13 ms·
> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate
by rossipedia 5y ago
> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.”
I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be somebody who raised a stink about all the security problems during their time there.
Form your own opinion, I'm just a guy who worked at Ubiquiti for a year, raising all kinds of hell about the security, architectural, and operational problems that I saw while I was there.
But what do I know...
- judge2020 5y agoGiven they were stupid enough to spin up some VMs, I doubt it was someone that knew what they had access to. A skilled attacker would stay dormant sucking up all data accessible via the AWS API (including s3 stuff) and potentially keep access to the infrastructure for years.
- smashed 5y agoThere is no evidence that this did not also happen.
- brippalcharrid 5y agoAnd if it is happening, we might hear about that in a few years' time, if it's discovered, and if it's brought to light in circumstances that are conducive to the vendor making a public disclosure (eg. which are impossible to cover up).
- deleted 5y ago[deleted]
- throwaway8581 5y agoThis kind of analysis is basically worthless because you don’t know whether they are operating at multiple levels of deception by, e.g., making you think they are a stupid script kiddie and that you successfully wiped them out.
- LilBytes 5y agoIf they had root access to an AWS account, this is exactly what you would expect. If there's a cyber security firm that's been hired to provide analysis they're going to be combing through egress traffic to find anything suspicious. But, egress traffic is difficult and expensive to analyse. Worse yet, the attackers could easily just sit there and not use their attack methods for a little while and start up their compromises in weeks or months. You couldn't be certain nothing's still there till you ripped the AWS resources out and replaced them.
- TeMPOraL 5y agoThat would be the reverse of the usual strategy, wouldn't it? Most companies seem to try to pin breaches on sophisticated hacker groups backed by nation states. But then, they benefit from the perception of a threat that's impossible to defend from (so there wasn't anything they could do) - whereas Ubiquiti benefits from people thinking the attack was just a small actor that couldn't possibly threaten Ubiquiti's customers.
- rossipedia 5y agoYes, you're right. But I don't really expect them to make the "smart" or "usual" play. That would honestly surprise me. Now, pinning it on somebody that was generally disliked because they constantly blocked things that had obvious gaping security holes? Basically sicking law-enforcement on somebody out of pure spite? I can absolutely believe that.
- woofie11 5y agoAccusing whistleblowers of criminal activity? That's a pretty common ploy. Been there, done that. Early in my career when I was naive enough to try to whistleblow on things over my head.
- TeMPOraL 5y agoAccusing whistleblowers and reporters is indeed common - it pretty much seems the standard behavior in infosec in particular. What I meant was something different. The breach, as I understand it, was quite critical. Ubiquiti in this case could take the standard corporate spiel of "it has hallmarks of a nation state attack, there was nothing we could do" bullshit disclaimer - but given the nature of this breach, every customer of theirs would now be wondering if $Enemy has put malware in their infra, and whether it isn't a good idea to smash it all with a hammer and buy new one from someone else. So I suspect Ubiquiti is going the other way, blaming it on a single, inconsequential individual, that absolutely, positively didn't give access to anyone else, and thus nobody's infra was in any danger. (Note: I have no inside knowledge, or even any deep knowledge, of this topic - I'm just a random Internet person speculating.)
- 5y ago
- ghughes 5y agoThis quote says nothing at all. Obviously the perp is someone with intricate knowledge of their network. They might as well come out and say they have well-developed evidence that the perpetrator has an IQ over 50.
- dylan604 5y agoAre you volunteering for the role? It almost reads as if you are expecting to be named on a list of potential suspects.
- admax88q 5y agoOr he _is_ the culprit trying to get ahead of the story.
- rossipedia 5y agoHeh... no. I quit two years ago, well before all this happened. I have ideas about who this "Adam" is, and I also have some suspicions about who they're accusing as the culprit. But that's all they are. Hunches.
- rossipedia 5y agoI mean, don't get me wrong, there absolutely _is_ somebody who's responsible for it, but I wouldn't place any money on Ubiquiti being able to figure out who it really was. They want to brush this under the rug as fast as they can, and that means using the opportunity to pin it on somebody that's been "problematic".
- ex_ubiquiti 5y agoI remember the cloud lead they hired out of Amazon was as toxic as they come. If he's still in charge I can see him blaming his own team members. The culture at Ubiquiti collapsed in my last year there. The company was unrecognizable because everyone was quitting so fast.
- vvanders 5y agoDamn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.
- posguy 5y agoI want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based network with one central web interface and not have to deal with corporate/state entities deciding to push fun changes out in the management interfaces that power these systems.
- bpye 5y agoIt's an interesting idea to have a single pane of glass management experience for OpenWRT - given that all config is under UCI [0] it seems very possible. One of the things on my todo list is to try and get Nix to push config to my Unifi APs when I flash them with OpenWRT. [0] - https://openwrt.org/docs/guide-user/base-system/uci https://openwrt.org/docs/guide-user/base-system/uci
- mopsi 5y ago
- vmception 5y agoyeah this is just a good as just saying it "has the hallmarks of a state-level attack", pointing at Russia and calling it a day everyone believes it
- harry8 5y agoThat may have worn thin, nowadays. The average response here would have been described as cynical in the past. The Russia/China scapegoat had been way overused to the point where I'm cynical every time it comes up probably even where it's actually true, one time in a hundred or whatever. Nobody blames the NSA in these circumstances, ever.
- Hjfrf 5y agoGoogle did it with an allied op recently. Not NSA, but as close as we're likely to hear about. https://www.technologyreview.com/2021/03/26/1021318/google-security-shut-down-counter-terrorist-us-ally/ https://www.technologyreview.com/2021/03/26/1021318/google-s...
- elliekelly 5y agoDo we know for sure it was an allied operation? Everything I saw mentioned a “Western government operation” which doesn’t necessarily exclude the NSA.
- edoceo 5y agoI hope you don't end up fulfilling your own prophecy
- rossipedia 5y agoI'm pretty sure I'm safe. I left as soon as I could (almost 2 years ago) once I realized how institutionally broken the company was.
- inetknght 5y ago> I'm just a guy who worked at Ubiquiti for a year Would you be able to point to unofficial compatible operating systems for Ubiquiti devices? I want to remove Ubiquiti software from the devices I bought and paid for.
- ex_ubiquiti 5y agoThe gear is locked down to UniFi firmware. Some of us wanted to open it up to alternatives like OpenWRT but that wasn't an option for us.
- electro_blah 5y agoSo, why & how did you do this?
- late2part 5y agoSo, did you do it?
- someonehere 5y agoFor LastPass, did they enforce the policy to mandate 2fa for everyone’s vault? Where I work they mandate 2fa be enabled. Some orgs overlook this.
- geoduck14 5y agoWhen I'm bored, I sometimes intentionally take comments out of context, just to see where they go, I know this isn't what you ment, but I like to pretend: >Form your own opinion, I'm just a guy who worked at Ubiquiti for a year, raising all kinds of hell about the security, architectural, and operational problems that I saw while I was there. You are a lawn man/woman. Security problems: I have to show my badge EACH TIME I go to the bathroom Architectural problems: these bricks are the WRONG COLOR! Operational problems: The painters used the WRONG COLOR OF OFF WHITE! Again, I know this isn't what you ment, but I enjoyed transposing a well written critique of their software from (presumably) a knowledgeable software guy into a lawn person in a jumpsuit. Thank you, amd have a good day.