via wired or meshing off of each other. One of them can even be a NAT thing if you want.
I think I paid around $160 because someone had a bunch of off-lease ones. But if you look up anything that supports the Unleashed firmware you'll be good. 802.1ax is the hotness right now, so the slightly older (but still work great) ones are a LOT cheaper.
I replaced a Ubiquiti setup with a Ruckus R610 and small fanless running OPNsense (Protectli) with a basic switch and POE injector and it's excellent. Sure, it's not single pane of glass for it all, but the AP is rock solid and OPNsense is a solid known quantity. I've got no regrets.
I get that people with larger networks would find centralized management useful, but I'm fine just managing a couple APs, a router, and a couple switches on their own. They're pretty much set-it-and-forget-it devices anyway.
You probably want something like [0], which has PoE support and an optional Cloud connection. You can roll your own automation with (e.g.) SSH access since they are just Linux machines.
All cloud based management stuff is optional and provides TP-Link’s own DDNS support and remote access only. You don’t have to use it.
If you are willing to go this price range, I think FortiAPs feeding back to a Fortigate FW is rock solid solution. But a FortiAP-431F is $616. And a base FG60F as controller is $535 + service if you need it. And although you probably won't need repair options, support/maintenance is a yearly fee ontop of that.
Ubiquity was definately a unique company offering many of the enterprise features for consumer pricing.
I use the TPLink forums to put local management in as a feature request. Perhaps if enough people make a noise?
It needs some getting used to, but preform well.
They have their clod versions also, but they keep putting out non cloud devices.
Setting up a UDM first thing I did was add a local super admin account, then disable remote access. That way, if their cloud auth servers are down I'm not affected as I use the local admin account.
Or something like this: https://www.aliexpress.com/wholesale?&SearchText=pfsense+wif...
Again, dont expect it to be simple. Be prepared to learn.
Is it rally cost and complexity?
Or just missing awareness?
Or the lack of consequences when you get hacked in a way which could easily have been prevented (through then they might have attacked in a different way, tbh.).
Joseph Heller predicted 2FA in Catch 22 when he wrote:
"Almost overnight the Glorious Loyalty Oath Crusade was in full flower, and Captain Black was enraptured to discover himself spearheading it. He had really hit on something. All the enlisted men and officers on combat duty had to sign a loyalty oath to get their map cases from the intelligence tent, a second loyalty oath to receive their flak suits and parachutes from the parachute tent, a third loyalty oath for Lieutenant Balkington, the motor vehicle officer, to be allowed to ride from the squadron to the airfield in one of the trucks.
Every time they turned around there was another loyalty oath to be signed. They signed a loyalty oath to get their pay from the finance officer, to obtain their PX supplies, to have their hair cut by the Italian barbers. To Captain Black, every officer who supported his Glorious Loyalty Oath Crusade was a competitor, and he planned and plotted twentyfour hours a day to keep one step ahead. He would stand second to none in his devotion to country. When other officers had followed his urging and introduced loyalty oaths of their own, he went them one better by making every son of a bitch who came to his intelligence tent sign two loyalty oaths, then three, then four;"
Notice how 2FA turns into MFA? Keep adding FA until you're as secure as the security theater demands.
"To anyone who questioned the effectiveness of the loyalty oaths, he replied that people who really did owe allegiance to their country would be proud to pledge it as often as he forced them to. The more 2factor logins a person went through in a working day, the more secure he was; to Captain Black it was as simple as that"
"Captain Piltchard and Captain Wren were both too timid to raise any outcry against Captain Black, who scrupulously enforced each day the doctrine of 'Continual Reaffirmation' that he had originated, a doctrine designed to trap all those men who had become insecure since the last time they passed a 2factor authentication prompt a few minutes earlier."
Authy Desktop?
You login to a physical machine with a password (the machine is trusted on the network via AD so physical access is one factor and password is a second)
You visit websites and they use SPNEGO to land on Kerberos or NTLM auth which then bootstraps off the fact you're already authenticated to Windows. You never even need to see a login page
It's achievable with macOS and Linux but afaik there's some more configuration to be done. The only place I saw with a setup like that was a bank and it was part of a new technology stack that almost nothing used yet
With that setup there's almost nothing to phish if you can train people to only enter their password into the OS at login. You can pretty much eliminate the possibility of credential sharing but locking logins to certain machines
The attacker had access to the whole database. Which meant he could alter the 2FA seed. So it wouldn't have mattered much.
So with 2FA they would have had a much harder time to gain access to the database.
The part of changing the seed only matters for customers of the hacked company but is (as far as I can tell) unrelated to them gaining access.
Not to mention legacy code that only knows about access key ID and secret, and doesn’t have a place to even put a token.
https://aws.amazon.com/premiumsupport/knowledge-center/authe...
Because it's a giant PITA unless you have a dedicated team managing it. And the service companies get this and charge accordingly (aka enterprise levels).
It's why companies like 0Auth get bought for gigabucks.
absolutely not
It's extremely difficult to lock down an AWS account when there are a bajillion services, IAM policies, roles, etc.. I've been trying for the last few days and it's so difficult that I can understand things like this. I don't think it's acceptable, but I can see how it happens.
I think the expectation for AWS, Azure, GCP, etc. needs to change. Accounts should allow nothing by default and part of the tutorial / learning process should be understanding the permissions needed for each service and how to limit access to those services. As a bonus, they should show you how to configure Budget Actions to catch anomalies and runaway services. For example, I'm trying to set up my account so SMTP access to SES gets revoked for SMTP users if the message count exceeds a certain threshold. It's really, really hard because there's not a single document / guide that shows the process from start to finish.
While your concerns are 100% valid, we need to remember too that setting up access in restricted ways and inviting users to understand the protection and remove the correct barriers, or implement the concerns necessary to interact with those for themselves, always runs the risk that some users will find your protections cumbersome and instead find a (totally incorrect) way to baffle them, or otherwise even route around them entirely mooting any efforts to secure a platform.
And every time I hear this played out in conversation, the answer is "that's on them!" But it's clearly a balancing act, it's a trade off; tautologically, when you make the service less accessible then... it is, well, ... made less accessible.
Besides facilitation of the secure access also sales conversion ratios will depend on that accessibility. The crux of your argument stands, the defaults are too open, and we need to do more to ensure that naive users aren't handed a loaded gun to aim at their own feet.
Especially once you couldn't just login as root anymore in many distros.
The hard part for me is figuring out how to disable access without breaking everything. I know it’ll be useful once I understand and I’ll take the time I need to learn it, but most people won’t.
