11 ms·
The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in
by JanSolo 3y ago
The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised.
That's a shame; I was thinking of installing some in my house.
I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.
- andreasley 3y agoI think at this point it's pretty safe to assume that all of the well-known network hardware is compromised.
- tekeous 3y agoI wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.
- chinathrow 3y ago> have to bow to the NSA You don't have to bow in order to be compromised. You can be compromised without even knowing it.
- ElectricalUnion 3y agoSeveral MikroTik routers use marvel hardware underneath. So marvel might be compelled to backdoor the hardware for the NSA.
- lowkeyoptimist 3y agoJoking? LOL https://thehackernews.com/2023/07/critical-mikrotik-routeros.html https://thehackernews.com/2023/07/critical-mikrotik-routeros...
- smolder 3y agoMikroTik has come up in their slides before, yes...
- pizzalife 3y agoThere's been plenty of remote 0days in MikroTik's products. At one point people were paying a pretty penny for them.
- somehnguy 3y agoI think it’s worth noting that these vulnerabilities affected devices which had their management page open to the internet, which is universally known as a bad idea. At least the ones I’ve seen. There is a big difference between an exploit affecting all devices vs a subset which requires a specific not-best-practice configuration. Regardless, still good to be aware they exist.
- HideousKojima 3y agoI assume by default that any hardware from any NATO nation is compromised by the NSA and other Western intelligence agencies. I also assume that any Chinese or Russian hardware is compromised by their respective intelligence agencies. And I assume that the NSA and other Western agencies are constantly trying to get backdoors into Chinese hardware (and I assume the Chinese are trying the do the same to ours). You're basically screwed no matter what.
- ok123456 3y agoBuy products that are compromised by both, and let them battle it out. Sort of like the inverse of the plot of the movie hackers.
- some_random 3y agoWhy would the NSA need to strong arm MikroTik to implement a backdoor when they can pay ~10k for an 0-day to do the exact same thing?
- irreticent 3y agoBecause zero day vulnerabilities are usually patched when discovered by the vendor. They're completely different than an intentional backdoor.
- greenie_beans 3y agoi've always assumed they were the least secure of all my networking hardware
- greenie_beans 3y agoah shit now i've outed myself to the fbi if they didn't already know this about my network
- deleted 3y ago[deleted]
- paganel 3y ago> they’re Latvian and don’t necessarily have to bow to the NSA. reply The majority (I'd say all) of the Eastern-European countries that are also NATO members do in fact bow to the US, and thus to the NSA/FBI/the Secret Service.
- hedora 3y agoSo, Marvell bought the company that backdoored all my Ubiquiti gear. Since it was never working as advertised, do I contact them or Ubiquiti to get my refund / warranty replacements?
- snoman 3y agoIt’s an interesting thought experiment to wonder if consumer protections extend to defects from state sponsored acts of espionage.
- tltimeline2 3y agowasn't ubiquiti totally compromised in that breach a couple of years ago?
- tristor 3y agoNo. It turns out that breach was faked, effectively. It was done by manipulating Brian Krebs. He's since issued a mea culpa (although a somewhat weak one): https://krebsonsecurity.com/2022/08/final-thoughts-on-ubiquiti/ https://krebsonsecurity.com/2022/08/final-thoughts-on-ubiqui...
- stephen_g 3y agoThat was an insider trying to extort the company by pretending to be an outside hacker. He then posed as a whistleblower to try and throw investigators off the trail.
- deleted 3y ago[deleted]
- RationPhantoms 3y agoIf you're not under the threat cone of nation state surveillance (like trying to exfiltrate the radar-asborbing paint formula on the F35) then I wouldn't be too concerned. "That's not the point! It's about privacy!" Sure. I'll choose it ignore the fact that our civilization is somehow still functioning in a post-nuclear world.
- isykt 3y ago100% agreed. If you’re concerned about privacy, being tracked online by corporations is a bigger concern than the the NSA. If you’re the target of an NSA investigation, you’re already fucked. Changing your network equipment is not going to help.
- Minor49er 3y agoOn the contrary, changing equipment may actually help quite a bit when dealing with the NSA. The 2016 documentary "Zero Days" which was centered around the creation of Stuxnet showed that the NSA targeted specific hardware models to look for security holes. They had to buy matching hardware themselves and rigorously try to break it which took time and wasn't trivial to do
- isykt 3y agoSo you’re saying that no matter what hardware you have, the NSA will buy that specific hardware and take the time to break it.
