11 ms·
The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in
by JanSolo 3y ago
The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised.
That's a shame; I was thinking of installing some in my house.
I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.
- sneak 3y agoUbiquiti is all cloud based. If the government wants in to your auto-updating ubnt hardware, it's just a simple court order away. They don't need a backdoor.
- anderiv 3y agoIt may be auto-updating by default, but that can be trivially disabled. Likewise, their cloud connectivity/management is optional. I'm running without issue multiple air-gapped Ubnt networks using their self-hosted controller software.
- fyloraspit 3y agoYeh but it is still closed source, no? I guess if it is air gapped that could be fine, but we are talking mid level network gear here, so for 99% of its use, it isn't air gapped. It is enabling broader connectivity. So you would have to trust the closed source software at some point.
- sneak 3y agoIf it's airgapped, what do you care about it being backdoored?
- lofaszvanitt 3y agoAirgapped doesn't necessarily mean it can't be accessed remotely...
- sneak 3y agoThat's literally and precisely what it means. Perhaps there is some new watered down usage (like what happened to "literally" or "bricked") but that is precisely why people use the term "air-gapped" - to denote networks with PHYSICAL separation from other means of access. (Of course, if you connect an AP, it's no longer air-gapped."
- lofaszvanitt 3y agoAll your computers are plugged into the mains for electricity... Always, always the thing that's ubiqutious is the perfect entrance for the oppressors, since noone suspects anything about those innocent things.
- locusm 3y agoYes, but you can host & run your own controller from anywhere.
- stephen_g 3y agoThat's part of the reason I've started moving away from their routers - I still have an Edgerouter but never went to the Dream Machine or USIP routers. At the moment the OPNSense appliances [1] which are made by the company that sponsors the fork (Deciso B.V.) are my pick for that. They're an EU company, and the thing runs fully open source software on a commodity embedded AMD chip. I'm still using the access points, since I can run my own controller still, either virtualised in a container or VM, or a raspberry pi and you don't have to connect it to the cloud. I haven't found anything better, TP Link seem to have some interesting looking stuff but I worry about the security given they're based in Shenzhen... 1. https://shop.opnsense.com/product-categorie/hardware-appliances/ https://shop.opnsense.com/product-categorie/hardware-applian...
- andreasley 3y agoI think at this point it's pretty safe to assume that all of the well-known network hardware is compromised.
- tekeous 3y agoI wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.
- chinathrow 3y ago> have to bow to the NSA You don't have to bow in order to be compromised. You can be compromised without even knowing it.
- ElectricalUnion 3y agoSeveral MikroTik routers use marvel hardware underneath. So marvel might be compelled to backdoor the hardware for the NSA.
- lowkeyoptimist 3y agoJoking? LOL https://thehackernews.com/2023/07/critical-mikrotik-routeros.html https://thehackernews.com/2023/07/critical-mikrotik-routeros...
- smolder 3y agoMikroTik has come up in their slides before, yes...
- pizzalife 3y agoThere's been plenty of remote 0days in MikroTik's products. At one point people were paying a pretty penny for them.
- somehnguy 3y agoI think it’s worth noting that these vulnerabilities affected devices which had their management page open to the internet, which is universally known as a bad idea. At least the ones I’ve seen. There is a big difference between an exploit affecting all devices vs a subset which requires a specific not-best-practice configuration. Regardless, still good to be aware they exist.
- hedora 3y agoSo, Marvell bought the company that backdoored all my Ubiquiti gear. Since it was never working as advertised, do I contact them or Ubiquiti to get my refund / warranty replacements?
- snoman 3y agoIt’s an interesting thought experiment to wonder if consumer protections extend to defects from state sponsored acts of espionage.
- RationPhantoms 3y agoIf you're not under the threat cone of nation state surveillance (like trying to exfiltrate the radar-asborbing paint formula on the F35) then I wouldn't be too concerned. "That's not the point! It's about privacy!" Sure. I'll choose it ignore the fact that our civilization is somehow still functioning in a post-nuclear world.
