TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ubiquiti Networks Breach

647 pointsby ShaneCurranover 4 years ago

37 comments

ex_ubiquitiover 4 years ago
As a former Ubiquiti employee, I&#x27;m sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.<p>The saddest part is that we had many good engineers who could have continued to do amazing things with the UniFi momentum. So much time was wasted on dead end products like FrontRow. Most everyone I know left for jobs where we were treated better and paid more.
评论 #25742082 未加载
评论 #25743501 未加载
评论 #25738511 未加载
评论 #25741662 未加载
评论 #25741609 未加载
评论 #25738247 未加载
评论 #25742117 未加载
评论 #25738022 未加载
评论 #25745168 未加载
评论 #25743421 未加载
评论 #25738123 未加载
评论 #25741755 未加载
评论 #25741788 未加载
评论 #25740673 未加载
bacondude3over 4 years ago
PSA: with Mailchimp URLs, it&#x27;s best to remove the `?e=xxx` URL parameter. That way, A) you can&#x27;t be identified by the sender as the person who shared the email, and B) other people can&#x27;t flood your inbox by clicking the &quot;unsubscribe&quot; link at the bottom of the email.<p>In this case, the cleaned URL that should have been posted is <a href="https:&#x2F;&#x2F;mailchi.mp&#x2F;ubnt&#x2F;account-notification" rel="nofollow">https:&#x2F;&#x2F;mailchi.mp&#x2F;ubnt&#x2F;account-notification</a>
评论 #25741774 未加载
评论 #25736819 未加载
nh2over 4 years ago
Regarding authenticity, from the TechCrunch article about this:<p>&gt; The networking company quickly followed its email with a post on its community pages confirming that the email was authentic, after several complained that the email sent to customers included typos.<p>Indeed: How am I supposed to know whether this email is really from Ubiquiti?<p>* There was apparently no official press release.<p>* All links in the email, including the &quot;Change password&quot; button, are to e.g. `<a href="https:&#x2F;&#x2F;ui.us8.list-manage.com&#x2F;track&#x2F;click?u=somehexnumber&amp;id=morehex&amp;e=morehex" rel="nofollow">https:&#x2F;&#x2F;ui.us8.list-manage.com&#x2F;track&#x2F;click?u=somehexnumber&amp;i...</a>`.<p>* The delivering server is `mail42.atl11.rsgsv.net`, which the TLD of which doesn&#x27;t seem to resolve in my browser to provide hints.<p>* Various news sites that reported this either just referred to &quot;emails people got&quot;, screenshots random people got via Twitter, or link to the Mailchimp site, for which I&#x27;m not sure how to verify whether the &quot;ubnt&quot; account actually belongs to Ubiquiti.<p>Given this, how shall the normal affected user figure out that this isn&#x27;t well-executed phishing?<p>It seems companies could do a much better job making it obvious that their emails are legit. Especially if they were just breached, and &quot;Change password&quot; buttons are involved.
评论 #25748123 未加载
评论 #25744466 未加载
评论 #25753155 未加载
评论 #25741137 未加载
评论 #25742870 未加载
3gukover 4 years ago
I must admit - Ubiquiti has lost some of it&#x27;s shine in the last few years, whilst AP and routing hardware seems to still be very good in terms of pricepoint, it does feel like the software side of things has been going in a very strange direction for quite some time.<p>I&#x27;m still quite annoyed by the fact that I was forced to migrate from Unifi Video to Unifi Protect - due to vendor lock in and the fact that the remote interface for Unifi Video was switched off this month.<p>I guess on the plus side - no one who is still using Unifi Video has to worry all that much.....<p>Hopefully it is just a case of resetting passwords and enabling 2FA if you haven&#x27;t done it already - not entirely sure how much damage could be done otherwise, unless there is an undocumented backdoor into Ubiquiti products ?
评论 #25736869 未加载
评论 #25741455 未加载
评论 #25736395 未加载
评论 #25741877 未加载
评论 #25746670 未加载
评论 #25744621 未加载
评论 #25741797 未加载
ziddoapover 4 years ago
No specific comments to the breach... But, I couldn&#x27;t help but chuckle at We Take Your Security Seriously™.<p>Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling &quot;make sure you tell the victims of this breach that we care!&quot;
评论 #25736514 未加载
评论 #25736363 未加载
评论 #25736850 未加载
评论 #25736543 未加载
评论 #25736408 未加载
评论 #25736045 未加载
评论 #25737201 未加载
评论 #25745206 未加载
评论 #25736373 未加载
评论 #25742375 未加载
exabrialover 4 years ago
Ubiquiti has typically been the &quot;cloudless&quot; provider which is why I&#x27;ve used their stuff. They&#x27;ve been sorta moving in a disturbing direction for cloud control. I don&#x27;t want that risk.
