Ubiquiti is suing Brian Krebs for his reporting on their breach
twitter.com
twitter.com
IIRC the Ubiquiti 'hack' was an insider attack from an employee lying and intentionally breaking things while pushing his lies to the press to hurt his employer. Krebs was wrong and tricked by the employee. I don't know if that justifies this legal action, but it's not the normal going after someone who reported a breach. This one is more complicated.
I'm pretty sure Corey is wrong on the facts in this case (and so was Brian). I also felt a lot better about Ubiquiti once the dust settled and the details about Sharp came out.
Edit: I missed this comment thread which basically says the same thing: https://news.ycombinator.com/item?id=30850793
In either case, you assert "Krebs was wrong" a couple times but you skirt the topic of the twitter thread, the comments, and the lawsuit: that Krebs intentionally misled readers in order to drive traffic for ad revenue.
Do you think Krebs did this?
Krebs got the big story exactly right: Ubiquiti had a bad security problem and flubbed the handling of it.
- the supposed hacker was the goddamn Unifi Head of Cloud, using the access keys needed to do their job
- the initial internal investigation into the hack and ransom was being conducted by the attacker
- that the whistleblower account is a complete fabrication by the internal attacker and his reporting on a coverup are false
Ubiquiti aren't suing him for reporting on it, they're suing him for not retracting it properly once it was revealed how false it was. As per the filing:
70. Ubiquiti brings this litigation because of Krebs’s refusal to do the right thing and retract the March 30 article or the December 2, 2021 update, which continue to malign Ubiquiti’s reputation, damage its relationships with its stockholders, and disrupt its business operations.
Krebs and Corey are _way_ wrong on this.
There is plenty to be said and very valid criticisms about how Ubiquiti dropped the ball and handled the situation. The attack being an insider does not excuse them. But it invalidates much of the reporting.
Krebs was specifically and personally targetted by the attacker as a method of spreading false statements to damage the company and, by keeping the articles up, remains complicit and liable.
https://krebsonsecurity.com/2021/12/ubiquiti-developer-charg...
What part of that update is incorrect? Naming that update is not going to help their case, at all.
This lawsuit is likely doing the exact opposite of what Ubiquiti expected.
Before the lawsuit, I had some sympathy that they got jerked around by an ex-employee with major access and took it in the shins. I'm kind of in the glass houses and stones camp ... I doubt very many companies could withstand a high-level technical person going rogue. They found the problem. Now they're pursuing charges against him and that's rattling through the legal system. Sure, there's lots of reputational damage, but that's the kind of thing that happens when you centralize management of things--it makes them a high profile target (see: Solarwinds).
However, the lawsuit against a reporter is causing me to pause and think "Wow. Maybe they're actually institutionally incapable of recovering from this, worried that something else might get exposed and really do suck."
The lawsuit moved me from slightly sympathetic to Ubiquiti into "What kind of idiots think this is a good idea?" and looking for alternatives.
I'm not a journalist so I don't know how these things are supposed to go, but shouldn't Krebs have verified his sources identity before publishing? Isn't that a thing journalists are supposed to do?
That said I think Krebs was right to publish the story at the time, but when it became clear that Adam actually was Sharp the story should have been retracted. Perhaps Krebs should even issue an apology at that time?
I'd entirely forgotten about the Ubiquiti breach until today.
From my perspective this lawsuit looks like they've Streisand Effected the fact that they let their internal security be even worse than the initial accusations.
It's like finding out your financial advisor had all your money stolen, which is bad enough, and then it turns out it's because they gave their gardener the password to your bank account.
Genuine question.
It seems to me that Krebs might be in a position to claim:
1. He honestly reported the facts as were made available to him.
2. Either:
A. He didn't know his original source was Sharp (quite feasible that Sharp disguised this)
Or
B. He did know his original source was Sharp, but felt compelled to continue to protect his source despite charges having been brought (innocent until proven guilty).
3. He took the view was that nothing in the revelation of this hack as an inside job casts doubt on his initial reporting, which was about Ubiquity's response to the incident not the attacker's identity.
We should at least wait to read the defence before drawing any conclusions.
Which is a more than adequate defense. See New York Times vs. Sullivan.
