Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

31–40 of 486 posts

Re: Ubiquiti Networks Breach

#31
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

[deleted]

Re: Ubiquiti Networks Breach

#32
post #24
post #20

At least we know third party have access to our salted passwords et. al?

Sounds like their cloud provider environment was breached. If that's the case then access to databases with salted and hashed passwords is to be expected, is it not? Would be good to know which provider this is and whether it was the fault of the provider itself.

As some of the IPv4 addresses for ui.com seem to be assigned to AWS I'm not sure what to make of it.

Re: Ubiquiti Networks Breach

#33

Ubiquiti had a data breach, but what could hackers possibly want to know which we didn't know already? All their customers are overpaid engineers who got sucked into dumb influencer marketing convincing them to buy overpriced industrial grade networking kit for their 50m2 flat.

Ehh they make great products for smb/coliving/coworking spaces, where you need better hardware than the box the ISP gives you but you don’t need the kitchen sink that comes with Cisco. Simple enough that a slight savvy frat bro or small business owner can set it up in an afternoon and have seamless handoff across a large space with several access points and PoE.

Re: Ubiquiti Networks Breach

#34
post #33

Ubiquiti had a data breach, but what could hackers possibly want to know which we didn't know already? All their customers are overpaid engineers who got sucked into dumb influencer marketing convincing them to buy overpriced industrial grade networking kit for their 50m2 flat.

Ehh they make great products for smb/coliving/coworking spaces, where you need better hardware than the box the ISP gives you but you don’t need the kitchen sink that comes with Cisco. Simple enough that a slight savvy frat bro or small business owner can set it up in an afternoon and have seamless handoff across a large space with several access points and PoE.

Ubiquiti is amazing for your home. You can cycle 50km on your Peleton and still get excellent WiFi signal. Which other router can deliver such outstanding performance!

Re: Ubiquiti Networks Breach

#35
As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.

The saddest part is that we had many good engineers who could have continued to do amazing things with the UniFi momentum. So much time was wasted on dead end products like FrontRow. Most everyone I know left for jobs where we were treated better and paid more.

Re: Ubiquiti Networks Breach

#36
post #30
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Just for reference, I did receive an email from them.

I received one as well approximately an hour ago.

Re: Ubiquiti Networks Breach

#37

Earlier quoted context omitted.

Cloudless if and only if you run their gigantic bloated Java network management tool. I really like ubiquiti hardware but I got fed up with their software BS. Now I use either Mikrotik or TP-Link’s industrial offerings. Both are way easier to work with than ubiquiti and the hardware is usually in the same tier.

... we run it on a raspberrypi. Not sure I'd call that gigantic or bloated.

RasPis have a fair bit more grunt than people give them credit for.

The big problem with the Ubiquti thing is that it takes a long time to start, so if your usage model is to start it whenever you want to make a change it's rather piggish. If you start it once and leave it running forever on a dedicated device it's not nearly as bad.

Re: Ubiquiti Networks Breach

#38

Ubiquiti has typically been the "cloudless" provider which is why I've used their stuff. They've been sorta moving in a disturbing direction for cloud control. I don't want that risk.

Cloudless if and only if you run their gigantic bloated Java network management tool. I really like ubiquiti hardware but I got fed up with their software BS. Now I use either Mikrotik or TP-Link’s industrial offerings. Both are way easier to work with than ubiquiti and the hardware is usually in the same tier.

They have a little device (IIRC they call it "cloud key" or something like that) that runs that interface pretty well. Much better than setting that UI up on a device yourself.

Re: Ubiquiti Networks Breach

#39

Earlier quoted context omitted.

Cloudless if and only if you run their gigantic bloated Java network management tool. I really like ubiquiti hardware but I got fed up with their software BS. Now I use either Mikrotik or TP-Link’s industrial offerings. Both are way easier to work with than ubiquiti and the hardware is usually in the same tier.

... we run it on a raspberrypi. Not sure I'd call that gigantic or bloated.

Its not a great solution. The application logs and writes to storage alot.

Also it usually works fine, but when it breaks, it breaks HARD

Re: Ubiquiti Networks Breach

#40
I must admit - Ubiquiti has lost some of it's shine in the last few years, whilst AP and routing hardware seems to still be very good in terms of pricepoint, it does feel like the software side of things has been going in a very strange direction for quite some time.

I'm still quite annoyed by the fact that I was forced to migrate from Unifi Video to Unifi Protect - due to vendor lock in and the fact that the remote interface for Unifi Video was switched off this month.

I guess on the plus side - no one who is still using Unifi Video has to worry all that much.....

Hopefully it is just a case of resetting passwords and enabling 2FA if you haven't done it already - not entirely sure how much damage could be done otherwise, unless there is an undocumented backdoor into Ubiquiti products ?

Post reply on HN