TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Security Issue: Cloud Site Manager presented me your consoles, not mine

295 pointsby amaccuishover 1 year ago

42 comments

ubiquitithrowover 1 year ago
Ex Ubiquiti employee here. I barely recognize the company any more. The company always had problems but we had a lot of smart and hard working peopl in the early days. People are always amazed when I tell them how small the company was when we made Ubiquiti and UniFi into household names among nerds.<p>Some of those people remain. UI-Marcus in that link is a good person. The company went into a steady decline after the CEO started centering the company around the offices in Portland and China. Portland was home to the UX designers who wanted to redesign everything to look nicer but didn&#x27;t understand how customers used our products. Portland was also home to Nick Sharp, the cloud lead who tried to extort the company and lied to the press about hacks. The favorite office in China made the FrontRow product, which failed so badly that I doubt anyone has heard of it. These people were supposed to be the future leaders of the company, but everything they did was a disaster. We could all see the writing on the wall and left. Well, almost everyone.<p>I don&#x27;t even know which Ubiquiti office owns the cloud any more because everyone working on cloud at Ubiquiti either quit or was laid off after the cloud lead went to prison for extorting the company.<p>I hope the company can get back on track some day. It&#x27;s sad to see all of our old work decay like this.
评论 #38644606 未加载
评论 #38644411 未加载
评论 #38645998 未加载
评论 #38644059 未加载
评论 #38645263 未加载
评论 #38644361 未加载
评论 #38644140 未加载
评论 #38644019 未加载
评论 #38644869 未加载
评论 #38644900 未加载
评论 #38644616 未加载
评论 #38644831 未加载
评论 #38647848 未加载
评论 #38645485 未加载
评论 #38645344 未加载
评论 #38645093 未加载
calamari4065over 1 year ago
I built a UniFi network 6 or 7 years ago. I was pretty excited, as the hardware seemed properly solid. A touch expensive, but I was expecting it to run forever, essentially.<p>The hardware was actually really good from what I could tell. Not a single issue that wasn&#x27;t caused by my own misconfiguration. But the software, woof. The software was designed to do exactly one thing: look impressive to execs in a board meeting. It was nearly unusable for me. I don&#x27;t recall any specifics, but all you really need to know is that it took multiple days to get a simple home network with a single AP and a single router set up. It was so much effort just to log in to the damn thing.<p>I went into this project excited at the prospect of all the cool monitoring and analytics I could do. Fancy security and remote access and whatnot. After I finally got everything configured, I never touched it again. There were a few times when I needed or wanted to get into it, but I couldn&#x27;t remember the specific incantation and combination of software needed to access it, so I just didn&#x27;t.<p>I&#x27;d <i>love</i> to have a solid system built on quality hardware. UniFi is notionally exactly what I want, and exactly what a <i>lot</i> of hackers and tinkerers want. But the quality of your hardware is pretty much irrelevant if your software wasn&#x27;t designed to be used by humans.<p>So I&#x27;m stuck using consumer routers with open firmware. It&#x27;s fine I guess.
评论 #38645223 未加载
评论 #38645242 未加载
评论 #38645071 未加载
评论 #38645373 未加载
评论 #38646084 未加载
js2over 1 year ago
Also on r&#x2F;Ubiquiti:<p><a href="https:&#x2F;&#x2F;old.reddit.com&#x2F;r&#x2F;Ubiquiti&#x2F;comments&#x2F;18hgpw1&#x2F;security_problem&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;old.reddit.com&#x2F;r&#x2F;Ubiquiti&#x2F;comments&#x2F;18hgpw1&#x2F;security_...</a><p><a href="https:&#x2F;&#x2F;old.reddit.com&#x2F;r&#x2F;Ubiquiti&#x2F;comments&#x2F;18hs684&#x2F;no_official_announcement_on_security_breaches&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;old.reddit.com&#x2F;r&#x2F;Ubiquiti&#x2F;comments&#x2F;18hs684&#x2F;no_offici...</a>
评论 #38645311 未加载
farmdveover 1 year ago
The cloud is like those portable toilets in public. They are private, but there are also people around you at all times. Sometimes you forget to lock the door and someone else opens it.
评论 #38654129 未加载
评论 #38655524 未加载
magicmicah85over 1 year ago
Do they by any chance use a CDN for their cloud console? This has burned organizations so many times before where they cache the dynamic data and not static data.