If this comment from a former employee is correct then no, he had root access to a bunch of stuff for no good reason and their security stance is abysmal.
Nobody should have the root aws tokens. They should be split between two teams and stored in a safe & access should go through another method that is audited
Criminal Accusations <> Facts until proven in a court of law. All Krebs knows at this point is Sharp was arrested.
And what we all don’t know at this point is whether Ubiquiti is competent enough to have unfettered access to all their customer networks because they failed to defend against insider threats.
Off the top of my head:
a) don't force your clients to add their networks to be accessible by your cloud, this was their entirely huge mistake. or by design to enable spying activities. the same way I can log into unifi and set a switch port in promiscuous mode and forward the traffic to my remote ip, so can they.
b) two people required for secure access to sensitive systems.
c) sensitive gear on-premise under constant video surveillance.
d) logging to remote servers under control of "internal security" not "security", regularly monitored by "internal security".
Companies do this and more. They do it by contemplating a solution to a problem rather than dismissing the solution as "illogical".
He got inside information from being...chairman of the committee that managed disclosure of sensitive information.
https://arstechnica.com/tech-policy/2019/02/lawyer-who-wrote...
The HN comment majority also changed from when I made my first comment. At the time I was pushing back against the overwhelming sentiment here and on Twitter that Ubiquiti was going after a journalist just for reporting a breach. The story is way more mixed than that and from the stuff I remember reading at the time Brian wasn't in the right.
I don't want to be overconfident (I don't really know the specifics), but I did want to push back against the overwhelming overconfidence I saw arguing the other direction.
It's very common elsewhere. Just keep repeating a thing until it is accepted but it really isn't how things are supposed to be in sensible discussion.
I was replying to someone who said Krebs was "exactly right" - that's what I was pushing back on. My first comment was also more nuanced. The evidence exists for those who care to look and I think what I wrote is inline with it.
"I'm right, go find the evidence if you dare doubt me." Not so useful.
This can be true while still being massively exposed to legal liability. The court of public opinion is one thing, the law is another.
"Their undetected security breach was by an insider" is not the sterling defence of Ubiquiti that you seem to think it is.
Considering the nature of the attacker (and the HN comments about the guy at the time of the attack) my take away of ubiquiti from this event and their response was positive. I also down ranked my expectation of Krebs’ accuracy.
It’s not personal - he writes lots of great stuff, but his response to being wrong in this case was worse than Ubiquiti’s response to the incident.
It's like Okta. Of course it's hard to protect against an insider ( although Ubiquti didn't really try), but that's not an excuse to screw up the disclosure.
This is just more and more embarrassment for a company that clearly just doesn't understand security, and yet wants to force all their users of their products to rely on them as a trust model by making all of their ongoing product systems completely cloud reliant or at least holding third party root keys to sell ads / customer telemetry.
And yet, enterprise-level suppliers do it successfully every day.
The original article[0] seems perfectly fine. But, if "Adam" (original informant) and Sharp are the same person[1] and Sharp is in fact the person who perform the breach such that this is an inside job instead of an external hack.
IANAL and while I'm not sure of the merit to this lawsuit itself, there's still a lot of problems if your informant is the person performing the illegal activity.
[0] https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-b...
[1] https://krebsonsecurity.com/2021/12/ubiquiti-developer-charg...
Seems pretty updated to me.
I don't think that should be worth a lawsuit, but it would reflect badly on him if that's proven true and he doesn't update. Of course, filing lawsuits over disclosure of security issues is also a bad look, but I never used their stuff to begin with.
On the homelab subreddit, they're no longer the go-to recommendation they were a few years ago.
For instance, I keep hoping for an updated USG3 given the current one hasn’t changed since 2014 and can’t do IPS without throttling speeds to 80Mbps which is simply unacceptable these days, but all they seem to be doing is focusing on big and expensive 1U hardware which I just don’t have room for.
Everyone I know in tech would probably agree with you, and consider suing reporters to be a bad approach. But everyone I speak to in business management seems to take the view that this strengthens their view of Ubiquiti.
Ubiquiti basically needs to weigh whether it makes sense to get burned by Streisand effect now or cut their losses and hope journalists don't burn them again in the future when they don't do due diligence on a lead. After reading through the complaint, it looks like their demands are reasonable.