I prefer the opposite learning direction. Start closed and open the 1 or 2 things I need instead of having to understand 1000 things immediately to configure permissions reasonably.
Can you explain how IAM doesn’t work well with the “starting closed” approach? IAM authorization is “default deny” and every principal needs an explicit allow statement with the appropriate action before authorization will pass.
> Can you explain how IAM doesn’t work well with the “starting closed” approach?
It works ok once you do a lot of learning and read the best practices. I think a lot of people will skip that and use their root account for everything.
The biggest mistake I made was creating an admin user, but giving it too many permissions and using it like a normal user.
After learning more I use the root account to make an admin account, but I think the admin account should only use IAM to create other fine grained users.
So it works fine, but I think it would be better to force people into creating those first couple of accounts with permissions chosen by experts. It’s too easy to jump right in and start using an over privileged account.
Isn't one of the major selling points of cloud-everything "How can you possibly secure your service better than BigRespectableCompany?" I know any time I bring up self-hosting E-mail or a web site or whatever, someone always comes out of the woodwork to remind me that I am not an expert in securing Internet services, and that BigRespectableCompanies have full-time employees dedicated to security. Surely I should be moving to the cloud for this expertise! This is sounding more and more like FUD to me.
As your manager, how can I tell the difference between someone who actually did the work right, and someone who said they did the work right (and also legitimately believes that they did)?
I posit that it doesn't take burning a zero day, or a coordinated effort by the CIA, the FSB, and Randy Waterhouse to break the typical DIY self-hosted security implementation. (And that the manager paying someone to build it has no ability to tell between a great, a good and a bad DIY job.)
Ubiquiti really aren't in the same ballpark as AWS or Microsoft, which are the companies people use that argument for, and you can bet your ass their security is better than in most places.
Once I saw it required cloud login I got scared. After I saw an ubiquiti ssh key preinstalled in a device with unfeteted internet access I shut it down to never bring it up again
1) You dont need to turn on cloud acccess 2) My UDM pro doesn't have ssh open to the world so not sure how that would be useful externally
About 2... I guess when you got access to all their source and infra is just a matter of pushing an update to enable ssh and they don't even need to even push a key. My problem with the keys is that they come bundled with it and you don't know it. There's no reason for them to install a key in there without your consent. Imagine Microsoft presetting an Administrator account on every Windows Server without telling anyone... It's just a security problem, even more in a firewall
The state of security in the tech industry is miserable. The only companies we should trust not to leak our data are those that never collected it in the first place.
Maybe connecting everything to a network and making it a high value target by collecting everyone's data is just a terrible idea in the long run.
Do you have a source for this? I follow OpenBSD quite closely and this is news to me..
https://www.csoonline.com/article/3250653/is-the-bsd-os-dyin...
My concern (and the concern of many others, I think) is that if OpenBSD suddenly got enough attention from the wider security community, including people who actively look for holes that can be exploited, there'd be plenty of important stuff found. Until then, these issues sit quietly waiting for a malicious party to discover them. There's quite some fanfare for OpenBSD, but how many of you are actively auditing the code? I'm subscribed to cvs@ and tech@ and I read them daily and I just don't see much contribution at all from outsiders. And when I do see it, it's mostly stuff like fixing typos or amending man pages. All the commits that change code with security implications tend to come from the core developers, and are reviewed by a handful of people at best. And I have seen some obviously broken stuff slip through.
This seems like a structural advantage to less popular software. If your software is less common, attackers will have put less time into exploiting it, and therefore you will be more secure. My impression is that MacOS and Linux both benefited from this relative to Windows for a long time.
In general this should be true if usage grows faster than security resources for popular system. It might be still be true even with significant, commensurate investments in security while you grow, because if a small percentage of users mis-configure the software and create vulnerabilities, that population will hit a critical mass with growth regardless of your security efforts.
My TL-R605 router, OC300, HD660s, and 8 port 2.5 gigabit switch are going strong, and I put the whole network together for under $1000.
Uh. AWS? GCLOUD? Those have network control planes, maybe not for physical networks, but a control plane nevertheless.
This is the same for any breach. At least if you're using AWS, you know that your management tools aren't lying to you (as long as you assume AWS itself isn't hacked) and you can use those tools to cleanup. If you run your own machines, you can't assume your management tools work correctly. All your machines could have rootkits, all your tools could contain backdoors, and every attempt to cleanup might just be a fake veneer. See Reflections on Trusting Trust.
Full disclosure I work for a cloud computing company (but not AWS).
Yes, if they destroy all of their backups, all of their hardware and every one of their current AWS accounts. Then start entirely from scratch. Any measure falling short of that (and let's be reasonable, it definitely will) means that they're entirely untrustworthy from now on.
Of course having your home network controlled from the cloud should already have been entirely untrustworthy, so in practice it won't be an issue for their sales.
Sure it isnt. It is extremely bad idea and actually something like the ubiquiti breach is not even strange to me, once you have worked once in "enterprise(tm)" world this doesnt seem like anything strange.
There is just no way to buy a router that communicates with 3rd party servers and to let it access the LAN is a complete no-go (even if I am paying ISP router as a part of the package it is running as bridge just to pass the connection to my router).
I consider router as a first line of defense for inbound traffic and last line of defense for outbound and there is just no way to trust some fishy corporation for this.
And if the corporation is actually promoting cloud access, like Ubiquiti or Google, they are pretty much banned from my shopping list for all times.
Trust me, this whistle-blower "Adam" (I have a few suspicions of who it actually is), toned it down.
The reality is much much worse.
The US offices were starting to feel empty because so many people were leaving the company. Only place I've ever worked where engineers would quit before they got another job.
Saddest part was all the wasted potential. There were good engineers making good products at Ubiquiti only a few years ago. Once UniFi exploded in popularity the CEO started trying to micromanage everything and it all started falling apart.
So much wasted potential ... so much customer goodwill wasted because (apparently) no company is worth running unless it is a publicly traded unicorn.
Most successes come with some amount of risk or foresight to anticipate the market.
That's a company that needs to be re-worked from the top. All C-level management fired, no golden parachute.
edit: Robert Pera owns 75% of the company, looks like C-level mgmt will never get fired. If you are at this company, just leave.
Based on this, it seems more like an asshole with some attitude problems rather than greed per se.
Being private and successful is hard to achieve in the Capitalistic world we live in, when you achieve it stick to it.
I think it’s best to be specific.