- tinco 3y agoIt's not about privacy, it's about security. If there's a backdoor in a HSM or network interface, that backdoor can be used by others as well. That might start with foreign nation states, but might eventually leak to regular private persons or entities as well. A backdoor is an extra attack vector with often very unfavorable properties that you as a user are unaware of.
- slackfan 3y agoSure. See you in the gulag, comerade
- RationPhantoms 3y agoOh please, the United States is so incredibly armed, my death will likely come at the hands of some misplaced right-wing militarized fascist group performing mass murders under the guise of "Freedom" and "A return to the constitutional purity of the US".
- digging 3y agoI mean, that more or less describes most police departments in the country. And they are spying on you.
- slackfan 3y agoI've been promised that that was going to happen any day now since the wrong person got elected back in 2000. Nearly a quarter century on I am beginning to suspect that somebody was overstating something, I can't quite put my finger on what though...
- tltimeline2 3y agowasn't ubiquiti totally compromised in that breach a couple of years ago?
- tristor 3y agoNo. It turns out that breach was faked, effectively. It was done by manipulating Brian Krebs. He's since issued a mea culpa (although a somewhat weak one): https://krebsonsecurity.com/2022/08/final-thoughts-on-ubiquiti/ https://krebsonsecurity.com/2022/08/final-thoughts-on-ubiqui...
- stephen_g 3y agoThat was an insider trying to extort the company by pretending to be an outside hacker. He then posed as a whistleblower to try and throw investigators off the trail.
- deleted 3y ago[deleted]
- colordrops 3y agoUbiquiti has many other problems besides this. The worst is their vendor lockin, where even basic network operations are not possible if you happen to have any non-ubiquiti hardware in your network. You should stay away.
- georgebashi 3y agoCan you provide an example of this issue? This has not been my experience.
- colordrops 3y agoPeople are misinterpreting me, thinking I mean that it's not even possible to intermingle equipment. That is not the case. The specific issue I ran into was that I had a non-ubuiqiti router and AP on my network, and there was absolutely no way to set firewall rules on the Ubiquiti gateway for any clients connected through the non-ubiquiti equipment. This should obviously not be a problem. The gateway provided those clients IP addresses through DHCP and they are in its ARP table, so it should be supported.
- tssva 3y agoI have a mix of Ubiquity and non-Ubiquity equipment and have no problem achieving not only basic but fairly complex networking operations.
- Freestyler_3 3y agoI ran UBQT hardware with mikrotik router and third party firewall. UBQT replaced old frankenstein hardware that had the worst channel management etc. Everything got so much better, customers issues dropped to almost zero (sometimes was hundreds of issues a day) We always had other vendor for part of the network, and that had no impact.
- stephen_g 3y agoPretty sure only the EdgeRouter and some of the older Unifi Security Gateways use Cavium chips. Most of the newer stuff (like the Dream Machine line) I don't think are anymore. None of the Unifi APs did either I don't think (the U6 ones have Mediatek chips in them)
- slau 3y agoAnnoyingly, the ER4 uses the Cavium Octeon III. I have a few of those in production.
- stephen_g 3y agoYeah, I have one at home too, so I really want more detail on what the exploit is (I wonder if if is perhaps IPSEC specific, like an RNG flaw since they talk about VPN and encryption appliances, or it could be something to do with Cavium HSMs and unrelated to the network processors).
- inferiorhuman 3y agoSome of the EdgeRouter stuff (ER-Lite, ER-4) use Cavium SoCs. The ER-X uses a MediaTek SoC.
- djangelic 3y agoI recently upgraded my USG for a dream machine, glad it seems the upgrade was worth it.
- mrweasel 3y agoI'm currently replacing my network equipment with Mikrotik, not because I believe it to be safer than Ubiquity, but because then at least it's made in the EU. But now I'm thinking: Is it better that the US is spying on me in Europe, vs. having EU governments do it? I feel like I'd be somewhat more safe from the US, compared to if my own government decides to spy on me. Maybe I should look into Chilean network equipment, I can't imaging that they'd have much interest in my online activities.
- Freestyler_3 3y agoOther countries spy on you and sell it to your own country.
- manmal 3y agoEurope doesn’t make that many chips (unfortunately), chances are high there’s US/Chinese components in there too. Since your network hopefully sees mostly encrypted traffic anyway (even if you're running Plex on the LAN, that should use SSL), I‘d be more concerned about HW in desktops, notebooks and tablets.