What I'm more interested to know is whether never issuing a correction/retraction is going to work for or against Krebs.
"Within five years of the appointment of a business manager, wages decline by 6% and the labor share by 5 percentage points in the US, and by 3% and 3 percentage points in Denmark. Firms appointing business managers are not on differential trends and do not enjoy higher output, investment, or employment growth thereafter."
Not a cool move from them.
That said, I am really excited about their forthcoming pre-paired PTP Gigabit link kit. I have been using ancient Ubiquiti paired links and need a replacement.
2. To be fair, this is the big one. Who does replacing all the hardware ALREADY BOUGHT hurt other than the customer who bought the hardware? You're generally not getting a refund because you no longer like the company. The company has your money. It's not like their products are things you buy on a monthly basis. You aren't hurting the company.
They're not suing to censor a researcher or to create a chilling effect on reporting about security or their company. They have to sue to show the court, their customers, and their investors exactly how Sharp manipulated public opinion to damage the company so he could "save it", how Sharp used Krebs' authority as a security reporter to damage the reputation and trust in their brand to apply that pressure and force leadership to act in the way he wanted, and to be able to claim appropriate damages by rightfully discrediting a false and inaccurate report.
Krebs either has to weaken his own brand and admit he was played or stick to his guns that he faithfully reported. Either way, this lawsuit ensures he's got to correct the report.
Late last year I kitted out my home with a switch and two wireless access points.
The switch (S3410-10TF-P) does everything that you expect a switch to do. It has a pretty simple web interface, and a pretty comprehensive CLI.
The access points are AP-W6T6817C (6800mbps WiFi 6, 802.11ax). It is rebranded from Ruijie Networks. The access points have a simple web UI for configuring everything, the range is pretty awesome. Multiple radios can be configured with separate SSIDs that have access to different VLANs.
The usability is less than Ubiquiti, but it seems that they work a little better than my old UniFi setup that this replaced (though, that was purchased more than 8 years ago).
There's WPA3 support.
Getting data via SNMP into Prometheus means that you can see per-client usage history, too.
Edit:
Access Point AP-W6T6817C: https://www.fs.com/products/108707.html
Switch S3410-10TF-P: https://www.fs.com/products/115387.html
for home use at this point I would also recommend mikrotik routers over anything ubiquiti edgeOS based, since they seem to have abandoned development on their fork of vyatta... the $50 edgerouter-x (ER-X) as a standalone wired gigabit router was a good choice in 2017 but not so much anymore.
I moved my four HAP AC devices onto OpenWRT; speed and stability has been much improved, and roaming works much better. If you don't need WiFi 6 then I'd go as far as to say this is a great solution.
That has been my (one?) major complaint with my Ubiquiti APs - I have four of them scattered around my house/garage and moving between them always suffers a bit of a delay in handing over (or refusing to hand over at all).
I recently migrated a router (not Ubiquiti) over to OpenWRT and have been happy with the stability. I read a bit about roaming, but thought it looked a little daunting.
Here's an example: https://parkercs.tech/enabling-802-11r-fast-roaming-transiti...
I did lose the central management interface of Mikrotik (CAPsMAN) but for my home set-up this wasn't a big deal. I used the backup and restore capability in OpenWRT's LUCI interface to clone most of the settings.
Roaming / fast transition now works much better. I do still lose a few packets as I wonder around but nowhere near as flakey as on the Mikrotik stack.
I did spend an inordinate amount of time optimising channels, signal strength and placement etc. on the Mikrotik stack before migrating over, and so I kept these settings on OpenWRT. I think a lot of making wifi work well is in this particular black art. All things being equal, though, OpenWRT works better for me.
are these any good? has anyone had any luck with going full oss for this stuff?
You can also search AliExpress for “fanless pfsense” and find lots of options for less $$$.
For APs, you could also check out the Cisco Small Business line. Their 240 is the same hardware as some of their enterprise access points, and pretty trivial to set up.
If you are in the US, I'm pretty sure I saw very similar devices sold there as well, but didn't keep the link as buying from there would be too expensive.
The TL-WDR4300 and TL-WR743ND have a special unauthenticated URL that causes the device to connect back to your IP, download a file, and execute it as root.