It’s the C-Suite circle jerk.
My apologies for the language, but throwing away the advantage and further potential of the USA, in the interest of personal wealth and quarterly profits, is even more disgusting.
The majority of America’s management culture is horribly broken.
On the plus(?) side this management culture sometimes allows for easy external disruption.
> Now rewrite your entire comment with sonos instead of ubiquiti.
:%s/ubiquity/sonos/g
In the early days, it seemed like Ubiquiti was going to nail it and was building up a strong, loyal following as a result. Then came all the reports of quality problems, promised features never delivered, phoning-home, ads in UIs, the not just security breaches but cover-ups...
How the brand hasn't become toxic already is a mystery to me, yet look at the stock price tracker. It's been trending up for years and it has well over doubled in the past six months alone. Apparently investors aren't too worried about any potential consequences of all these reported problems.
> How the brand hasn't become toxic already is a mystery to me, yet look at the stock price tracker. It's been trending up for years and it has well over doubled in the past six months alone.
This is your answer. No incentive to change. All of the bad engineering decisions have been rewarded by increasing stock price and continued sales.
Most of the original engineers have quit by now. I lost track of how many UniFi engineering leads joined and then quit after it started falling apart. Before I quit, I heard rumors that the CEO was making two separate teams work on the Dream Machine project separately, competing against each other. That made more people quit. I think they were trying to reboot engineering in foreign countries when I left because it felt like we were forgotten in the US offices.
The router will probably reliably carry me until saturating 1Gbps becomes a daily occurrence and the access point will be retired when WiFi 6E comes around (assuming Ubiquiti's WiFi 6E access points aren't required to connect to the cloud.)
Following is to the best of my knowledge! Any ex-Unifi folks or other pros are welcome to correct me:
- The Edgerouter absolutely does not talk to ui.com (except check-for-updates). There's no remote control ability etc etc.
- The Unifi range can be controlled from the cloud, but via your Unifi Cloud Key. You can run this software yourself, without buying extra hardware. When it is not running there is no comms to the cloud. Run the software, configure things, stop the software - I run it in docker on an rpi4.
I don't work in tech, so maybe I'm dumb to this, but why would you ever do this?
IMO, the CEO had a bit of a Steve Jobs hero-worship complex, but only all the bad parts. I can absolutely see him putting two teams on the same project, and "may the best product win".
The team that "lost" would get canned, obviously (I saw it happen to two separate offices while I was there).
Part of me wishes Steve Jobs had never been brought back to Apple and died in obscurity. He's such a bad example. People idolize him, but his good parts can't be imitated, his bad parts can, and a lot of people can't seem to tell the difference.
Without dropping acid at work at least, but that seems to be frowned upon these days.
Businesses put projects out to tender all the time, and other businesses that can provide what is wanted invest sometimes very considerable resources into putting in a bid, knowing that if they don't make the winning bid then those resources will mostly likely be completely wasted. Evidently it is still worth operating a business on that basis because the benefits when you do win outweigh the costs of the failed bids, and those costs might include reducing morale in a team who worked on a failed bid.
If that is the case across industries as a whole then economically it might make sense for a business to operate on the same basis internally for their Next Big Thing. Run multiple independent teams at the start, give them all the same brief, then see which team comes up with the most promising starting point. I don't see much of an argument for continuing the internal competition beyond the concept to prototype stage, though, unless perhaps it turned out that more than one team could produce a product that was viable in its own right without competing for the same market.
It's also the premise of David Mamet's famous play Glengarry Glen Ross.
A lot of CEOs who think they’re the next Steve Jobs, don’t understand their own tech, and presume the solution to their technical problems is a lack of “motivation”.
Creating a skilled skunk works team to handle a critical problem is a great idea. Making two? And putting them in conflict? It’s like throwing your a steak to your dogs to have them fight over dinner. Idiocy.
Perhaps internal competition to that extent simply confuses customers?
XMPP was so promising.
I think this is where strong technical leadership is needed. At some point someone needs to make a decision on the technical direction and have the conviction to stick with it.
It'll come around, it just takes waaaaaaaay longer than you'd think for a slump in engineering quality to be reflected in the market. Especially with hardware.
We have a few publicly traded clients that we've worked with for decades (and by "decades" I mean longer than I've been alive). It's cyclical that they want our engineering to build new products when they're doing bad in the market, and once our work is released and gets them some success they'll design transfer back inhouse as aggressively as possible (their engineers aren't all bad, it's just not an engineering culture there). By the time we're out, they're still riding the upswing. Their management's institutional memory either doesn't see the cycle and/or they don't care beyond the next few quarterly reports.
What I'm trying to say is I know hurts to see your baby languish but it catches up to them, eventually.
Even with this hack, their stuff is still the best available for home use. Netgear or Linksys consumer routers are awful. The mesh devices are okay, but serve of a different market.
The other stuff people recommend is often 2-3x the Unifi price and 2-3x more complicated to setup and configure.
Any ex-employees want to start a company making this stuff that doesn’t suck?
I don't know about 2-3x the price, at least not here in the UK. We looked into this when fitting out a new office with the networking essentials a couple of years ago, and Ubiquiti wasn't particularly attractive on headline prices compared to the other typical brands that get mentioned in that space (MikroTik, DrayTek, etc.).
However, the ability for non-networking experts to set something up quickly that does the job and doesn't have glaring security problems is definitely a competitive advantage in that prosumer to small business market. None of those other brands has a great UI that I've seen and they all tend to assume that anyone who wants to set up a couple of extra APs for a small office WiFi and a standard firewall for the Internet connection will be a pro-level network expert.
I think it would help a lot of people if better products/companies started to compete seriously on that front, and I have to think that with the SME market to fight for there is room to compete with the established names. After all, that is largely how Ubiquiti themselves broke into the market, or at least that's the perception I had at the time.
Also, there are DD-WRT, OpenWRT and such. How comes people don't use those instead of whatever broken software the manufacturer bestows on them?
Perversely, this is exactly the logging that you want to have in place in case of a breach.
You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”
As an excuse for why to not do the right thing I really hate "plausible deniability".
I'd certainly argue your inability to account for processing operations after having been breached through lacking knowledge of what was done due to a lack of logs was therefore a breach.
I don't live in the US but I've watched as plausible deniability had been deployed there at the very highest levels, with great success, for 4 years.
If you need to search on some of this data you should use blind indexes (Google blind index for more info).
https://aws.amazon.com/blogs/storage/protecting-data-with-am...