评论 #38644441 未加载
评论 #38644410 未加载
评论 #38645963 未加载
tomkinstinchover 1 year ago
For anyone with a UDMP looking to disable remote access via UniFi servers, the setting isn&#x27;t under the Network application, it&#x27;s part of the higher level console management:<p>Console Settings (menu on left) -&gt; Advanced (heading) -&gt; &quot;Remote Access (checkbox)&quot;<p>Or via: <a href="https:&#x2F;&#x2F;$UDMP_IP&#x2F;console-settings" rel="nofollow noreferrer">https:&#x2F;&#x2F;$UDMP_IP&#x2F;console-settings</a><p>(Hopefully the setting applies locally...)
评论 #38644727 未加载
cmsjover 1 year ago
The real question here for me is: why is my data not flowing through Ubiquiti&#x27;s servers end-to-end encrypted?<p>They should be able to accidentally send my data to another user and have it merely result in a decryption failure.
评论 #38646067 未加载
评论 #38645940 未加载
syntaxingover 1 year ago
I really wish there was an open source equivalent that’s user friendly. I run OPNSense but the learning curve is steep and I wouldn’t recommend it to family because of it. I’ve been debating Firewalla but this same issue can happen since the control panel is cloud based.
评论 #38644136 未加载
评论 #38645296 未加载
评论 #38644118 未加载
netsharcover 1 year ago
Put it on the cloud they say...<p>Reminds me of that time someone at Dropbox pushed a change onto production that ignored your password, so you could login as anyone with any password...
评论 #38653618 未加载
评论 #38655273 未加载
评论 #38655093 未加载
freedombenover 1 year ago
When people ask me why I don&#x27;t use Ubiquiti products, and I tell them that I don&#x27;t trust companies with closed&#x2F;proprietary offerings with something as critical as this, I get a lot of skepticism and even eye-roll. Open source isn&#x27;t a silver bullet, but if I were self-hosting my own &quot;cloud&quot; controls I wouldn&#x27;t be worried about something like this.
评论 #38644848 未加载
LeifCarrotsonover 1 year ago
Navigate to your router&#x27;s IP, go to Console Settings, scroll to Advanced and un-check Remote Access:<p><a href="https:&#x2F;&#x2F;i.imgur.com&#x2F;RzXpT6Q.png" rel="nofollow noreferrer">https:&#x2F;&#x2F;i.imgur.com&#x2F;RzXpT6Q.png</a><p>After doing that, you can&#x27;t access your router remotely from The Cloud, (well, you can log in over the VPN, remote into a computer on-site, and access the router from that computer) but you&#x27;re secure against a whole class of bugs and errors in Someone Else&#x27;s Computer.
评论 #38654224 未加载
评论 #38657496 未加载
评论 #38655067 未加载
twisterifficover 1 year ago
Had a &quot;is this actually your local console?&quot; Prompt from protect this morning. I&#x27;m getting a bad feeling about this.
boilerupncover 1 year ago
Ubiquiti Statement: <a href="https:&#x2F;&#x2F;community.ui.com&#x2F;questions&#x2F;Bug-Fix-Cloud-Access-Misconfiguration&#x2F;fe8d4479-e187-4471-bf95-b2799183ceb7" rel="nofollow noreferrer">https:&#x2F;&#x2F;community.ui.com&#x2F;questions&#x2F;Bug-Fix-Cloud-Access-Misc...</a>
评论 #38653919 未加载
评论 #38655809 未加载
评论 #38653854 未加载
nottorpover 1 year ago
Hmm I should upgrade my wifi next year. Right now I have an old ish Ubiquiti AP that does its job without bothering me, but it&#x27;s from before the cloud insanity.<p>Have they seen the light and made their devices usable without ever logging into their servers? Last time I asked this question the &#x27;cloud&#x27; was unavoidable during the initial set up but could be turned off later. This doesn&#x27;t look like enough to me. I want a damn access point that doesn&#x27;t talk to anything outside my network.