The TL-WA701ND and similar models create a hidden SSID that acts as an unauthenticated bridge into your network.
If you can even manage to report security issues to them, they will only patch models you specifically tell them are vulnerable. So as a researcher you have to buy one of every model to actually get things fixed.
They suffer from extremely poor code quality, a complete lack of understanding of security, and severe code reuse without recording what devices the code ends up in. You can take existing TP-Link exploits, poke around in a new model of device, and often find the same vulnerable endpoint under a new "hidden" URL.
Edit: to address your specific question, CVE-2021-35004 is RCE against both routers and standalone APs.
Sadly the consumer department doesn't seem to follow the same model as their business department.
Here's the actual complaint: https://storage.courtlistener.com/recap/gov.uscourts.vaed.52...
Ubiquiti seems to be arguing (count 1) that Krebs defamed them by not clearly identifying Sharp as his source in the December 2 post and December 5 update to the original article. That simply updating the original article constitutes repeating everything contained in it and is therefore defamatory beggars belief.
They also argue (count 2) that the initial March article was defamatory. But it can't have been if if Krebs at the time didn't know the information provided by his source, Sharp, was false. Presumably Sharp didn't share that with Krebs that he was the one behind the breach, so Krebs wouldn't have had particular reason to suspect he was providing false information. Maybe Sharp defamed them, since he obviously did know he was telling falsehoods, but it's hard to see how Krebs did (and two of the supposedly defamatory statements in count 2 are just Krebs describing or quoting what Sharp said).
Bad journalistic practices may abound, but I don't think any of that constitutes defamation. Neither Krebs nor Ubiquiti look great here.
https://itwire.com/security/infosec-researchers-slam-ex-wapo...
https://itwire.com/business-it-news/security/image-board-adm...
https://www.emptywheel.net/2017/11/28/the-russian-metadata-i...
I’m not sure I agree with ubiquities decision to go after him - see the Streisand effect - but he has made some really dubious choices.
Ubiquiti is asking for:
WHEREFORE, Plaintiff Ubiquiti Inc. demands judgment against Defendant Brian Krebs as follows:
(a) awarding compensatory damages in an amount to be determined at trial, but greater than $75,000.00;
(b) awarding Ubiquiti $350,000 in punitive damages or in an amount to be determined at trial;
(c) awarding Plaintiff all expenses and costs, including attorneys’ fees; and
(d) such other and further relief as the Court deems appropriate.
Which is certainly a lot of money, but nothing compared to the billions Krebs' supposed "defamation" cost Ubiquiti. I suppose their goal with this must be to improve their reputation with potential business customers?Plus, this is why they're suing Krebs. People like you have this opinion and don't really know why. Sharp's strategy was effective.
So now, suing a journalist is going to fix their reputation? Good luck with that, there's around zero chance of that happening. The way to fix their reputation would be to consolidate product lines, do QA and not ship broken software, and stuff like this. Admit mistakes were made, and outline their strategy on fixing them ( the parts about abandoning hardware lines and security). Digging in won't do them any favours.
This situation also brings a much more interesting problem to light, namely, how do companies protect themselves and recover from internal sabotage?
they also had (maybe still have) such poor internal controls that they got spearphished to the tune of $46 million in wire transfer: https://www.google.com/search?client=firefox-b-1-d&q=ubiquit...
you know that something has gone wrong with a tech company when the founder's ego has inflated to the size that they think the best thing in life to do is buy a professional basketball team.
https://sfconservancy.org/blog/2019/oct/02/cambium-ubiquiti-...
I couldn't find anything about the outcome of that one.
I am about to double down on Ubiquiti as the networking backbone and security cameras for my new house, so I have a special interest in this currently.
To be clear with my own experience:
- Ubiquiti requires an online login to use UniFi products (which you _should not_ encourage especially for home/prosumer use)
- UniFi does not integrate with the products that you might have purchased when you were less experienced or have less requirements. For example: I bought several EdgeRouter X products then moved on to UniFi products because I needed SFP+. UniFi management does not manage any EdgeRouter devices despite being manufactured by the same company, so I effectively have a dozen different network management pages to deal with.
- The web interface for UniFi is terrible; they've had a "new" UI and an "old" UI and support requires you to use the old UI to retrieve information to solve a lot of the problems. The "new" UI looks nice but often renders incorrectly (especially the network topology page).