Here is how:
1. Login with your online account credentials and password 2. Choose system settings 3. Choose advanced 4. Disable Remote Access 5. Confirm that "Transfer owner" won't be available if you disable remote access.
The issue in general is that the UniFi stuff can be crappy and buggy, but it SUCKS LESS then any other complete solution for a home / small enterprise there at the price point.
I personally used to given them a strong recommendation and even now that is a recommendation with some footnotes. They have been growing to fast and the SW quality has gone down. Being on the latest release is not always the best idea.
To be fair in my I have had many conversation with Cisco that started with "no, not the latest GA, but what is the latest proven STABLE GA."
1. use leaked SSO keys to forge an SSO token
2. craft a malicious webpage
3. get an unsuspecting UDMP user (e.g., me) to navigate to that page
4. run scripts on that page that would access & interact with the UDMP from the browser within the network, using the forged SSO
Is this still a possible vector? Presumably UI would have rotated their SSO keys by now, but since there's no way to disable SSO-based login to the UDMP....
I have also created a local account, that I can use to log in alongside my ui.com one, but I cannot disable my ui.com SSO from being able to sign into the device.
You have local and SSO account.
You disable remote access in your local cloud key.
You open the local IP for the CK and are able to sign in using the SSO account is what you are saying, so auth token is coming from remote.
Question if I got this correct, can you go to the ui.com portal, the UI cloud based one in a web browser do you see the controller still? Can you login and still manage it through the remote web portal? This is what turning off remote access does. You should not be able to manage the system remotely.
Disabling remote access is for the remote web base ui site portal and that should not work after you disable remote access (my understanding). It is possible that you can connect to the local controller and use SSO to authorize vs web and be passed a valid token to login however that would be local only and not remote. Ie the hacker would have to have your SSO AND be on your local network.
Have you tired / are you able to delete the SSO account in the local CK? I have not tried but will later.
Hope that makes sense.
1. Disable "Enable Remote Access"
2. Setup SMTP (since disabling remote access stops routing emails through Ubiquiti's backend)
3. Create a new admin not tied to a cloud Ubiquiti account (via "Administrators")
4. Disable "Sync Local Admin with Ubiquiti SSO" (the older UI says "Enable Local Login with UBNT Account")
5. Delete the old admin account
Steps 3 and 5 may not really be necessary, but I did to be safe.
[1] https://www.reddit.com/r/Ubiquiti/comments/kslyh9/cloud_key_...
I have a few Ubiquiti devices I haven't updated in months, that don't use any cloud accounts, and I used to run their controller software in a container that I only started when I needed to administer something. But now I guess I'm never updating and will be looking to get rid of all their equipment.
What an incredibly consumer hostile and incompetent company. Shame, because the hardware pretty much works reliably.
Am i just lucky or something that i havent been forced to the cloud yet, or is it something i am missing here?
[1]: I don't even remember the steps, to be honest!
A lot of people quite reasonably got CKs seeing them as very easy ways to have a low power always on local controller since they didn't have some other server running 24/7 already. If the firmware on those was updated to require tie-in to Ubiquiti's SSO that's a horrible betrayal. But I'm confident in saying the full standalone Controller doesn't since I have mine locked down from any general net access, remote L3 management was done to IP only at the firewall and I've been switching to just putting it all through WireGuard.
In any case, this sort of a hack of any other company's root users would result in the same spectacularly catastrophic pwnage. That your root users have root access on your own machines won't help you.
What they need is to structure their security properly. I'm not sure why this user needed root access to everything globally for instance? That seems wrong to me at first blush, but it could be a matter of me not understanding their business model.
Ubiquiti has recently been pushing there cloud set up (to the point that you can't set up a local controller with out setting up a cloud account) that's why it's so annoying.
*There is probably a way but the last time I tried I couldn't find it in setup and so installed using a previous version.
Not that this whole screw-up should be excused in any way or downplayed.
The 'in house' software, unifi-video, was discontinued 3 months after I got it set up. All of the apps I use to connect to the system have been pulled from the app store, and you now have to use their camera controller for the one camera, vs the software Im running on my linux box.
Their controller is much more limited, and many, many security camera installers were caught off guard with no path forward for their customers. It's a nightmare of a shitshow and I would never in a million years recommend Ubiquiti as a company at this point.
The Protect app works pretty well now assuming you have a controller to connect to, but the time between the Video app shutting down and Protect actually working properly was very frustrating. I would never trust the Protect app to stay connected while I'm asleep, though. It's definitely not stable enough for that.
(Ignoring the fact that Ubiquity marketed these cameras as having a speaker, when, in fact, you cannot send audio to the camera, only that it makes noise on its own)
My approach has been an isolated (read basically no internet) LAN, bridged by a small PC running hardened and locked down Linux. There's no egress from the LAN. VPN access to this LAN goes via the PC under my control, which itself has access to the wider internet via its second interface.
This approach is nice as I don't have to trust any router vendor or proprietary software vendor to be competent, by relying on their equipment to control internet access for devices. Although I recognise this is probably inconvenient for users, none of this is really too impractical - a bit of adverse publicity for cloud and "internet connected", and I could see properly firewalled, egress blocked networks taking off...
(I am more concerned about egress than ingress, because it's the biggest gap most people forget about, and most people just rely on NAT to stop ingress, forgetting any device can phone home anywhere, and they're not monitoring... I don't even allow DNS on that network. IoT that can't handle this just doesn't get in the door)
Settings one up is easy, blocking internet for a network device on the router level is trivial. No need for complicated setups IMHO.
I don’t trust anything that tries to solve the “firewall problem” by setting up a cloud service for what should be a local appliance.
Just finished setting up my Ubiquiti-based home network that includes a dream machine, 6 access-points, and a wireless bridge to an outbuilding. All told about a $1,500 investment I made because I thought I was investing in "best-in-class" hardware and software.
Sigh.
Not buying any more hardware from them though, unless things significantly change.
A root user user breach, seemingly on the organization main account. Ouch.
I wonder if MFA was set up, with the TOTP creds also kept in LastPass.
Hardware keys?
Generate a long random password, print it out and then lock it in a safe without allowing anyone to see it.
Turn on 2FA and then lock the second factor in a different safe.
There’s virtually never a need for the root account and it’s impossible to attenuate (by design).
MFA is the important one to keep it safe for AWS root accounts, set for the master AWS account and lock root access for all member accounts via SCPs.
The privileged IAM user should then be used to administer other IAM users and roles. All IAM users should be required to have hardware security keys like Yubikey.
