Hacker News new | past | comments | ask | show | jobs | submit login
CVE-2020-28936 – Risks from symmetric encryption in UniFi’s inform protocol (jade.wtf)
2 points by andrewnicolalde on Nov 21, 2020 | hide | past | favorite | 2 comments



I am absolutely shocked that the initial encryption key is literally the md5sum of "ubnt".

https://gchq.github.io/CyberChef/#recipe=MD5()&input=dWJudA

I wonder what the folks at HostiFi (cloud hosted UniFi controller software) might be thinking right now...

edit: Looks like they've seen it. Their response is here: https://twitter.com/_rchase_/status/1329949952408244231


Thanks for sharing our response. I expect this to be fixed by Ubiquiti, but it will probably take some time, so we have that mitigation process available for those interested.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: