HACKER Q&A
📣 JaggerJo

My WiFi password changed over night


This morning I woke up to notice something strange. My internet radio alarm was not playing and instead wanted me to setup a internet connection.

Did not really think about it - because radios usually have crappy software and a short power outage could have caused it was my thought.

Then I realised that I can't stream music to my Sonos speakers while still in bed. Also just thought Spotify probably has some issues (happened before).

When I finally tried to use my computer I realised that all my devices aren't connected to my wifi anymore. It prompts with an 'invalid password' dialog - and wanted me to enter the password.

My router is a Ubiquity Dream Machine (not pro) and I use their cloud account. I checked what was put there as the password and it's an old password from me. (this shocked me - I did not change it.)

How could this have happened?

Are there things I should do?

Other thoughts I had:

- Someone is trying to get my wifi credentials by cloning my SSID name. (unplugged my AP and the network disappeared so I guess that a not the case.)

- Ubiquity screwed up an update. (Nope - works properly after changing the password back)

- Ubiquity somehow restored an old version (I might have had that password as the wifi password before. But this was a year ago.)

Actions I have taken:

- changed unify account password

- checked https://haveibeenpwned.com

my mail address is included in one breach.


  👤 computator Accepted Answer ✓
Not an answer to your question, but just a warning to anyone considering buying a Ubiquity Dream Machine. You can no longer set up or manage a Dream Machine locally — you must use Ubiquity’s cloud management. You could do everything locally in the past, but no longer with new Dream Machines. Another great product ruined by the trend in which every device has to phone home, be centrally managed, and report every action you take.

👤 brudgers
I would guess that the service restored the old password. It fits the evidence and is the sort of thing that a business of that type would do.

👤 jtchang
Ubiquiti did disclose a breach on Jan 11, 2021. Is it possible that your data was compromised and they logged in and reset your data?

👤 space_rock
What encryption level was set on the WiFi? WEP is compromised and can be hacked. Reset the router and change the protocol