Is something like kidnapping in the threat model for companies like ubiquiti?
I doubt it. That's going to raise some blinking red flags on the radar of organizations you don't want to be on the radar of. Not just three-letter federal organizations, but three-letter news organizations too. The current situation is Yet Another Security Breach that will be forgotten about in 15 minutes. But a kidnapping is interesting! People will be making documentaries and shit about that.
It's so much easier and cheaper to bribe people than it is to kidnap them.
IAM doesn't even let you register more than 1 MFA device.
Longer term I expect AWS will add this capability.
The situation is somewhat more relaxed with GCP Billing Accounts and Azure EA Accounts, though they have better separation of concerns than AWS (billing vs. workload access). Nonetheless, never give these passwords to finance department lest they store it in an excel sheet on a SharePoint. Access to these credentials allows anyone to suspend billing for an entire enterprise... not sure what controls the providers have in place to verify any of this before initiating automated shutdown of all workloads.
- private keys for ssh, gpg, vpn auth
- 2fa for sudo access, password manager access, etc
Why do password managers let people store TOTP next to the password, this completely invalidates the 2FA of TOTP if your password manager get broken into.
I think that's the big "if". If you assume the password manager is secure (which something clearly wasn't in this case, but that seems like an outlier), TOTP secret in the password manager still secures the account.
Is such a setup as protective as a separate storage method? No, but it's leagues more convenient. A cloud-based PW manager also solves the problem of a lost/broken/new phone causing you to lose all of your 2FA setups. Some 2FA apps do as well (Authy, iirc), but trust me when I say people lose 2FA codes _all the time_. And then 2FA needs to be disabled by support, which is its own can of worms.
The best security measures are the ones people actually use. If not having to use a separate app is the convenience people need, then I think it's totally worth it.
Which, incidentally, when you store you TOTP secrets with your passwords, is what you have.
The F in 2FA is factor. Satisfying one login request from one factor (password vault) is 1FA. This is why the second factor is normally something that isn't your password vault (historically your head, now a piece of software): a hardware key, a recovery code, etc.
A slightly more generous interpretation is 1.49A (rounds down), because someone with a reused username/password combination. But if you're using a vault with a sophisticated factor, the venn diagram of "people who have your password," and "people who also have your master password," are pretty tight, except for cases where the provide has been breached (all bets are off).
Don't dispose of the second factor for convenience.
Colocating the storage factors definitely makes certain attack vectors possible that aren’t otherwise possible, but it’s still 2FA. Are hardware keys best? Likely, but still many probably have their password vault and TOTP application and storage on the same device (e.g. both Bitwarden and Authy on their mobile device) which is a middle-ground convenience vs. security between TOTP in the password vault and hardware keys—but I doubt many would say that it’s not 2FA.
I have my password in a password database, and my TOTP tokens on my phone and a Yubikey.
I have a second “break glass in case of emergency” password database that contains TOTP secrets for all my most essential accounts and a backup of the key loaded on my Yubikey.
One absolutely invaluable use-case is that it lets multiple employees share access to an account with 2FA enabled.
Many systems don’t have appropriate role/permission systems to allow for 2FA otherwise.
Also, how is this a securities case? The company did not disclose the scale of the breach to shareholders.
It's already started.
'SHAREHOLDER ALERT: Ubiquiti, Inc. Investigated for Possible Securities Laws Violations by Block & Leviton LLP; Investors Should Contact the Firm'
Everything is securities fraud.[0]
[0] https://www.bloomberg.com/opinion/articles/2019-06-26/everyt...
> For example, in January 2021, we became aware that certain of our information technology systems hosted by a third party cloud provider were improperly accessed and certain of our source code and the credentials used to access the information technology systems themselves had been compromised. We received a threat to publicly release these materials unless we made a payment, which we have not done. As a result, it is possible that the source code and other information could be publicly disclosed or made available to our competitors. Due to the nature of the source code and the other information that we believe was improperly accessed, we at this time do not believe that any public disclosure will have a material adverse effect on our business or operations, but it is impossible to gauge the precise impact of any such disclosure. We have taken, and will continue to take, steps to remediate access controls to our information technology systems.
http://ir.ui.com/sites/default/files/2021-02/ui-10q-12-31-20...
tsk.
Crazy.
Of course it looks even worse now that we know they didn't do anything to help customers.
But telling your client to sweep something like this under the rug isn’t exactly great advice.
Legal made the right decision. You clean up the internals, close the backdoors, and then you notify/refresh user credentials.
https://finance.yahoo.com/news/shareholder-alert-ubiquiti-in...
It seemed to me Ubiquiti would never allow customers the option to install their own OS (e.g., BSD) or boot from external media containing a non-Ubiquiti OS, without sacrificing the benefits of hardware specs that were likely deciding factors in selecting the Ubiquiti hardware above existing alternatives. The intent was clearly to have Ubiquiti retain control over the hardware after purchase. The customer effectively remained tied to Ubiquiti forever, so if the company started serving ads, using AWS unnecessarily, etc., there's no way to opt out. Customer is compelled to accept all updates.
Specs are important, but maybe not as important as control.
Reliance on third parties necessarily increases potential risk. Unnecessary use of third parties is, IMO, poor decision-making. This is of course rampant in "tech" and, IMO, marks a triumph of the salesforce for those third parties over common sense, possibly assisted by network effects. Further, I dislike products where there is a heavy focus on opaque "updates". Again, many customers have been trained to believe that not updating is always the wrong decision. (Meanwhile they have no idea what is in each update.)
As stated in one of the blog post comments:
"It is even worse: Ubiquiti forced all users to use cloud-based authentification even for accessing your controller software on a local network with a local client. This was not even properly communicated but deployed by one of the regular maintenance updates."
Ubiquiti sells turn key HW and there never was any hint that this was HW you could roll you own on.
I could buy APs that I could install OpenWRT. I could setup an OpenBSD firewall. I could run my own DNS. I have done all this in the past. The point is I do not want to anymore. I have better things to do with my time. So as a turn key solution that is "prosumer" their kit works and I think you will find that is why most people here have recommend it.
You can disable the Cloud connection and I posted how in this thread. People on HN are tech savvy enough I sort that part.
The fact of the matter is they had a bad security breach and they have a cloud connected platform. Ops. That sucks. But the reality is that market forces have pretty much tied evaluations to cloud connections and telemetry gathered from it. That is the part that REALLY sucks. I do not blame them for trying to make money. I am angry if they were less then truthful in the details of the breach and I am sure both the SEC and the court of public option with punish them.