- owenmarshall 3y ago> But now I'm thinking: Is it better that the US is spying on me in Europe, vs. having EU governments do it? I feel like I'd be somewhat more safe from the US, compared to if my own government decides to spy on me. https://en.wikipedia.org/wiki/Five_Eyes https://en.wikipedia.org/wiki/Five_Eyes > In recent years, documents of the FVEY have shown that they are intentionally spying on one another's citizens and sharing the collected information with each other, although the FVEYs countries claim that all intelligence sharing was done legally, according to the domestic law of the respective nations. So in practice, it's entirely irrelevant: your data will end up Hoovered up by someone, coated with a veneer of legality, and provided back to your government to act on (or not). Don't be too interesting to your government, I guess?
- BlueTemplar 3y agoNone of these are EUropean countries.
- some_random 3y agoIn a world where local PD can kick my door in, shoot me in the face, and the news will report that I had it coming because I own a gun, I find it hard to care that the IC can burn a technical access backdoor to access my private data.
- drexlspivey 3y agoTrying to understand what crypto is the network hardware itself performing? TLS is end to end, even if you run a VPN on the router the keys were not generated there probably
- slt2021 3y agocrypto doesn't matter if chip itself has backdoor that will grant root access on some "magic" packet
- dna_polymerase 3y agoCrypto matters for exactly this reason. All my internet traffic passes through unsafe middle-boxes, it is TLS and DH that make sure I can pass through untrusted middlemen without them knowing what is going on.
- slt2021 3y agoCavium chips are installed on security appliances (lol): think Palo alto firewall, fortinet firewall, F5 Big-IP etc. they will see your traffic in plain text by design
- irreticent 3y agoIf everything is encrypted then you're safe... until you decrypt the data on a machine with a backdoored CPU.
- ilyt 3y agoFlashing openWRT on some boxes is probably your best bet; Or, alternatively, treat your LAN/WiFI like public internet and don't send anything unencrypted thru it
- wil421 3y agoUnifi lets you flash custom firmware? I thought they started singing all firmware years ago to stop it.
- blueridge 3y agoI was also going to move to Ubiquiti but decided to go with Peplink instead based on recommendations from: https://routersecurity.org/ https://routersecurity.org/ https://www.peplink.com/products/balance-20x/ https://www.peplink.com/products/balance-20x/
- locusm 3y agoHad never heard of Peplink till now - their modular stuff looks useful.
- deleted 3y ago[deleted]
- Astronaut3315 3y agoSome specific Ubiquiti gear uses Cavium SOCs, but certainly not all. The UDM Pro uses an Annapurna Labs SOC and my old EdgeRouter-X was Mediatek.
- sneak 3y agoUnifi stuff auto updates from the vendor, which is subject to US law. The SoC manufacturer is irrelevant. If the USG wants in, it's just a click away in any case.
- pvg 3y agoIf the USG wants in, it's just a click away in any case. What's a legal and practical mechanism the US Government could use to do this? In almost any number of clicks, never mind one.
- ricktdotorg 3y agookay, so assuming the US gov can access my private LAN data due to my use of the Ubiquiti USG as router/firewall, USG wifi APs etc, of what form would this data exfiltration take? can we please explore/explain how this "compromise" would happen in real-life. if i were sniffing for outbound WAN traffic as root on the unix-like that the USG run, would i see the exfiltration traffic? or is this [supposedly/apparently] happening at a lower layer that an OS can't see i.e. some kind of BMC or BIOS layer? wouldn't such traffic also have to navigate the varieties/restrictions of DOCSIS etc? or are they also compromised? is the worst-case scenario here some kind of giant C2 network with waves hands tons of compromised lower-than-OS mini pieces of firmware exfiltrating data over waves hands compromised network providers hardware into the giant NSA AWS cloud?
- lofaszvanitt 3y agoWould be an interesting experiment to see what an oscilloscope sees on the wire vs what tcpdump records... There was a story somewhere on the net where someone complained thay they wanted to include a do not record payload parameter in tcpdump and couldn't get it through.