4 ms·
Yes it does, both on the local device, and on the Unifi cloud service. This is true as of recent firmware versions. But 2FA in this case is useless. The hacker
by teilo 6y ago
Yes it does, both on the local device, and on the Unifi cloud service. This is true as of recent firmware versions.
But 2FA in this case is useless. The hackers owned the UBNT servers. If they harvested user logins, then one can assume that they also harvested the corresponding TOTP secrets.
To make matters worse: When you setup a Gen2, Gen2+, UDM, or UDM-Pro, you are required to login to the UBNT cloud service to activate your device. Once you do this, your device now has an "Owner" account cannot be disabled.
If you have enabled 2FA on your Unifi account, then you can now login to the device locally using your Unifi credentials + 2FA, with a nice false sense of security.
So in other words, if your account creds and TOTP secret got leaked, and you did not change them, anyone who gains access to your local device's login page can still own you.
This remains true even if you disable Remote Access. (And in fact, as of recent firmwares, the ONLY way to disable remote access is through the Unifi cloud panel. You can't even do it locally.) It will still call out to Unifi's cloud service and authenticate you. There's no way to turn off this SSO account. The best you can do is block all access to Unifi at the firewall, and download all firmware updates manually. And good luck with that if you are using a Unifi device as your gateway.