- Minor49er 3y agoThat's right. And I'm also saying that switching hardware will make the break attempts take longer
- isykt 3y agoAnd in the mean time, all my browsing, payment, and location data collected by corporate ad brokers got handed over to the NSA for just the cost of a letter. I don’t see the point in constantly changing hardware that I don’t even know is safe, just to prevent what will already happen.
- colordrops 3y agoUbiquiti has many other problems besides this. The worst is their vendor lockin, where even basic network operations are not possible if you happen to have any non-ubiquiti hardware in your network. You should stay away.
- georgebashi 3y agoCan you provide an example of this issue? This has not been my experience.
- colordrops 3y agoPeople are misinterpreting me, thinking I mean that it's not even possible to intermingle equipment. That is not the case. The specific issue I ran into was that I had a non-ubuiqiti router and AP on my network, and there was absolutely no way to set firewall rules on the Ubiquiti gateway for any clients connected through the non-ubiquiti equipment. This should obviously not be a problem. The gateway provided those clients IP addresses through DHCP and they are in its ARP table, so it should be supported.
- tssva 3y agoI have a mix of Ubiquity and non-Ubiquity equipment and have no problem achieving not only basic but fairly complex networking operations.
- Freestyler_3 3y agoI ran UBQT hardware with mikrotik router and third party firewall. UBQT replaced old frankenstein hardware that had the worst channel management etc. Everything got so much better, customers issues dropped to almost zero (sometimes was hundreds of issues a day) We always had other vendor for part of the network, and that had no impact.
- stephen_g 3y agoPretty sure only the EdgeRouter and some of the older Unifi Security Gateways use Cavium chips. Most of the newer stuff (like the Dream Machine line) I don't think are anymore. None of the Unifi APs did either I don't think (the U6 ones have Mediatek chips in them)
- slau 3y agoAnnoyingly, the ER4 uses the Cavium Octeon III. I have a few of those in production.
- stephen_g 3y agoYeah, I have one at home too, so I really want more detail on what the exploit is (I wonder if if is perhaps IPSEC specific, like an RNG flaw since they talk about VPN and encryption appliances, or it could be something to do with Cavium HSMs and unrelated to the network processors).
- inferiorhuman 3y agoSome of the EdgeRouter stuff (ER-Lite, ER-4) use Cavium SoCs. The ER-X uses a MediaTek SoC.
- djangelic 3y agoI recently upgraded my USG for a dream machine, glad it seems the upgrade was worth it.
- mrweasel 3y agoI'm currently replacing my network equipment with Mikrotik, not because I believe it to be safer than Ubiquity, but because then at least it's made in the EU. But now I'm thinking: Is it better that the US is spying on me in Europe, vs. having EU governments do it? I feel like I'd be somewhat more safe from the US, compared to if my own government decides to spy on me. Maybe I should look into Chilean network equipment, I can't imaging that they'd have much interest in my online activities.
- Freestyler_3 3y agoOther countries spy on you and sell it to your own country.
- manmal 3y agoEurope doesn’t make that many chips (unfortunately), chances are high there’s US/Chinese components in there too. Since your network hopefully sees mostly encrypted traffic anyway (even if you're running Plex on the LAN, that should use SSL), I‘d be more concerned about HW in desktops, notebooks and tablets.
- owenmarshall 3y ago> But now I'm thinking: Is it better that the US is spying on me in Europe, vs. having EU governments do it? I feel like I'd be somewhat more safe from the US, compared to if my own government decides to spy on me. https://en.wikipedia.org/wiki/Five_Eyes https://en.wikipedia.org/wiki/Five_Eyes > In recent years, documents of the FVEY have shown that they are intentionally spying on one another's citizens and sharing the collected information with each other, although the FVEYs countries claim that all intelligence sharing was done legally, according to the domestic law of the respective nations. So in practice, it's entirely irrelevant: your data will end up Hoovered up by someone, coated with a veneer of legality, and provided back to your government to act on (or not). Don't be too interesting to your government, I guess?
- BlueTemplar 3y agoNone of these are EUropean countries.
