Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

21–30 of 486 posts

Re: Ubiquiti Networks Breach

#21
post #14

This is a terrible public notification. What is the scope of the breach? Their forum software? The accounts Unifi customers can use for cloud-based admin of their private networks? Support tickets? It doesn't inspire one iota of confidence. Quite the opposite.

[deleted]

Re: Ubiquiti Networks Breach

#22
No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™.

Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

Re: Ubiquiti Networks Breach

#23
Ubiquiti has typically been the "cloudless" provider which is why I've used their stuff. They've been sorta moving in a disturbing direction for cloud control. I don't want that risk.

Re: Ubiquiti Networks Breach

#24
post #20

At least we know third party have access to our salted passwords et. al?

Sounds like their cloud provider environment was breached. If that's the case then access to databases with salted and hashed passwords is to be expected, is it not?

Would be good to know which provider this is and whether it was the fault of the provider itself.

Re: Ubiquiti Networks Breach

#25
Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers providing sane defaults for a common case of having multitude of devices at your home which can be categorized as intruder but expect to be on the same network as your phone.

Is there a better alternative? When I tested multiple routers mostly regarding low latency, network stability and reliability a few years ago nothing came close, especially when having multiple access points.

Re: Ubiquiti Networks Breach

#26
Ubiquiti had a data breach, but what could hackers possibly want to know which we didn't know already? All their customers are overpaid engineers who got sucked into dumb influencer marketing convincing them to buy overpriced industrial grade networking kit for their 50m2 flat.

Re: Ubiquiti Networks Breach

#28

Ubiquiti has typically been the "cloudless" provider which is why I've used their stuff. They've been sorta moving in a disturbing direction for cloud control. I don't want that risk.

Cloudless if and only if you run their gigantic bloated Java network management tool.

I really like ubiquiti hardware but I got fed up with their software BS. Now I use either Mikrotik or TP-Link’s industrial offerings. Both are way easier to work with than ubiquiti and the hardware is usually in the same tier.

Re: Ubiquiti Networks Breach

#29

Ubiquiti has typically been the "cloudless" provider which is why I've used their stuff. They've been sorta moving in a disturbing direction for cloud control. I don't want that risk.

Cloudless if and only if you run their gigantic bloated Java network management tool. I really like ubiquiti hardware but I got fed up with their software BS. Now I use either Mikrotik or TP-Link’s industrial offerings. Both are way easier to work with than ubiquiti and the hardware is usually in the same tier.

... we run it on a raspberrypi. Not sure I'd call that gigantic or bloated.

Re: Ubiquiti Networks Breach

#30
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Just for reference, I did receive an email from them.
Post reply on HN