- Support will sometimes ask you to SSH into your own devices to do certain steps that can't be done from their fancy UI.
- UniFi has several different settings pages all with overlapping and confusing terminologies instead of having an actual _unified_ settings page for all of the products being managed.
- I've also had trouble managing their updates insomuch as one device that they claim was bricked but in fact simply wasn't compatible (and wasn't _advertised_ as incompatible) with my network settings. They told me to RMA the item (at my own cost) and the replacement item had the exact same problem and required additional troubleshooting after I'd already spent money and time to return the item. After resolving that problem, with a USP-Plug, it ended up creating its own wifi network whose security can't be configured by me. I'm sure glad I don't have to deal with network audits...
I think Krebs is a scapegoat. That doesn't excuse any incorrect information he has on his blog. But Ubiquiti certainly isn't a bastion of good either.
Did they revert it? You can really use an AP with recent firmware now without connecting in any shape or form to Ubiquity servers?
I must say this is a bit of an extreme/maximalist position to take - I agree being local only by default, or having the option to choose during setup would be better, but the option is there.
Do you have a link with instructions to do so?
https://community.ui.com/questions/CloudKey-Gen2-or-setup-wi...
Yes, Kreb's reporting wasn't great and he should have retracted the original article once the facts came out, but I don't think being a bad journalist is something you take someone to court for.
It could kill Ubiquiti on all enterprise deals with "cybersecurity business risk" factors each enterprise ways before making decisions.
He generally does good work but the thing he's being sued over was an example of lazy journalism. I would expect a seasoned journalist to actually verify the claims being fed to them rather than regurgitating things blindly. He didn't do that in this case it seems, instead buying the story he was being (figuratively) sold completely and not bothering to do any checking.
Ubiquiti might not be doing themselves favors in PR here but if they have actual proof that he knew they were not covering it up, and there's provable damages this won't go the way people want. That's going to be a really high bar for them to clear though, barring them responding directly to a request for comment with "no absolutely not we're investigating and will release details later" or something to that effect.
Defamation suits on this scale are difficult, just look at what's been happening with Fox's election system related lawsuits[2] -- judges keep ruling against them on requests for dismissal. They may not ultimately lose any of these cases based on the facts but they also have the resources to make that a lengthy journey, where I don't think Krebs does.
[1]: https://itwire.com/business-it-news/security/infosec-researc...
[2]: https://www.reuters.com/legal/government/fox-news-appeals-de...
As a Ubiquiti product owner I’m being turned off Ubiquiti equipment in the future.
I mean, his source wasn't great, but the fact is that they were suffering a breach. The fact that the breach was an undetected insider hardly makes things better.
[1] https://www.microsoft.com/security/blog/2022/03/16/uncoverin...
Default creds (configuration issue) Common creds via bruteforce (configuration issue) Exploit of CVE-2018-14847 (4 year old patched vulnerability).
All of the methods mentioned require local network access in a default configuration. None of these are issues from the public internet.
If you have lateral movement within most networks, you're already likely to have the ability to route and disguise traffic and use the network as a relay point.
I am interested to read of your "many other examples". I'm yet to see a serious network gear vendor without big vulnerabilities to their name. From memory, Cisco had about 4 backdoor root accounts found and CVE'd in 2018 alone.
open the management ports up to the internet (not the default) and be running a firmware prior to April 2018 (or be using a default password)
I've got some of their switches running SwitchOS, which is great, but my minute exposure to winbox has thoroughly put me off anything that uses RouterOS.
(1) SSH into you box for shell and use the command line interface (2) Use the comprehensive web interface (3) use the shell tool in the web interface (4) use wine to run the client
Fuck you, Krebs.
I remember when the original post came out and I was worried about having compromised gear at home. Then it turns out it wasn't true and the author of the post refused to update it to acknowledge that he was manipulated after it became clear. I don't follow Krebs so don't have an opinion on him but I'm happy the security problem is a non issue.
I do agree with the anti-SLAPP comments having read more about this since I posted that.
