Yes, Kreb's reporting wasn't great and he should have retracted the original article once the facts came out, but I don't think being a bad journalist is something you take someone to court for.
Yes, Kreb's reporting wasn't great and he should have retracted the original article once the facts came out, but I don't think being a bad journalist is something you take someone to court for.
It could kill Ubiquiti on all enterprise deals with "cybersecurity business risk" factors each enterprise ways before making decisions.
He generally does good work but the thing he's being sued over was an example of lazy journalism. I would expect a seasoned journalist to actually verify the claims being fed to them rather than regurgitating things blindly. He didn't do that in this case it seems, instead buying the story he was being (figuratively) sold completely and not bothering to do any checking.
Ubiquiti might not be doing themselves favors in PR here but if they have actual proof that he knew they were not covering it up, and there's provable damages this won't go the way people want. That's going to be a really high bar for them to clear though, barring them responding directly to a request for comment with "no absolutely not we're investigating and will release details later" or something to that effect.
Defamation suits on this scale are difficult, just look at what's been happening with Fox's election system related lawsuits[2] -- judges keep ruling against them on requests for dismissal. They may not ultimately lose any of these cases based on the facts but they also have the resources to make that a lengthy journey, where I don't think Krebs does.
[1]: https://itwire.com/business-it-news/security/infosec-researc...
[2]: https://www.reuters.com/legal/government/fox-news-appeals-de...
As a Ubiquiti product owner I’m being turned off Ubiquiti equipment in the future.
I mean, his source wasn't great, but the fact is that they were suffering a breach. The fact that the breach was an undetected insider hardly makes things better.
[1] https://www.microsoft.com/security/blog/2022/03/16/uncoverin...
Default creds (configuration issue) Common creds via bruteforce (configuration issue) Exploit of CVE-2018-14847 (4 year old patched vulnerability).
All of the methods mentioned require local network access in a default configuration. None of these are issues from the public internet.
If you have lateral movement within most networks, you're already likely to have the ability to route and disguise traffic and use the network as a relay point.
I am interested to read of your "many other examples". I'm yet to see a serious network gear vendor without big vulnerabilities to their name. From memory, Cisco had about 4 backdoor root accounts found and CVE'd in 2018 alone.
open the management ports up to the internet (not the default) and be running a firmware prior to April 2018 (or be using a default password)
I've got some of their switches running SwitchOS, which is great, but my minute exposure to winbox has thoroughly put me off anything that uses RouterOS.
(1) SSH into you box for shell and use the command line interface (2) Use the comprehensive web interface (3) use the shell tool in the web interface (4) use wine to run the client
Fuck you, Krebs.