- some_random 3y agoIn a world where local PD can kick my door in, shoot me in the face, and the news will report that I had it coming because I own a gun, I find it hard to care that the IC can burn a technical access backdoor to access my private data.
- drexlspivey 3y agoTrying to understand what crypto is the network hardware itself performing? TLS is end to end, even if you run a VPN on the router the keys were not generated there probably
- slt2021 3y agocrypto doesn't matter if chip itself has backdoor that will grant root access on some "magic" packet
- dna_polymerase 3y agoCrypto matters for exactly this reason. All my internet traffic passes through unsafe middle-boxes, it is TLS and DH that make sure I can pass through untrusted middlemen without them knowing what is going on.
- slt2021 3y agoCavium chips are installed on security appliances (lol): think Palo alto firewall, fortinet firewall, F5 Big-IP etc. they will see your traffic in plain text by design
- irreticent 3y agoIf everything is encrypted then you're safe... until you decrypt the data on a machine with a backdoored CPU.
- ilyt 3y agoFlashing openWRT on some boxes is probably your best bet; Or, alternatively, treat your LAN/WiFI like public internet and don't send anything unencrypted thru it
- wil421 3y agoUnifi lets you flash custom firmware? I thought they started singing all firmware years ago to stop it.
- blueridge 3y agoI was also going to move to Ubiquiti but decided to go with Peplink instead based on recommendations from: https://routersecurity.org/ https://routersecurity.org/ https://www.peplink.com/products/balance-20x/ https://www.peplink.com/products/balance-20x/
- locusm 3y agoHad never heard of Peplink till now - their modular stuff looks useful.
- deleted 3y ago[deleted]
- Astronaut3315 3y agoSome specific Ubiquiti gear uses Cavium SOCs, but certainly not all. The UDM Pro uses an Annapurna Labs SOC and my old EdgeRouter-X was Mediatek.
- sneak 3y agoUnifi stuff auto updates from the vendor, which is subject to US law. The SoC manufacturer is irrelevant. If the USG wants in, it's just a click away in any case.
- pvg 3y agoIf the USG wants in, it's just a click away in any case. What's a legal and practical mechanism the US Government could use to do this? In almost any number of clicks, never mind one.
- ricktdotorg 3y agookay, so assuming the US gov can access my private LAN data due to my use of the Ubiquiti USG as router/firewall, USG wifi APs etc, of what form would this data exfiltration take? can we please explore/explain how this "compromise" would happen in real-life. if i were sniffing for outbound WAN traffic as root on the unix-like that the USG run, would i see the exfiltration traffic? or is this [supposedly/apparently] happening at a lower layer that an OS can't see i.e. some kind of BMC or BIOS layer? wouldn't such traffic also have to navigate the varieties/restrictions of DOCSIS etc? or are they also compromised? is the worst-case scenario here some kind of giant C2 network with waves hands tons of compromised lower-than-OS mini pieces of firmware exfiltrating data over waves hands compromised network providers hardware into the giant NSA AWS cloud?
- lofaszvanitt 3y agoWould be an interesting experiment to see what an oscilloscope sees on the wire vs what tcpdump records... There was a story somewhere on the net where someone complained thay they wanted to include a do not record payload parameter in tcpdump and couldn't get it through.
- sneak 3y agoUbiquiti is all cloud based. If the government wants in to your auto-updating ubnt hardware, it's just a simple court order away. They don't need a backdoor.
- anderiv 3y agoIt may be auto-updating by default, but that can be trivially disabled. Likewise, their cloud connectivity/management is optional. I'm running without issue multiple air-gapped Ubnt networks using their self-hosted controller software.
- fyloraspit 3y agoYeh but it is still closed source, no? I guess if it is air gapped that could be fine, but we are talking mid level network gear here, so for 99% of its use, it isn't air gapped. It is enabling broader connectivity. So you would have to trust the closed source software at some point.
- sneak 3y agoIf it's airgapped, what do you care about it being backdoored?
- lofaszvanitt 3y agoAirgapped doesn't necessarily mean it can't be accessed remotely...
- sneak 3y agoThat's literally and precisely what it means. Perhaps there is some new watered down usage (like what happened to "literally" or "bricked") but that is precisely why people use the term "air-gapped" - to denote networks with PHYSICAL separation from other means of access. (Of course, if you connect an AP, it's no longer air-gapped."
- 3y ago