评论 #38653988 未加载
评论 #38654059 未加载
评论 #38674476 未加载
InTheArenaover 1 year ago
<a href="https:&#x2F;&#x2F;community.ui.com&#x2F;questions&#x2F;Bug-Fix-Cloud-Access-Misconfiguration&#x2F;fe8d4479-e187-4471-bf95-b2799183ceb7" rel="nofollow noreferrer">https:&#x2F;&#x2F;community.ui.com&#x2F;questions&#x2F;Bug-Fix-Cloud-Access-Misc...</a>
cturnerover 1 year ago
My parents live in another country, and I want to set up some network equipment at their house so that I can coordinate their network if they get into trouble, and to support cameras as one of them has become high-care. My dad also has some complex data. I intend to install a rackmount server for him so that I can help him with data problems from time to time.<p>For network equipment, I have a fair bit of experience with datacentre grade equipment, but none in the consumer space. I think I want this, 1. Good quality. 2. Fanless 3. Drives multi-node wifi APs 4. Control cameras 5. Web interface that parents can use. 6. Cisco-like CLI that I can use. 7. No cloud.<p>The unifi equipment seems to fit all criteria above except the last two points. Seems you cannot make permanent changes from the console, and their offering is oriented towards cloud configuration. Would someone who knows the segment be happy to offer advice? (thanks in advance)
评论 #38654374 未加载
评论 #38654774 未加载
评论 #38654313 未加载
stusmallover 1 year ago
One possible explanation for this can be a mistake in caching. While it is tempting to log in and see if you can see other people&#x27;s consoles... that just might put you in the cache for someone else to see.<p>There is no way for us to know what is causing the bug and what will help without official word for Ubiquiti but logging in can only possibly hurt and won&#x27;t help.
评论 #38644183 未加载
boeingUH60over 1 year ago
<i>Random fact</i>: Ubiquiti is publicly traded, yet Pera owns 90%+ of it, meaning shareholders virtually have no power to push for changes. You might as well call it a privately held company, lol.
tokamakover 1 year ago
Feels like the issue Steam had with caching <a href="https:&#x2F;&#x2F;securityaffairs.com&#x2F;43189&#x2F;security&#x2F;steam-users-data-exposed.html" rel="nofollow noreferrer">https:&#x2F;&#x2F;securityaffairs.com&#x2F;43189&#x2F;security&#x2F;steam-users-data-...</a>
jbverschoorover 1 year ago
Remote access anything should be banned. Just use a VPN&#x2F;wireguard.<p>Reverse control is such a mess and the application is not the place to handle this
评论 #38644391 未加载
评论 #38644383 未加载
评论 #38644737 未加载
meltynessover 1 year ago
This place has quite a rap sheet.<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=29411775">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=29411775</a> <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9331512">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9331512</a> <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;Ubiquiti&#x2F;comments&#x2F;t7br4a&#x2F;since_the_software_update_at_4am_all_the_switch&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;Ubiquiti&#x2F;comments&#x2F;t7br4a&#x2F;since_the_...</a>
cooljacob204over 1 year ago
I really wish they weren&#x27;t forcing everything to their cloud services for exactly things like this.
评论 #38648024 未加载
barbazooover 1 year ago
Easy to host the console yourself: <a href="https:&#x2F;&#x2F;help.ui.com&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;360012282453" rel="nofollow noreferrer">https:&#x2F;&#x2F;help.ui.com&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;360012282453</a>.<p>There&#x27;s even a docker image for those who have trust: <a href="https:&#x2F;&#x2F;github.com&#x2F;linuxserver&#x2F;docker-unifi-controller">https:&#x2F;&#x2F;github.com&#x2F;linuxserver&#x2F;docker-unifi-controller</a>
评论 #38645270 未加载
评论 #38645231 未加载
评论 #38645475 未加载
Machaover 1 year ago
My decision to not enable remote access feels vindicated now.
awillover 1 year ago
I have a few unifi things at home, and for the most part, they&#x27;ve been good, and work well together. But this sort of stuff is very concerning, and forcing the cloud account on everyone is really stupid.<p>But what are the alternatives. Firewalla seems to be a good alternative, but they don&#x27;t do APs, leaving me with a mixed system.
