6 ms·
> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed” Perversely, this is exactly the lo
by noinsight 6y ago
> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed”
Perversely, this is exactly the logging that you want to have in place in case of a breach.
You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”
- baaym 6y agoIronically they can factually make that statement now as well.
- jasonhansel 6y ago"We believe that the hackers obtained read-write access to our database, but we also believe that they were too polite to actually use it for anything."
- samstave 6y ago"Hacker came in through the server hard-line" <-- HollyWoods favorite Hacker Trope.
- toyg 6y agoAka plausibile deniability
- chillfox 6y agoI have never ever seen "plausible deniability" keep someone out of trouble. I have seen attempts at applying it several times, but never successfully. As an excuse for why to not do the right thing I really hate "plausible deniability".
- g_p 6y agoUnder GDPR, a failure to know about (detect) a breach (and then report it yourself) is in itself a violation. Likewise, failing to have suitable organisational and technical measures in place to protect the data is a breach. I'd certainly argue your inability to account for processing operations after having been breached through lacking knowledge of what was done due to a lack of logs was therefore a breach.
- deleted 6y ago[deleted]
- abraae 6y agoYou're joking right? I don't live in the US but I've watched as plausible deniability had been deployed there at the very highest levels, with great success, for 4 years.
- deleted 6y ago[deleted]
- tinus_hn 6y agoWhy, they also have no evidence now!
- hn_throwaway_99 6y agoBetter solution: never store unencrypted PII/PCI/PHI/etc. in the database. There are loads of tokenization solutions (Very Good Security got a bunch of buzz a couple years back) that do this, or alternatively all of the big cloud providers have key services (KMS on AWS and Google, Key Vault on Azure) so that you can ensure that every decryption attempt is tracked and logged. If you need to search on some of this data you should use blind indexes (Google blind index for more info).
- Traster 6y agoThat works for exactly as long as the data hasn't come out. Once the data comes out... well, you've got questions to answer.
- williamsmj 6y agoReminds me a little bit of Adverse Event Reporting in pharma. If a drug manufacturer finds out about an adverse event (i.e. a bad reaction) to a drug, it kicks off all sorts of obligations that have the potential to be time-consuming and expensive. So pharma is the one sector you won't see with a "social media listening/analysis" department in marketing. They actively avoid tracking or learning about discussion of their products on social media.
- deleted 6y ago[deleted]
- anchpop 6y agoSounds like a case of poor incentives. It's easy to wag our fingers and say "well they shouldn't be doing that" but difficult to come up with a system of incentives that makes everyone want to do what's socially beneficial. In this case, it seems like there should be a separate organization in charge of looking for adverse events that is rewarded for finding events (instead of punished). We use some strategies like this currently when regulating the finance industry
- vxNsr 6y agoI worked for a pharma co for a while, they did have a social media listening department in marketing, also we were trained to report any discussion of the company at all to a special investigations unit that would follow up.
- La1n 6y agoAs someone who works in pharma currently, I have seen the same. The pharmacovigilance unit does search the internet/social media for AE's, off-label use, etc (depending on region). Secondly every single person in the company also needs to report events when they see/hear/read them. So not having that social-media department wouldn't be doing much, not all thousands of employees can/will/want to avoid social media.
- williamsmj 6y ago
- maliegrl 6y agoUbiquiti's response is not surprising. Of course they would lie and deflect about the severity of the attack. They have terrible customer support and awful software update communications; besides, they are hostile to analysts and the press. Either Ubiquiti made false material statements, or the company is negligent. In both cases, it will get them into hot water.
- jart 6y agoIn Ubiquiti's defense, I once brought a disclosure to their attention on Twitter a few years back and they very swiftly issued an update. I guess things have gone downhill since then. It boggles the mind why a company whose core business is catering to the self-hosting crowd, would try to force self-hosters onto its cloud plantation, when it can't even protect its own house.
- cced 6y agoCan you provide more information regarding a system that can log these types of breaches (and all other activity, as required) and that would be deemed "safe" and reliable post-breach? i.e.: A system that can provide logging and that can *assert* that all logs, even in the event of a breach, are asserted CIA?
- grit-t 6y agoAWS offers object locking, which is similar to a WORM drive (Write Once Read Many). This prevents logs from being deleted. The other approach is to ship logs to another AWS account. https://aws.amazon.com/blogs/storage/protecting-data-with-amazon-s3-object-lock/ https://aws.amazon.com/blogs/storage/protecting-data-with-am...
- neoncontrails 6y agoThanks. I was a bit puzzled earlier why AWS was so insistent about enabling object locking, my specific use case doesn't profit from remote versioning at all. But I can see how this would mitigate log integrity concerns. I'll definitely enable it for that.
- m463 6y agoMost places I've worked say - do not read other people's patents.