For my part, I have no plans to replace the 4 switches in my house with boxes running SONiC nor the 4 APs with OpenWRT or my firewall with OpenBSD because I just really do not care to have to maintain it, and if I drop dead tomorrow my wife can likely sort the UniFi stuff (as I have documentation on the setup) but there is no way could she sort the roll you own.
Uh? that is demonstrably not true. Any more details?
But shady as f*ck and kind of sets the tone.
I run plain-vanilla Debian on all my Ubiquiti boxes, six or seven of them at this point.
debootstrap --arch=mips
Octeons are awesome. Ubiquiti hardware is the bomb. I hear their software is junk, but I wouldn't know anything about that, I always erase it right after unboxing the device. man debootstrap
for details. Debootstrap is the tool that generates a "minimum bootable rootfs". You can use any existing debian install (even a non-mips architecture) to do the debootstrap.You will need to build your own kernel. Check the OpenWRT project for patches, although only a very very few Ubiquiti devices (USG-3 for example) need kernel patches. For other devices (EdgeRouter-4) the OpenWRT packages make things nicer, like getting the network device names to match what's printed on the front of the case.
Put the kernel and rootfs on a USB stick, plug it into the router, attach the serial console (nice easy RJ45 jack on the front!) and boot. Once it's up you can migrate stuff to the internal soldered-down emmc.
Octeons are awesome.
If you and your team have the skills you can operate fairly effectively on a small scale, but that's a pretty luxurious situation. Most home users can't tell the difference between a router and cable modem hence it's in the interest of cable providers to lower support costs by providing a managed offering. It's terrible from a security perspective, but customers have signed that away.
The common theme running through these breaches is that the organization isn't necessarily small, but they aren't Google/Apple/Microsoft-size either. Those companies have multiple layers of expertise and the cash flow to hold up development of anything in order to make sure things are secure. It's hard to wing stuff once the bureaucracy understands security is needed. They even start pushing their product security initiatives outside of product development to mundane departments because they get attacked by very smart actors. You can see from the news it's still far from perfect.
Once you get to companies the size of Ubiquiti, you start having challenges with implementing close to the same degree of security because you don't have float in the system to allow for additional costs, delays, etc. on top of the lack of expertise. Apparently Ubiquiti have been hemorrhaging expertise in other areas due to opportunistic cost-cutting, so it isn't a surprise that they suffer and respond in this way given that culture. A bad security decision by one exec in companies of this size can cut across many departments which doesn't happen in the behemoths.
If hadn't failed with that it'd have failed in another way. Perhaps that failing wouldn't have been as bad in other cases, but we already see how their products have declined for the same reasons.
One of the truly sad things about all this though is precisely that UniFi made this a lot easier for small orgs and even individuals (and could have gone even farther). Stuff like VLANs and RADIUS became dramatically more accessible "for free", using just what was built-in to a UniFi stack someone might get anyway. Back when they were still more competent Ubiquiti added management VLAN support across the lineup, and the setup is fairly intuitive and then just works. At one point I'd hoped they'd continue in that direction much more. It's not some impossible thing, it mainly just needs better UX putting the pieces together in a graspable way. Graphical VLAN topologies and point-and-click, automating all the certificate authentication/signing stuff, the generation of profiles for onboarding, all the components for this stuff exist right now just not, well, unified.
I think a lot of places don't want to in fact, because they'd rather push cloud ties since that can yield subscription revenue.
As far as the team having skills, there is not much that ubiquity does that can't be handled on prem, I mean you're already installing physical devices, how much more effort is it to install a controller? Sure, that means you're on the hook for upgrades, but in most cases you're better off not getting them instantly anyway.
And to clarify my point about ISP gear, I agree that the average user can't be expected to understand or care. I meant so called technical users.
Counterpoint: https://en.wikipedia.org/wiki/2021_Microsoft_Exchange_Server...
Aaannd this is why we can't have nice things. Like trust in our vendors. Or security. Or consequences.
The interesting part of this story is how the employee's LastPass got popped. My guess is their local workstation was compromised, and their LastPass was either not logged out in a browser plugin, or they didn't have 2 factor auth required for each login and a keylogger got the password. In either case, it's a good reminder to be paranoid about your password manager, make sure it's got a logout timer, and use 2 factor auth.
I also don't let my cloud password managers touch a mobile device. It's fairly inconvenient, so I hesitate to recommend this to others. But I don't trust mobile devices very much. Anyone have thoughts on this?
You mean someone was physically at the laptop/desktop and could access the OS and apps? Maybe if the employee was working remote (covid?) from, say, a cafe and left the laptop unattended when refilling coffee?
Or something else? ... Hmm, could also have been eg a browser zero day that gave someone remote access to the computer? Or a dev tools supply chain attack?
Honestly I don't think it was even that complicated, considering when I needed to spend money on some SaaS product the "chief accountant" (because there was no CFO) straight up sent me a photo of the corporate credit card and said "delete that when you're done".
The magic thing that absolutely sold me on their equipment was the ease with with you could provision and mesh new gear. Does anybody have anything that compares with that ease of use?
To explain what I mean: I recently had a buddy move into our guest house/apartment. While we waited for the ISP to come out and hook up his internet, I just put an AP on his counter, powered it up, and meshed it into our home network. The whole process took less than a minute and didn't require any running of ethernet.
(Maybe that's a common feature nowadays and I've just been out of the industry for so long?)
Smaller threat area, much larger utility plus they by default have more resources than any other company to have better security.
Don't get me wrong, I was looking forward to moving to ubiquity but that's not happening anymore unfortunately.
As far as I'm aware Google has not had this magnitude of hack recently.
I have had plans kicking around for a bit over a year to do a full build out using their products, and just within that time it seems like they've gone from a glowing reputation to severely tarnished. Unfortunate, as it seems like they once had great products.
An individual vulnerability in a device is an issue but it gets patched. Hopefully it can't be exploited remotely. My biggest annoyance is when "infrastructure" ends up with outside connections in place (to the cloud or elsewhere), that breaks this model down (trusting the provider to mediate remote access, for example).
They're a big single point of failure, and this incident really proves that.
Technically EdgeRouter gear is unaffected as it's very cloud-optional, but I can't bring myself to trust any firmware from them at this point. It supports OpenWRT so I guess I'll install it and go back to OpenWRT.
I see this thread already has people discussing alternatives, so I won't ask for ones -- just had to put it out there that if you own an EdgeRouter, chances are that OpenWRT has a build for it.