评论 #38644837 未加载
评论 #38644299 未加载
评论 #38645429 未加载
评论 #38644560 未加载
评论 #38644836 未加载
boilerupncover 1 year ago
Ubiquiti Statement: <a href="https:&#x2F;&#x2F;community.ui.com&#x2F;questions&#x2F;Bug-Fix-Cloud-Access-Misconfiguration&#x2F;fe8d4479-e187-4471-bf95-b2799183ceb7" rel="nofollow noreferrer">https:&#x2F;&#x2F;community.ui.com&#x2F;questions&#x2F;Bug-Fix-Cloud-Access-Misc...</a>
throwaway202312over 1 year ago
If I had to take a guess they might be using a CDN like Cloudflare and temporarily misconfigured a cache rule…
zzyzxdover 1 year ago
Ubiquiti has always been pushing the remote management feature pretty hard. But recently they are also making some really nice VPN features. I hope incident like this would further change their standpoint and actually make local account access nicer.<p>There are tons of dark pattern in the Protect app that prevents you from using a local account. And when you finally learned to workaround all of them, you realized that there&#x27;s no push notification without remote access. (I understand the difficulty to push message straight from console to mobile device, but many selfhostable software offer a centralized, managed push notification relay over internet. I am not sure if this is too much to ask for)
sschuellerover 1 year ago
Ah the beauty of cloud connected networks management. A hackers delight...<p>And then I am the one that gets chastised for not wanting cloud connected router&#x2F;switches in my networks.
tmikaeldover 1 year ago
Considering all of the shit that goes on with routers, maybe it&#x27;s time to say that OpenWRT is the (only) safe-ish option at this point?
aetherspawnover 1 year ago
So what’s the alternative for SMB… Cisco? Where can we buy this stuff cheap without going through an IT company..?
hk1337over 1 year ago
I tried the AmpliFi mesh router several years ago and hated it. It didn&#x27;t seem any better than the Arris gateway that ATT sent me.<p>Why would you have a central console that has the potential for accessing all the routers with a single login though? Why wouldn&#x27;t this be just local to the network with remote access?
everdriveover 1 year ago
I feel very vindicated for avoiding the cloud solution when everyone was praising Ubiquiti back in 2016 or so.
BrianHutchover 1 year ago
<a href="https:&#x2F;&#x2F;community.ui.com&#x2F;questions&#x2F;Bug-Fix-Cloud-Access-Misconfiguration&#x2F;fe8d4479-e187-4471-bf95-b2799183ceb7" rel="nofollow noreferrer">https:&#x2F;&#x2F;community.ui.com&#x2F;questions&#x2F;Bug-Fix-Cloud-Access-Misc...</a>
xystover 1 year ago
UI just can’t catch a break.<p>Earlier this year, some tech tabloid (krebsonsecurity?) reported how bad security was at UI. I think it was ultimately determined to be a bad story and UI sued for defamation.<p>Now we are here again with another possible leak.
评论 #38645464 未加载
op00toover 1 year ago
It’s unlikely that simply seeing things in the main console means you’ll be able to change things if this is a caching issue. It can still expose passwords and other internal information you don’t want to get out.
cogogoover 1 year ago
Odd coincidence in that I had the same problem with Ubiquity the 401k provider several years ago. Could see most of my colleagues 401k accounts. Never good.
gunapologist99over 1 year ago
The cloud is still just someone else&#x27;s computer. (Or camera.)
MenhirMikeover 1 year ago
Does anyone have a recommendation for a replacement? After the requirement to create a cloud account on their so-called &quot;Pro&quot; Dream Machine I already felt something is wrong, and after &quot;Please don&#x27;t use shielded Ethernet cables with our so-called &quot;Professional&quot; WiFi Access Points, they can randomly reboot&quot;[1] and now this nonsense, I&#x27;m just simply done with them.<p>But I really like the hardware of the Dream Machine Pro (Router, Switch with 10G uplink) and the overall view of clients and connected devices, so I don&#x27;t just want to buy some random Router and pair it with random WiFi APs - though I guess that&#x27;s the best choice?<p>[1] <a href="https:&#x2F;&#x2F;help.ui.com&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;8823742725015-UniFi-6-Access-Point-Professional-U6-Pro-Advisory" rel="nofollow noreferrer">https:&#x2F;&#x2F;help.ui.com&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;8823742725015-UniFi-6-...</a>
评论 #38645506 未加载
arczaover 1 year ago
Nice, yet another breach that doesn&#x27;t affect me self hosting my Unifi controller.
28304283409234over 1 year ago
Mikrotik is the way.
teamspiritover 1 year ago
So the guy makes the initial post, within an hour UI team reaches out to him to gather more info and the next post is a criticism of their handling!<p>What’s wrong with people? I think 1 hour response to a forum post isn’t unreasonable or am I wrong?
评论 #38645203 未加载
评论 #38643980 未加载
评论 #38643884 未加载
评论 #38643907 未加载
评论 #38644432 未加载
评论 #38644887 未加载
评论 #38646896 未加载