If you read carefully, Ubiquiti did not say that no customer data was accessed, they said they have no evidence that customer data was accessed. The first article Krebs wrote quotes the employee (likely the person arrested) saying that this was because they didn't keep logs long enough (this fact was confirmed in Ubiquiti's complaint). That it was the person accessing the data who was able get rid of logs showing the data accessed doesn't change the lack of logs. It was externally breached in the sense that an empoloyee downloaded the data from outside the company and could have done anything with it prior to being caught (and could potentially have it stashed somewhere for later use). Ubiquiti also never denied that legal overrode technical considerations in not forcing all accounts to be reset. The initial reporting was substantially correct and the post was updated when new information was available.
https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-b...
One thing that might be slightly comforting for customers is that Ubiquiti claims in the March 31 update (linked from the first article and quoted in the last comment on that article) that customer data was never mentioned in negotiations, although that is a specific detail not just who accessed the data. There are potentially some theoretical reasons someone attempting economic sabatage as an empoloyee might be less likely to access customer data (e.g. the average attacker might be more likely to be in a legal jurisdiction where they are unlikely to ever face a judge while an employee in the US may want to be able to tell a judge that they didn't access customer data if they get caught), but I wouldn't count on that at all or make any distinction about what to do based on the employment status of the person who accessed the data (if employees stealing data were less likely to release customer data in gerneral they might decide to do so for no other reason than to look less like an employee stealing data). Sounds like you took reasonable steps. Most if not all companies are breached at times, a company that has no disclosed breaches almost certainly just has a policy of never disclosing them.
If the facts as alleged are true (as an attorney I usually assume they aren’t) then heck yes they should sue. This is the type of defamation case that actually doesn’t get dismissed. I.e. making specific, factually incorrect statements, directed at the business of the Plaintiff, for Defendant’s own commercial gain.
I hope Krebs has insurance.
I get that people really like him, but he had plenty of time to do the right thing here and has nobody to blame but himself.
The first time he could have been taken at face value. The second time? Seems closer to willful ignorance.
How much would it cost to make it go away? If it's going to cost millions of dollars, the defendant is toast regardless.
Even if you get better judges at higher levels, which is debatable given they are either politically elected or politically appointed, the cost in time and money dramatically increases.
Also, as I understand, all Krebs has done is wrote "X told me about Y". How is that statement false, if X really contacted Krebs and told about Y?
My advice would be to read the actual complaint[0]. It goes into detail why they are doing this and their various points. The part that is interesting to me at least is Krebs intentionally labeling Sharp differently depending on the sentence in the same article.
> 6. Krebs alternated his descriptions of Sharp, first he describes Sharp as a current employee. He then describes Sharp as a “former Ubiquiti developer” to deceive readers into believing that the sourcing for his original story was a legitimate source—someone other than Sharp. Krebs, therefore, intentionally concealed the fact that the only support for his reporting came from the very person who had just been indicted for hacking and attempted blackmail.
[0]: https://storage.courtlistener.com/recap/gov.uscourts.vaed.52...
https://krebsonsecurity.com/2021/12/ubiquiti-developer-charg...
It is completely obvious to everyone that there is no deception here. Sharp was an employee at the time of the first article but presumably wasn't at the time of the second article (post arrest). The clear implication is that previous employee source was quite likely the preson arrested. The previous article contains a link near the top to the new information. This is purely Ubiquiti harassing Krebs, who does things by the book because he gets harassed all the time from all side.
This does not seem completely obvious. He uses "Ubiquiti employee" as the source of his first story, and then "former Ubiquiti developer" as the guy who was arrested when it was published. These are two different descriptions used just a sentence away from each other, making it sound like two different people were involved.
Being cloud-free is a hard requirement for my network equipment.
But moves like that make very careful about going ahead with the purchase.
It seems like I will need to learn how to operate PFsense.
Are there any other alternatives worth exploring?
Or use OpenBSD (unixsheikh has a guide) or Linux (Vyos, OpenWRT, etc).
What exactly does Krebs have to offer if Ubiquiti "works with him"?
Even though we never went with it I feel like a sucker every time they come up in the news lately.
I was already off the Ubiquiti train once they started forcing people to buy a hardware appliance for Unifi Video, rather than allowing the previously 100% working software package to be used.
Extend, embrace, extinguish. They had the enthusiast crowd and got greedy.