Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

41–50 of 486 posts

Re: Ubiquiti Networks Breach

#41
PSA: with Mailchimp URLs, it's best to remove the `?e=xxx` URL parameter. That way, A) you can't be identified by the sender as the person who shared the email, and B) other people can't flood your inbox by clicking the "unsubscribe" link at the bottom of the email.

In this case, the cleaned URL that should have been posted is https://mailchi.mp/ubnt/account-notification

Re: Ubiquiti Networks Breach

#42
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

It's impossible to secure yourself against a devoted persistent threat group over the long term. The asymmetry of effort is not tractable to overcome.

So they can take your security seriously, but they will be hacked, or they have already.

Re: Ubiquiti Networks Breach

#43
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

[deleted]

Re: Ubiquiti Networks Breach

#44
post #40

I must admit - Ubiquiti has lost some of it's shine in the last few years, whilst AP and routing hardware seems to still be very good in terms of pricepoint, it does feel like the software side of things has been going in a very strange direction for quite some time. I'm still quite annoyed by the fact that I was forced to migrate from Unifi Video to Unifi Protect - due to vendor lock in and the fact that the remote…

Ubiquiti had a steady exodus of engineers in the past few years. It's a very different company now compared to the glory days of UniFi.

Re: Ubiquiti Networks Breach

#45
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

It's impossible to secure yourself against a devoted persistent threat group over the long term. The asymmetry of effort is not tractable to overcome. So they can take your security seriously, but they will be hacked, or they have already.

I think it is possible to secure yourself against a devoted, persistent threat group.

I think it's expensive, but possible.

Do you have data to back up your claim that no one, ever has ever successfully remained secure?

Re: Ubiquiti Networks Breach

#46
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I’m running pfsense as my router and TP-Link access points. I run their controller in a container locally and everything works great together. Super happy.

I think for some use cases this setup could be a nice alternative (and cheaper) to ubiquiti.

Re: Ubiquiti Networks Breach

#47
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

I mean, should they say that they don’t care about your security?

Re: Ubiquiti Networks Breach

#48

Ubiquiti had a data breach, but what could hackers possibly want to know which we didn't know already? All their customers are overpaid engineers who got sucked into dumb influencer marketing convincing them to buy overpriced industrial grade networking kit for their 50m2 flat.

While I would choose a less abrasive way of stating it, I agree with your underlying assessment. At the recommendation of basically every networking forum and subreddit, I bought some Ubiquiti stuff to power networking and wifi for a new place I recently moved into. It cost 3x what a mid to high-end Linksys would have cost, and as far as I can tell provides literally negative benefit for my purpose:

Specifically, rather than a single box and an easy interface, I now have 3 devices that all require their own power bricks, connected via Ethernet cables, and a UI that required reading all sorts of documents and tutorials just to mimic the functionality of my last consumer-grade router. Not to mention the wifi coverage isn't even as good as my old router, even when adjusting a bunch of settings from default based on said tutorials.

I'm not saying that this hardware isn't worth it for some people, but for anyone who uses it for regular streaming and remote working, it's completely not worth the expense, hassle, and inconvenient form factor.

Re: Ubiquiti Networks Breach

#49
Ubiquiti is in a weird market, where they are better than Linksys/Netgear etc, but they are crap compared to something like Meraki.

Their support isn't very good (they point you to a forum), their hardware replacement is spotty (sorry, out of stock, you'll have to wait!), and their hardware/software is buggy. We had 48 port switches that would randomly reboot, for example.

They can be a decent solution for SMB wifi, but that's as far as I would go. Nothing mission-critical unless you are willing to make compromises you wouldn't have to with a bigger vendor.

Re: Ubiquiti Networks Breach

#50
post #45

Earlier quoted context omitted.

It's impossible to secure yourself against a devoted persistent threat group over the long term. The asymmetry of effort is not tractable to overcome. So they can take your security seriously, but they will be hacked, or they have already.

I think it is possible to secure yourself against a devoted, persistent threat group. I think it's expensive, but possible. Do you have data to back up your claim that no one, ever has ever successfully remained secure?

No one could possibly prove this kind of negative.
Post reply on HN