{"id":3795,"date":"2021-04-04T11:59:51","date_gmt":"2021-04-04T15:59:51","guid":{"rendered":"https:\/\/www.technewsday.com\/?p=3795"},"modified":"2021-04-05T08:14:29","modified_gmt":"2021-04-05T12:14:29","slug":"whistleblower-accuses-ubiquiti-of-data-breach-cover-up","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/whistleblower-accuses-ubiquiti-of-data-breach-cover-up\/","title":{"rendered":"Whistleblower Accuses Ubiquiti of Data Breach Cover-Up"},"content":{"rendered":"\n<p>Ubiquiti, a company with prosumer routers that have become synonymous with security and manageability, is now accused of covering up a serious security flaw. After 24 hours of silence, the company has now released a statement that does not contradict the whistleblower&#8217;s claims.<\/p>\n\n\n\n<p>A company whistleblower claimed that the company itself had been breached and that the legal team was preventing efforts to accurately disclose the risks of the breach to customers.<\/p>\n\n\n\n<p>Hackers had full access to the company&#8217;s AWS servers &#8211; and they could have accessed any Ubiquiti network devices that customers had set up to control through Ubiquiti&#8217;s cloud service. Hackers were also able to gain cryptographic secrets for single sign-on cookies and remote access, complete source code control and signature key exfiltration.<\/p>\n\n\n\n<p>The whistleblower also stated that the company does not keep logs that show who accessed or did not access the hacked servers. The company&#8217;s statement also confirmed that the hackers were trying to extort money, but did not address the cover-up allegations.<\/p>\n\n\n\n<p>The fact that Ubiquiti does not deny the allegations gives its customers an insufficient warning. It encouraged users to change their passwords and allow two-factor authentication, but did not resort to the blocking of all accounts and the requirement for password resets &#8211; which would have been a more appropriate response.<\/p>\n\n\n\n<p>For more information, read The Verge&#8217;s original story.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ubiquiti, a company with prosumer routers that have become synonymous with security and manageability, is now accused of covering up a serious security flaw. After 24 hours of silence, the company has now released a statement that does not contradict the whistleblower&#8217;s claims. A company whistleblower claimed that the company itself had been breached and [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,16],"tags":[81],"class_list":["post-3795","post","type-post","status-publish","format-standard","hentry","category-companies","category-security","tag-ubiquiti"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/3795","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=3795"}],"version-history":[{"count":4,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/3795\/revisions"}],"predecessor-version":[{"id":3828,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/3795\/revisions\/3828"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=3795"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=3795"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=3795"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}