评论 #25742395 未加载
评论 #25735977 未加载
comboyover 4 years ago
Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think <a href="http:&#x2F;&#x2F;unifi&#x2F;" rel="nofollow">http:&#x2F;&#x2F;unifi&#x2F;</a> is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers providing sane defaults for a common case of having multitude of devices at your home which can be categorized as intruder but expect to be on the same network as your phone.<p>Is there a better alternative? When I tested multiple routers mostly regarding low latency, network stability and reliability a few years ago nothing came close, especially when having multiple access points.
评论 #25736757 未加载
评论 #25737577 未加载
评论 #25740760 未加载
评论 #25737180 未加载
评论 #25737520 未加载
评论 #25738160 未加载
评论 #25736028 未加载
评论 #25737174 未加载
评论 #25736628 未加载
评论 #25737875 未加载
评论 #25736401 未加载
评论 #25741349 未加载
评论 #25736612 未加载
评论 #25738967 未加载
评论 #25736631 未加载
评论 #25741108 未加载
评论 #25741183 未加载
评论 #25736696 未加载
评论 #25738607 未加载
tiernanoover 4 years ago
Bit more from reddit ubiquiti forum. <a href="https:&#x2F;&#x2F;reddit.com&#x2F;r&#x2F;Ubiquiti&#x2F;comments&#x2F;kv9fc8&#x2F;ubiquiti_email_re_breach&#x2F;" rel="nofollow">https:&#x2F;&#x2F;reddit.com&#x2F;r&#x2F;Ubiquiti&#x2F;comments&#x2F;kv9fc8&#x2F;ubiquiti_email...</a>
ocdtrekkieover 4 years ago
This is why cloud login for network devices is terrible. I use an EdgeRouter at home with no cloud connection and I&#x27;m quite happy with it, but I&#x27;ve used UniFi in another setting, and I am not thrilled at the ease of getting internal passwords and the like set on devices from any web browser, for instance.<p>Another company&#x27;s network products I work with technically has a self-hosted version of their management service, but it doesn&#x27;t scale down well (it expects dozens of GBs of RAM and to be running on SSD storage or it&#x27;s not supported). I&#x27;ve regularly felt pressured to move to the cloud just to avoid the jankiness.
rsyncover 4 years ago
Ubiquiti is slowly becoming Sonos.<p>The difference is, their potential for bad behavior, risks and attack surface is far, far greater.
评论 #25737046 未加载
评论 #25736620 未加载
ashtonkemover 4 years ago
As someone who was planning on buying Ubiquiti hardware for their house, this breach and a lot of the comments here are disconcerting. Are there any other alternatives that are more locally managed that people would recommend?
评论 #25737402 未加载
评论 #25737088 未加载
评论 #25736911 未加载
评论 #25737005 未加载
评论 #25737278 未加载
评论 #25741876 未加载
emptybitsover 4 years ago
I followed the instructions in their email: 1. change password, and 2. enable 2FA (confirm enabled in my case).<p>Password change went fine. I expected existing sessions to my controller login would be terminated upon a password change. I suppose that&#x27;s not mandatory but it sure wouldn&#x27;t be surprising behaviour for security software IMO. It&#x27;s the conservative thing to do, no?<p>Nope. Already logged-in sessions (web and iOS app) remained functional when I changed the underlying password. No need to re-authenticate.<p>Before I received their breach email today, the past two days I have been unable to log into my controller at all. This was being reported by others through unofficial channels at the same time (Twitter, Reddit). Ubiquiti was silent until this morning. Maybe it&#x27;s just a bad coincidence.<p>I&#x27;m a new Ubiquiti customer. My gear is &lt; 30 days old. Their UniFi Dream Machine seemed to be my &quot;dream&quot; for a home network (AP, VPN, notifications, guests, pretty dashboard). It&#x27;s probably better than the alternatives. But I&#x27;m forming a less than stellar first impression of them after this. Honeymoon over.
评论 #25740513 未加载
omniover 4 years ago
Does anyone have a better link for this, preferably one hosted on Ubiquiti&#x27;s own site somewhere?
评论 #25735637 未加载
评论 #25735541 未加载
评论 #25735649 未加载
评论 #25735679 未加载
评论 #25735650 未加载
评论 #25735651 未加载
评论 #25735434 未加载
cutthegrass2over 4 years ago
Must admit to being disappointed with recent Ubiquiti developments. The requirement to &#x27;Sync Local Admin with Ubiquiti SSO&#x27; for controller authentication is not great.<p>At least as far as I can tell, this means your local controller account requires an internet connection to reach your UI.com account, so there is no local isolation of administrative accounts anymore.
rangersangerover 4 years ago
I did a double take after clicking through- when did Unifi change their URL to UI.com? I thought this was a clever scaled phishing attempt for a second.<p>Come to think of it, how many times have they changed their URL&#x2F;how many are there? feels like im being trained to do something stupid.