The other way I think of it is, I don't use it right now. It likely has open doors, intentional or unintentional. If the open doors are widely discovered, reliably closing them seems difficult. The highest-leverage point in time to influence this story is before I start using it. "The only winning move is not to play."
Feedback appreciated on this thought process.
I see it no different from driving a car. You can get carjacked, you can get in a crash, you don’t just not drive a car because of it, you just calculate your risk tolerance and do it.
$50 isn't a reasonable payoff for most carjackings, but this isn't like a carjacking. They're doing the same thing at the same time to 1000 people using a script they wrote. That changes the payoff, and that means more people are likely to try to do something like this.
This is an extremely mild scenario. It's possible I'm wrong about IoT, and there's a case for using it in its current state. But one thing I'm _sure_ of is that analogies with cars don't work.
this is the other side of the coin of "you don't need privacy if you have nothing to hide", and it's exactly as stupid in application here as it ever is.
Holy...
Wow. That is catastrophic. Everything is compromised. That's a complete rebuild.
How are we ever going to solve security as an industry against this? Again we're told that security isn't important. Being the first to market and insecure is the winning play and that's just fucked.
SolarWinds is actually trading almost $2/share more than it did 1 year ago today ($15.67 v $17.23). Sure, it is down from its 52 week high ($24.34).
I would argue that SolarWinds should not be allowed to be in business in its current form, considering what a threat they have been to themselves and others in their mis-handling their software practices and subsequent breach. If an individual did what they did as an employee of the government, they would currently be in jail.
It is probably one of the most impactful national security events in our lifetimes and the impact of this event will be felt in certain areas for years or even decades.
But how do we achieve political intervention when technologists and politics appear to be completely incompatible? The closest I've seen is the Pirate Party which never get more than a few percent or that democratic candidate (Yang was it?) and he was pretty fucking clueless on the tech when poked with any significant vigour.
Cyberspace Solarium Commission [1] created a robust and well documented roadmap for the Biden transition team to address some of these fundamental problems. IMHO, it is one of the better policy documents and has a number of really good recommendations that I believe would be extremely helpful. The #1 thing I think we could do is address accountability, who is responsible for the security of devices/software and what legal recourse should people have if the vendor doesn't adequately secure or support their products.
I think that there are a bunch of issues and one of the biggest ones is that what we say vs what we do are 2 different things. We also have issues where many of the core business practices that are commonly accepted are incompatible with building a secure and resilient infrastructure.
[1] https://www.solarium.gov/public-communications/transition-bo...
In the 15 years I've been using OpenWRT, I have never been disappointed with it, and I don't have to worry about some company's "secure" backdoor into my network being exploited.
I haven't found the need to upgrade my hardware in a couple of years so I don't know what the market currently looks like. I'd just look on the OpenWRT wiki or forum and see what is best supported and buy that.
Also, Atheros radios are generally supported really well on Linux, so I stick with hardware that has an Atheros chipset over something with a Broadcom radio.
Probably why they got into this mess. Lots of successful product people deferring 'non product' stuff.
Brian Krebs is a reputable source who has a lot to lose if he makes unsubstantiated claims.
> if you did nothing but read about them on HN, Reddit, et al, you would think they're filing for bankruptcy tomorrow, set orphanages on fire, kill puppies, etc.
I need to check these posts ;)
Maybe we're the anomaly, but I have a feeling 2 years from now if they continue down the path they're on, their earnings will not be quite so rosy.
I know of at least two others that currently have hardware on order to replace existing ubnt routers with OPNsense so you can add them to the list by the end of April.
1. https://www.troyhunt.com/friends-dont-let-friends-use-dodgy-...
I'm still happy with the value, stability, and security updates (!!) of my UBNT hardware.
I still won't buy gear from another vendor that wants $$$/device-year in support contracts and have unavoidable cloud controllers.
I’m looking for a proper post-mortem and the steps to make sure it can’t happen again, recommitment to local-only users and respect of the customer, and a step back from the push to cloud everything.
Floundered some with random enterprise access points used off of ebay that either drew too much power or was still buggy (netgear was the worst).
Then I came across Mikrotik. Their hardware and conformance is somewhat dated, but I've never had anything run so stable. Haven't looked back and been going on 4 years now.
What legal reason would exist for that? I thought legal would instead force them to save their users, since otherwise they would risk getting sued by all of them by all the damages caused or something.
Legal isn't there to make sure the company complies with the laws. Legal is there to advise on and minimize legal risk.
Breaking laws is one sure way to increase legal liability.
I'm sure someone in legal knows someone at the AG's office who might be "considering the private sector" in the near future.
"It's not like we're building bridges or something." -- any legal department when faced with engineers' ethical duty to report a hack.
I'm sure their lawyers don't know anything about tech or forensics, but they know how buy shareholders time in a way that minimizes anyone's chances of going to prison or facing serious civil liability. If you ask someone in charge of hiring corporate counsel what they look for in a lawyer, they will flat out tell you "a good risk manager who understands discretion" which just means "someone who's going to tell us what we can get away with".
The regulatory system in the US is sufficiently dysfunctional that there is zero incentive for corporate counsel to even consider what's in the best interest of consumers.
Good legal departments understand that the company is there to serve the users and make them happy and operate within those constraints (even trading off possibly liability when it makes the products sell better).
Horrible legal departments will block anything that has even a smell of liability, even when it comes to sabotaging the product itself and hiding serious issues from users and employees.
I've met way too many ones from the second group.
My needs definitely don't exercise corner cases. Most of the UniFi gear I've got out there is just running a single SSID w/ WPA-RADIUS and a RADIUS-assigned VLAN. Here or there I've got an SSID w/ a PSK and a hard-set VLAN. Nothing too fancy. Adopting new APs quickly and easily based on a "magic" DNS name, alerting when an AP disappears, and syslog to show association/roaming/disassociation events is about all I want. I'm putting Customer-owned gear in small offices w/ under 10 APs, rather than being a service provider.
I guess just change your password and reset your 2FA?
Never again with the cloud-connected network appliances. Time to build a router from scratch, I guess.
1. https://help.ui.com/hc/en-us/articles/360012282453-UniFi-Set...
Your post seems to imply you have just that AP and that's it? If you set it up initially (putting the controller on one of your own computers temporarily maybe), and then just left it standalone from there on out you're fine. There is no need to have an active Controller for all the hardware to work as configured, a Controller is just needed to change configuration, collect real time statistics/send notifications, and do necessarily active things like run a guest portal.
