So … Did Ubiquity or Ubiquiti really get breached, or was it a hoax?

I believe you’ll need to search Ubiquity as Ubiquiti (I believe I misspelled it to begin with) but I saw an article through Brian where he pulled down two stories about a potential breach and we covered it on this podcast.

In fact, I got the spelling from Krebs himself, however, I’m not even sure if its Ubiquity or Ubiquiti.

Stoieve over at Security Now has it the other way, so I’m spelling it both ways so its picked up by search.

With that said, the article is short and is titled Final Thoughts on Ubiquiti and I also feel bad about the whole thing.

I believe I said that we’d see what would happen, as I’ve never had contact with the company.

Suffice it to say, while I’m not going to remove the podcast(s) and blog posts myself, just because I believe I’ve said in the past that we’ll see what happens, other articles may have been pulled.

Brian writes:

Last year, I posted a series of articles about a purported “breach” at Ubiquiti. My sole source for that reporting was the person who has since been indicted by federal prosecutors for his alleged wrongdoing – which includes providing false information to the press.

So now we learn that the source that made the articles sound so good and got everyone talking got himself in serious trouble. He continues:

As a result of the new information that has been provided to me, I no longer have faith in the veracity of my source or the information he provided to me. I always endeavor to ensure that my articles are properly sourced and factual.

When I blog, I always make sure that it seems credible and I believe those articles sounded like Brian writing something that was a developing story. I never felt like it wasn’t true, but with stories like this, you just never know. No wonder Ubiquiti or Ubiquiti (however its spelled) never commented. They probably knew all along that there wasn’t a problem, but we as readers of articles and blogging our thoughts just don’t know. Brian, I completely understand.

He finishes:

This time, I missed the mark and, as a result, I would like to extend my sincerest apologies to Ubiquiti, and I have decided to remove those articles from my website.

Brian, I think everyone who talked about this story has to apologize to the company. Learning this is something unfortunate, and I always find your writing valuable and also informative. I don’t think we missed the mark, I believe we went based on what was reported.

You are “correcting the record” as I call it. Please continue to do the best job you can as a reporter. I’ll be talking about this on podcast 111, as we did talk about this in news notes on podcast 73 of TSB.

Again, its unfortunate, I think we all missed the mark on this one. Lots of publications probably picked this up and that probably hurt the company more than their denial of the what was a no breach. Wow!

Just passed this on to Security Now’s Stieve Gibson, through Twitter. He talked about it in podcast 700 according to my blog. I’m sure the whole industry will be in shock on this one.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.