评论 #25737066 未加载
yskchuover 4 years ago
More discussions on Ubiquiti subreddit:<p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;Ubiquiti&#x2F;comments&#x2F;kv9fc8&#x2F;ubiquiti_email_re_breach&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;Ubiquiti&#x2F;comments&#x2F;kv9fc8&#x2F;ubiquiti_e...</a>
robertkluinover 4 years ago
&quot;We recently became aware of unauthorized access to certain of our information technology systems hosted by a third party cloud provider.&quot;<p>Is this an attempt to shift blame? Using wording that implies it was someone else&#x27;s fault is not confidence inspiring.
bluedinoover 4 years ago
Ubiquiti is in a weird market, where they are better than Linksys&#x2F;Netgear etc, but they are crap compared to something like Meraki.<p>Their support isn&#x27;t very good (they point you to a forum), their hardware replacement is spotty (sorry, out of stock, you&#x27;ll have to wait!), and their hardware&#x2F;software is buggy. We had 48 port switches that would randomly reboot, for example.<p>They can be a decent solution for SMB wifi, but that&#x27;s as far as I would go. Nothing mission-critical unless you are willing to make compromises you wouldn&#x27;t have to with a bigger vendor.
评论 #25738290 未加载
评论 #25737689 未加载
评论 #25736501 未加载
29athrowawayover 4 years ago
The Ubiquiti Cloud Key is the worst product I have ever purchased.
评论 #25738487 未加载
评论 #25737773 未加载
teekertover 4 years ago
I use the LinuxServer.io Unify controller docker container, it updates very often and everytime it asks me if I want to share data. It feels so dirty, my lan traffic is so personal and I meant to upgrade security and privacy by switching away from my ISP provided modem&#x2F;wifi. I&#x27;m beginning to regret this decision and maybe should have chosen another solution.
wnevetsover 4 years ago
I still haven&#x27;t gotten an email, does that mean I&#x27;m not affected or just a delay in the queue?<p>edit: I have since received the email
ch0I9daAiOover 4 years ago
There&#x27;s a neat docker container you can run for their management application instead of using Cloud™.
lkxijlewlfover 4 years ago
Wish they would roll Wireguard up into the firmware distribution for the edgrouter-x.
zaltekkover 4 years ago
Does anyone know how to completely delete the Ubiquity account? I can&#x27;t find an option anywhere on the website.<p>For now I&#x27;ve renamed the username and put in a fake email address (sadly the username `deletemyaccount` was taken).
alkonautover 4 years ago
Did they email everyone with an account this information? I.e., if I didn&#x27;t get that email, I don&#x27;t have an account?<p>You can&#x27;t check via a login page whether you have an account...
评论 #25737568 未加载
turbletyover 4 years ago
That link looks awful on a mobile browser. Isn&#x27;t MailChimp supposed to make responsive emails easy.<p>It&#x27;s so bad, they have disabled pinch to zoom, so I just horizontally scroll.
p0p0bawaover 4 years ago
ooooh, turn off &quot;Remote Management&quot; if you use Unifi products and are concerned<p><a href="https:&#x2F;&#x2F;help.ui.com&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;115012240067-UniFi-How-to-Enable-Remote-Access-for-Remote-Management" rel="nofollow">https:&#x2F;&#x2F;help.ui.com&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;115012240067-UniFi-How...</a>
评论 #25737927 未加载
neonateover 4 years ago
<a href="https:&#x2F;&#x2F;archive.is&#x2F;y193e" rel="nofollow">https:&#x2F;&#x2F;archive.is&#x2F;y193e</a>
keltover 4 years ago
...and password reset doesn’t work as expected now. Anyone manage to reset?
mygganover 4 years ago
At least we know third party have access to our salted passwords et. al?
评论 #25735925 未加载
xvectorover 4 years ago
Can&#x27;t even get a verification email sent to my address. Amazing.
Paul-ishover 4 years ago
Were any firmware updates pushed out? (To targeted users even)
politelemonover 4 years ago
This ought to be on their blog, rather than mailchimp, no?
评论 #25737401 未加载
评论 #25736932 未加载
lpgauthover 4 years ago
What systems were breached? I haven&#x27;t received an email...<p>Is UNMS ok?
评论 #25736897 未加载
tolienover 4 years ago
It&#x27;s particularly annoying that these happen but UBNT won&#x27;t let you delete your account without calling their help desk (?!) [1] or dropping some sort of GDPR bomb on their heads.<p>1: <a href="https:&#x2F;&#x2F;community.ui.com&#x2F;questions&#x2F;How-do-I-get-my-account-and-profile-deleted-and-removed-due-to-the-security-breach&#x2F;02dcbf9c-6f1c-4688-987f-496e944c3a61#answer&#x2F;cb83695e-c848-4652-a5ab-02b481fada63" rel="nofollow">https:&#x2F;&#x2F;community.ui.com&#x2F;questions&#x2F;How-do-I-get-my-account-a...</a>
rodgerdover 4 years ago
This is a terrible public notification. What is the scope of the breach? Their forum software? The accounts Unifi customers can use for cloud-based admin of their private networks? Support tickets?<p>It doesn&#x27;t inspire one iota of confidence. Quite the opposite.
评论 #25735798 未加载
评论 #25735861 未加载
评论 #25735777 未加载
based2over 4 years ago
<a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Ubiquiti_Networks" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Ubiquiti_Networks</a>