If you are running a Controller, but you're doing entirely standalone on your own hardware (or your own cloud service for that matter), and haven't enabled Ubiquiti SSO cloud access, you're unaffected. That's how I've always run since I don't trust 3rd party cloud stuff for something like this, ever.
It's """only""" an issue for their cloud service, and apparently their "Cloud Keys" and "Dream Machines" as well since they pushed it on people some recent firmware. Which granted covers a lot of surface area, and Ubiquiti has pushed very, very hard (see advertising outrage from just a few days ago). But it's thankfully still not everything.
>Your post seems to imply you have just that AP and that's it?
I recently moved to a house with a preexisting network, so I have only the AP itself set up with the Ubiquiti router/network controller still in storage. I use the mobile app to configure the AP. It sounds like the AP won’t phone home or open tunnels to their cloud by itself, so I’ll turn it back on for now.
Saying its only a db *that they know of*.
What about the software repositories that they host somewhere?? Did the admin have access to that?
This is pretty major....
The issue has been there for 2 years -- which is beyond odd. When I've reached out to tech support the issue was effectively closed as known issue.
[1] https://community.ui.com/questions/Tokenization-for-Stripe-I...
Guess I will just have to go bargain hunting on the used enterprise market, or just ask my BigCorp networking team to see if they sell or give away any of their equipment and try to repair it myself. My only concern would be noise generation and power consumption since they were built for use in data centers.
But less academically it's depressing as hell too, because the grapevine liked them for good reason and there still isn't any drop in replacement. Their p2p/p2mp gear is still solid. And UniFi was a wonderful concept solidly executed. It also eschewed the subscription/cloud bullshit so many other players are chasing, which indeed is something of a saving grace here. While there is a cloud option, lots (if not most) people can and do run their UniFi networks completely self-hosted even for remote sites. The single pane of glass, ease of provisioning and recovery, etc made sense and saved time. And they had an incredibly enthusiastic and supportive community, like when they asked about moving L3 switching way back on the old forums (back when the rot was in its earliest stages and not clear yet) they got huge amounts of feedback, their beta testing had many people putting in a lot of good work.
Such a damn stupid waste. And the nature of the beast for tech infrastructure is that market signals are always behind the curve and thus muted until things are already getting to be too late. Robert Pera also owns the majority of their stock IIRC so there isn't any way to effect an outside management change there either. It is odd to me that nobody has sought to go after them directly and aggressively, though I heard rumblings late last year that Cisco was giving a go at something clearly aimed right at the UniFi market (no subscriptions like Meraki)?
At any rate, final straw for me on routing was the flop their "UXG" has been, I finally gave up at long last and began migrating everything to OPNsense a month back. And once the single pane of glass is broken, the barrier to start moving more drops in turn and network effects (harhar) begin to go into reverse. I'd still be happy if they somehow recovered, but if they do I think it'll be a long time. Problems that build for years tend to take years to reverse too, if they can be. I hope we get some stories someday internally on how it all went down.
Then again we have a "clear skies" policy & wouldn't have bought anything that requires cloud blah. (Which covers a whole bunch of other vendors too, looking at you Cisco "SmartLicense")
Not good!
http://www.globenewswire.com/news-release/2021/03/30/2201903...
When looking for leakers internal security auditors don’t need proof you are Adam in order to fire you. They just put enough pressure on the most likely Adams such that they quit.
You will be one of them. If another Adam does so, so be it. Your actions likely flushed the other leaker when you thought you were the only one. You won’t be able to handle the pressure. Neither could she.
Adieu, Adam, et al.
Until these companies are held massively accountable for such negligence, nothing will change. Similar to what happened to Facebook and all they had to do was pay chump change fines.
https://www.theregister.com/2015/08/09/ubiquiti_stung_by_ema...
They're used as a bad example in my annual corporate infosec compliance training.
So the laptop probably had some malware/keylogger on it that was able to pick up some data in the lastpass browser extension or something?
Speed tests are pretty unreliable, but the peak unobstructed wifi speeds I've gotten from that have been better than what I get from my Unifi 6 lite, which supports wifi 6, even on wifi 6 devices. (couple hundred mbps on a home gigabit plan from Nazi Germany I mean Comcast)
EDIT: it's called the T-Mobile AC-1900
> DD-WRT has a license agreement and NDA in place with Broadcom that allow usage of better, proprietary, closed source wireless drivers (binary blobs) which they are not allowed to redistribute freely.
I bought the TP-Link first. It worked, but it's an underpowered device and it was struggling to keep up with all the devices on my network. It also has a MIPS chip so it couldn't some ARM only software I wanted to use.
I replaced it with the Linksys. I had nothing but problems with it. It was fast and reliable using the Linksys firmware (but functionality was severely limited). When running OpenWRT it was a buggy disaster. One example problem, it would randomly start dropping bonjour packets for no explicable reason thus preventing my wife from being able to print from her iPhone. It had to go.
I was about ready to give up on my OpenWRT dream, but I took one last chance and bought the Netgear for cheap off of eBay. It's great. It's fast, it's reliable, and so far it just works (been running it for a year now).
So the C7 is good if your needs are limited, but I really do recommend the R7800. It's a very nice device and you can probably find it for cheap on eBay like I did.
Why? Coincidence?
Would be great to better understand how the Lastpass credentials got leaked in the first place.
Anyone found any comment on that?
I never did because I thought it looked like asking to get pwned.
There were some other suggestions in yesterday's Ubiquiti discussion.[1]
Is there any (good) brand with pricing between Mikrotik and a Ruckus that doesn't need a cloud connection?
For AP, OpenWRT seems decent.
that would explain it then.
Go Eero Pro.
Your future time management self will thank you.
Router, Wifi AP (probably two to get full coverage), Powerline extender, Point-to-point extender with a switch on the other end.
Stupid outbuildings. Anyway, thanks for the tip!
Eero Pro (not standard) kit comes with 3 identical boxes, each with a third radio band for backhaul mesh, each can be wired or wireless as well.
https://evanmccann.net/blog/eero-vs-eero-pro
See comparison table illustration here:
https://evanmccann.net/blog/2021/2/eero-6-vs-eero-6-pro
Not sure if still the case, but last time I dug into it, eero was also the only consumer grade software-defined-radio router/ap, allowing them to rapidly patch for various vulns that others couldn’t necessarily or took much longer for.
Though it's not super well supported either because they prefer people using the web UI to the config file.